PDA

View Full Version : Forum hacked, version 4.0.6 Patch Level 4


pzet
05-10-2012, 07:32 AM
Hello,

Just found this morning that my forum was hacked. All IP's in "who is online" point to one and the same IP-address: 194.1.150.194
The last registration attempt comes from this IP. From what I can remember few days ago someone with the same email address was trying to register from a Russian IP address.

I am using the advanced IP manager as well as the stop forum spam addon - I banned the initial IP address from registering.

Can anyone help please.
Thanks
Peter

deadlySniper
05-10-2012, 07:53 AM
I know for one, I would upgrade. Second, have you banned the IP? Also, I usually would ask my host to ban certain countries. I was having issues with turkish spam, so I had the country blocked.

pzet
05-10-2012, 08:03 AM
I am running the latest available security patch (for version 4.0.6) so from that end it should be fine.

To ban certain countries won't really help. By using the Tor browser a hacker can attack virtually from any country.

deadlySniper
05-10-2012, 08:10 AM
The only thing I can think of, is that the version you have is not secure. I know when I was running 3.8.4 with PL. They released 3.8.5 which fixed more security issues that the previous patch level didnt fix. Also do you allow same IP registrations or duplicate registrations?

pzet
05-10-2012, 08:29 AM
no duplicate registrations allowed.

deadlySniper
05-10-2012, 08:32 AM
My other thought is, did the person actually hack? Like did they get any admin? It could just be the person registering multiple accounts.

pzet
05-10-2012, 08:34 AM
No, that user was blocked - no registration.

There must be another loop hole to access the database.

borbole
05-10-2012, 10:12 AM
I am running the latest available security patch (for version 4.0.6) so from that end it should be fine.

To ban certain countries won't really help. By using the Tor browser a hacker can attack virtually from any country.

No, it is not fine. As there are many security issues found in the later versions that affect your version as well. The best thing would be to upgrade to the latest stable version.

That said, can you ask your host to check their access logs for around the time of the hack and see what happened and how it did happen? That would help in identifying the point of entry and patch it up.

cellarius
05-10-2012, 10:42 AM
Hello,

Just found this morning that my forum was hacked. All IP's in "who is online" point to one and the same IP-address: 194.1.150.194
This is an IP address in Great Britain, belonging to Global Gold Network Provider. Any chance you're hosting with them?

Make sure your provider did not make any settings to his proxy, firewall or other network related setup. If IPs are not passed properly, all your users/guests will show as having the IP address of the proxy.

pzet
05-10-2012, 10:52 AM
This is an IP address in Great Britain, belonging to Global Gold Network Provider. Any chance you're hosting with them?

Make sure your provider did not make any settings to his proxy, firewall or other network related setup. If IPs are not passed properly, all your users/guests will show as having the IP address of the proxy.

Thanks for your reply. Yes I am hosting my forum with Globalgold.
Just contacted the hoster, they are working on the issue.

Thanks