PDA

View Full Version : Forum Destroyed By Hacker


Steve-Hoog
09-17-2013, 02:18 PM
In the last week we were still on 4.1.x and a hacker demolished our vB software; however, he did not touch the Database. Thank God

This hacker was:
Greeting From BangoBnG
this website has been Hacked have fun,
Egypt - t.w.e@msn.com
-SeiF 2007-2013

Age:16
Name:SeifAhmed
Country:Egypt
What is your experience with botnets:I am Trying To MAke DDos form BOts
What bots have you used before:vertexnet,zuse,Obtima
How often are you active:I am online evry day for 16 Hours
Are you willing to learn:yes
Do you have a little money to use:no :'(
All of your contact:
My Skype: Seifskp

Now we are on 4.2.1 and today someone was trying to get us but we caught them in time:

ppp ppp@gmail.com 09-17-2013 09-17-2013 0

I have done a great deal of reading here and IMO opinion too much effort is being put into identify that you have been hacked and how to try to fix it; should we just eliminate their ability to get in our systems, and shouldn't this be the job of vB? Not the customers; and not the customers paying third parties? This is very depressing to say the least.

Max Taxable
09-17-2013, 02:19 PM
I've been a vB licensee since 2005, never been hacked or defaced. Of course, I adroitly avoided getting vB4. Might have alot to do with it.

obglobal.net
09-17-2013, 02:23 PM
shouldn't this be the job of vB? Not the customers; and not the customers paying third parties? This is very depressing to say the least.

Exactly! I've payed vBulletin for an insecure forum that's now down for the second time in 2 weeks because of a hacker. F'ing scumbag.

WHy are they selling me on a software they can't protect?

--------------- Added 1379431576 at 1379431576 ---------------

And it looks like they've gotten in to my cPanel, as well.

Steve-Hoog
09-17-2013, 05:34 PM
Log of what my hacker friend did if this helps anyone else.

119416 N/A 22:20, 12th Sep 2013 plugin.php 41.47.48.122
119415 N/A 22:20, 12th Sep 2013 plugin.php update 41.47.48.122
119414 N/A 22:20, 12th Sep 2013 plugin.php add 41.47.48.122
119413 N/A 22:20, 12th Sep 2013 plugin.php modify 41.47.48.122
119412 N/A 22:20, 12th Sep 2013 plugin.php product 41.47.48.122


--------------- Added 1379443378 at 1379443378 ---------------

I have only these three Plugins, can anyone advise if either is a risk?

VSa - Advanced Forum Statistics 7.1 VSa - Advanced Forum Statistics
Edit Check Version Disable Export Uninstall

VSa - ChatBox 3.1.8 VSa - ChatBox
Edit Check Version Disable Export Uninstall

VSa - Visitors in Last X Hours 3.0.4 VSa - Visitors in Last X Hours



--------------- Added 1379508741 at 1379508741 ---------------

Has anyone turned off Registration and still been exploited?