View Full Version : security breached
xxxsaint
10-13-2003, 12:29 AM
Hi , I come home this afternoon to find that someone has changed my admin password and is logged in with it. Immediately I thought it was because I've had html enabled on my board , so the first thing I did was to de-activate it in each forum on there and disable it from signatures.
Is there anywhere else that I can / should disable it from ? I'm kinda lost here on this one , never thought I would have that problem , but here it is.
any help and suggestions appreciated.
Erwin
10-13-2003, 12:57 AM
What version are you using?
What hacks do you have?
Do you have other admins? Is you admin account unchangeable by other admins?
HTML is a bad idea as some code can be used to harvest cookie passwords.
xxxsaint
10-13-2003, 01:00 AM
What version are you using? 2.2.6
What hacks do you have?
LeSane's Store - vbquiz - awards hack for store - arcade
Do you have other admins? yes
Is you admin account unchangeable by other admins?no
HTML is a bad idea as some code can be used to harvest cookie passwords.
Xenon
10-13-2003, 02:34 PM
upgrade immediately to vb2.3.2, as there are a lot security holes below 229.
Update the Storehack, too.
There was also a big security hole in the old versions.
Dean C
10-13-2003, 03:38 PM
.htaccess your admin directory too :)
xxxsaint
10-13-2003, 04:49 PM
.htaccess completed
and get this , the guy just did it AGAIN but I caught how he did it :
through a donation in the store
if I upgrade the store , will it patch that ???
Lesane
10-13-2003, 05:36 PM
Yes:
https://vborg.vbsupport.ru/showpost.php?p=436467&postcount=2423
Xenon
10-13-2003, 05:40 PM
.htaccess completed
and get this , the guy just did it AGAIN but I caught how he did it :
through a donation in the store
if I upgrade the store , will it patch that ???
yes, but it'll just close the hole in the Store Hack.
There are other possibilities, too, so you should really upgrade the whole board
xxxsaint
10-13-2003, 05:47 PM
k , well , in process of entire upgrade now.
Erwin
10-14-2003, 07:05 AM
There you go. :) The vB.org community saves the day once again... ;)
xxxsaint
10-14-2003, 12:37 PM
yea , i love this place , if it weren't for vb.org , i wouldn't have re-done my forums.
Now , just how safe is this new store ? We need a points system , one that is simple to add and subtract points from users , and I don't wanna go through this again. Any suggestions ?
Dean C
10-14-2003, 12:55 PM
The new store is safe :)
xxxsaint
10-14-2003, 03:57 PM
kool , new store installed , thanks guys , i appreciate all of you ;)
Mickie D
10-14-2003, 07:11 PM
just wondering what did you do with the user and did they get a backup of your database ?
ADMIN LOG ?
just interested as i had the store hack back then and people found lots of holes to change things i never wanted them to do lol (but i heard the store hak is now security tight :))
xxxsaint
10-14-2003, 09:01 PM
i caught him just as he got it and locked the server down , booted him out , checked admin logs , he didn't have time to do much at all , just didn't want to fight that constantly ya know ;)
Erwin
10-15-2003, 09:10 AM
i caught him just as he got it and locked the server down , booted him out , checked admin logs , he didn't have time to do much at all , just didn't want to fight that constantly ya know ;)
You may want to back up your data, and restore your server, and restore the backup, just in case. You never know what the hacker has installed - a backdoor or trojan.
xxxsaint
10-15-2003, 02:17 PM
I wiped it and did a new database ;)
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.