vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.5 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=113)
-   -   Cracker Tracker (https://vborg.vbsupport.ru/showthread.php?t=110030)

Onur 03-09-2006 10:00 PM

Cracker Tracker
 
CrackerTracker

this is a port from the standalone system of the Cback.de CrackerTracker (was original made for phpBB) to an Product for vB
  • Description
    this hack search in the requeststring for definied codeparts, is found any hit the skript was die and send a little massage
    in addition of security this simply skript discharged the server by automatic attacks from botskripts if the definations have a hit in the requests
  • Instructions
    Install
    • upload the /elog/ directory and set the CHMOD of counter.txt and logfile_injects.txt to 666, this is only to log blocked requests
      if you not want to have writeable files on youre server this hack works without logging too and you can leave this part
    • at last install the CrackerTracker100-product.xml
    Update
    • uninstall product of v100
    • reinstall new product of v101
    Uninstall
    • uninstall the CrackerTracker100-product.xml
    • upload thedelete /elog/ directory
  • Credits & Information
    i have only port this hack to a Plugin
    Authorof the Hack is Cback from www.cback.de
    only restraint of Cback is the Copyright in the footer

    (i hope my english was understandable :o )


  • History
    • 10/03/06 Release 1.0.0
    • 15/05/06 Release 1.0.1
      • new searchpattern and handfull old replaced
      • little codemodifications
    • 15/05/06 Release 1.0.2
      • one typo in list (missing ",")

XtremeOffroad 03-10-2006 08:57 PM

What does this do? Sorry didnt quite understand.

Highendfreak 03-10-2006 09:08 PM

Quote:

Originally Posted by XtremeOffroad
What does this do? Sorry didnt quite understand.

This hack protecs your board against people who wants to '(cr)hack your forum. Original coded by CBack for phpBB and now ported to vb. One of the best hacks ever...;)

Onur 03-10-2006 09:09 PM

phpBB have any problems with automated hacking attacks by botskripts was found her victim over google and send many requets to the board

this skript search for a lot of requets how '<skript>' and died the request, so the server has a littel less of load and an bad request can block befor he does work

is an similar way like the $_global handling of vb in begin of ini.php

redlabour 03-10-2006 09:43 PM

The best Hack from cBack in the whole phpBB World. Thx Onur - absolut excellent work ! :)

If anyone does not know cBack : http://www.community.cback.de/viewforum.php?f=52

@Onur - please edit a Link to cBack and the Title of this Hack to cBack CrackerTracker. And do not forget a link to vbhacks-germany etc. ;)

And sorry - but no one can understand your english description here. ;)

Quote:

This is a complete security system for phpBB2 Forums. It protects against session cracks, floods, search overloads, worm attacks, BruteForce Attacks, Mass Mailing and much more to reduce Traffic and to protect Board and other MODs.
http://sourceforge.net/project/showf...roup_id=154972

puertoblack2003 03-10-2006 09:47 PM

ok trying to understand, what this hack do is if someone or something tried to hack your board it will keep a log and then what slow server respond or what?????:confused: :confused: :confused:

Onur 03-11-2006 05:52 AM

Quote:

Originally Posted by puertoblack2003
ok trying to understand, what this hack do is if someone or something tried to hack your board it will keep a log and then what slow server respond or what?????:confused: :confused: :confused:

i mean, comes a automated hackingskript (santy-webworm) who sending many requets to youre board, this skript end the bulid and delivery of the requestet site and save so cputime and traffic
some hackingrequests have no chance to do there work on patched boards, but you have a lot of traffic

Trigunflame 03-11-2006 06:13 AM

What this guys trying to say is that his "addition" to your forum will kill the script if it notices any potential "bad request" are being sent to the forum.

1. Most of these request differ in "what they can do", showing phpinfo() is not going to help anyone own your server.
2. Vbulletin is not phpbb, and does not suffer from any of these problems to date.
3. If the request is being sent through a vbulletin php file they are not going to get executed anyway, this hack is Worthless on a Vbulletin Forum.

Motoman 03-11-2006 10:44 AM

Acording to our phpbb specialist (on "my" board) :

Quote:

Originally Posted by abcde
Just a note about the CrackerTracker by CBACK.DE, some staff members of phpbb.com have looked at this mod and say there are some serious security problems, the automatic update-system is according to them unsafe. This is the stand-alone of that phpBB mdo so I think you should look at this issue.

Edit: I don't know if this is ported version of the phpBB mod, my German isn't fluent. ;)

Will this hack have any negative effects on vB through the "automatic update-system" or was this problem fixed when you ported it?

Motoman 03-11-2006 11:01 AM

Quote:

Originally Posted by Motoman
Acording to our phpbb specialist (on "my" board) :



Will this hack have any negative effects on vB through the "automatic update-system" or was this problem fixed when you ported it?

oops, I didnt see the edit note, but I'd still like to know it that "automatic update-system will cause any trouble...


All times are GMT. The time now is 02:56 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01066 seconds
  • Memory Usage 1,741KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (5)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete