vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Is this a possible hack?? (https://vborg.vbsupport.ru/showthread.php?t=313173)

DreadsUK 07-23-2014 12:38 PM

Is this a possible hack??
 
I've just had a message prompt on my forum saying that my password is over 180days old and i need to create a new one.

I didn't want to go ahead with that incase its a possible hacker attempting to gain access to my current passwords.

Is there a way i can disable the password update for my account.

It seems strange to me that an admin needs to be prompted to update a password

ForceHSS 07-23-2014 12:55 PM

That's default, you can disable it if needed, but its best to leave it for security reasons

DreadsUK 07-23-2014 02:25 PM

Quote:

Originally Posted by ForceHSS (Post 2507919)
That's default, you can disable it if needed, but its best to leave it for security reasons

The default was set to '0' for all over usergroups accept for admin. someone has definitely changed it.

I changed it back to '0' so it doesn't take effect and got back in ok.

Now it seems someone has tried to log into the admin panel as i've just tried and its telling me this message

https://vborg.vbsupport.ru/

Dave 07-23-2014 02:27 PM

If someone tried to login into the admin panel, you should definitely consider securing your admincp and/or changing the directory.

DreadsUK 07-23-2014 02:51 PM

Quote:

Originally Posted by Dave (Post 2507927)
If someone tried to login into the admin panel, you should definitely consider securing your admincp and/or changing the directory.

How do i do that?

ForceHSS 07-23-2014 02:59 PM

Quote:

Originally Posted by DreadsUK (Post 2507926)
The default was set to '0' for all over usergroups accept for admin. someone has definitely changed it.

I changed it back to '0' so it doesn't take effect and got back in ok.

Now it seems someone has tried to log into the admin panel as i've just tried and its telling me this message

http://s27.postimg.org/sr9paif2b/Scr...t_16_21_37.png

I was talking about the admin account what group are you talking about

Dave 07-23-2014 03:12 PM

Quote:

Originally Posted by DreadsUK (Post 2507932)
How do i do that?

There are many ways:
- a .htaccess file in the admincp directory which has a list of allowed IP's.
- A mod like https://vborg.vbsupport.ru/showthread.php?t=312555
- Hardcoding an IP restriction in the index.php file of the admincp.

ozzy47 07-23-2014 03:32 PM

I would suggest this mod, https://vborg.vbsupport.ru/showthread.php?t=312555

No need to do it I'm the files.

RichieBoy67 07-23-2014 03:34 PM

Quote:

Originally Posted by ForceHSS (Post 2507933)
I was talking about the admin account what group are you talking about

Hey, your supposed to be recuperating man!:D

--------------- Added 23 Jul 2014 at 12:36 ---------------

Quote:

Originally Posted by ozzy47 (Post 2507935)
I would suggest this mod, https://vborg.vbsupport.ru/showthread.php?t=312555

No need to do it I'm the files.

I know you do this stuff alot but wow! You finally turned into files? lol

Great mod btw!

I also use the admin firewall which lets certain ips in. That combo is rock solid.

DreadsUK 07-23-2014 03:42 PM

Quote:

Originally Posted by Dave (Post 2507934)
There are many ways:
- a .htaccess file in the admincp directory which has a list of allowed IP's.
- A mod like https://vborg.vbsupport.ru/showthread.php?t=312555
- Hardcoding an IP restriction in the index.php file of the admincp.

How do i locate the ip addresses for people who have accessed/tried to access and Admin CP?

ozzy47 07-23-2014 03:52 PM

Only problem restricting it to ip's is everyone needs a static ip not a dynamic one.

Dave 07-23-2014 03:55 PM

Quote:

Originally Posted by DreadsUK (Post 2507938)
How do i locate the ip addresses for people who have accessed/tried to access and Admin CP?

There might be a mod to log the ACP login attempts, you should search the mod section. You might be able to find the IP addresses in the access.log of your website though. Just look search for the string admincp in the access.log.

ForceHSS 07-23-2014 04:26 PM

Quote:

Originally Posted by RichieBoy67 (Post 2507936)
Hey, you're supposed to be recuperating man!:D

I know, but answering a few questions won't hurt besides, I miss helping. If I can help one or two people a day or a week with a quick answer it makes me feel I am not useless.

RichieBoy67 07-23-2014 04:40 PM

Quote:

Originally Posted by ForceHSS (Post 2507946)
I know, but answering a few questions won't hurt besides, I miss helping. If I can help one or two people a day or a week with a quick answer it makes me feel I am not useless.

I hear you mate. You will be back to 100% soon. All the best!

ForceHSS 07-23-2014 05:02 PM

The doctor said it normally takes 7 months to a year, but as mine was bad he said it might be closer to the year or a little over it, but it depends on many factors but I am not sure how much over a year it will be. My attack was bad some damage to the bottom of my heart this is why I went into the op a few hours after my attack. In 3 months I will be going to cardiac rehabilitation so not sure what will happen there this hope it helps will know more then

ozzy47 07-23-2014 06:37 PM

Quote:

Originally Posted by RichieBoy67 (Post 2507936)
Hey, your supposed to be recuperating man!:D

--------------- Added 23 Jul 2014 at 12:36 ---------------



I know you do this stuff alot but wow! You finally turned into files? lol

Great mod btw!

I also use the admin firewall which lets certain ips in. That combo is rock solid.

Lol that's what I get for typing on my phone.

cellarius 07-24-2014 07:46 AM

Quote:

Originally Posted by DreadsUK (Post 2507926)
The default was set to '0' for all over usergroups accept for admin. someone has definitely changed it.

No. 180 is default for Admin usergroup, it's the only ug this feature is activated by default. If you did not change it to 0 manually at some point (which I doubt, since you did not even know that setting), it is perfectly normal, and not a sign anyone hacking your forum.

obglobal.net 07-24-2014 11:43 AM

Quote:

Originally Posted by ForceHSS (Post 2507950)
The doctor said it normally takes 7 months to a year, but as mine was bad he said it might be closer to the year or a little over it, but it depends on many factors but I am not sure how much over a year it will be. My attack was bad some damage to the bottom of my heart this is why I went into the op a few hours after my attack. In 3 months I will be going to cardiac rehabilitation so not sure what will happen there this hope it helps will know more then

Just browsed through this thread and saw this.

Hope you're all good there, mate.

ForceHSS 07-24-2014 11:52 AM

Quote:

Originally Posted by obglobal.net (Post 2508096)
Just browsed through this thread and saw this.

Hope you're all good there, mate.

Thanks for asking trying to take one day at a time and trying to be stress free. Here is the one I made two days ago if you have not seen it yet.


All times are GMT. The time now is 04:19 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01233 seconds
  • Memory Usage 1,762KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (14)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (19)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete