![]() |
If he was just opening and closing the forum (e.g. from the adminCP), you can just demote all mods / admins except for yourself to a normal user, double check the rights of all the member groups, and check to make sure you're the only super admin (if you are one at all).
|
I'm sure he didn't had access to the admincp either, because he could run custom queries from there to get the user list.
It seems to me he got a way to upload a php file, and by adding an include('includes/config.php') he ran a script that turned the forum down. Now, If he knew what he was doing, he would have included a query in the uploaded file itself to strip the user list. Again, it's just a script kiddie. |
Just think for yourself: If you where a hacker and had software to gain access to any vBulletin board, why would i target your site, i would go for the sites that get most attention: vb.com & vb.org.
Now how come we are never target to such successfull attacks if it was possible to hack "any vBulletin board". |
I would seriously reconsider your password and security policy's for staff.
|
One little question, is your whole webspace down or only your vb board?
If its the whole site (server not reachable anymore), then your provider should update the linux software with a better kernel. I know this kinds of scripts getting your webspace down. |
His Reply.
Quote:
This guy is pissing me off... im going to have all my passes rest and then go from there. |
Resetting the passwords should have been one of the first things you did.
He's bluffing. Ignore him and do not respond to him. The chat remark gives him away. Most sites that have a chat on them have a chat directory. Also, if he had your FTP, you would be seeing some phantom pages by now. He's bluffing to try and get you to give in. And with language like he is using, I'm guessing he isn't 15 yet. Look there first at any staff you have had in the past. |
Quote:
|
As Iogames stated, he's playing mind games.
Don't give in, put on your poker face ;) Also, my pass is 40 chars long consisting of letters numbers and an alot code. Maybe you should do the same,so you don't have to worry about some little cracking attempts. Btw, if he does have your database already, all he has to do is crack your hash and he has your forum password. So your best off to change it. |
how is he getting in touch with u - if its by way of emails then he is leaving a trace etc - act upon it
|
All times are GMT. The time now is 05:34 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|