vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   These hackers have me fed up! (https://vborg.vbsupport.ru/showthread.php?t=119048)

Krahl 06-19-2006 05:06 PM

These hackers have me fed up!
 
Hi folks,

I'm in need of some advice and help, really.

I was having a few issues with someone hacking an admin account (they apparently took control of more than just that one account) on a site I admin which was running 3.5.3. We had a running battle for a few weeks. After I upgraded to 3.5.4, the attacks stopped for a few days. They then started back up. All along, all the person(s) were doing was changing (defacing) forumhome.

That changed finally, as they have now deleted my forum structure and posts as well as defaced the front page, forumhome and I don't know what all else (that seems to be all though). They created three new forums and one post, concerning a muslim political commentary.

I have a backup of the database (one week old) and my host can also restore it from last week if need be. I have the server access logs as well as my ACP logs. The site is currently turned off until I figure out how to stop these attacks.

I'm wondering if anyone has suggestions at this point for what I should do? I might be interested in getting some help as well, perhaps someone to look it over and also help restore the database properly.

Any input would be greatly appreciated.

:)

Sean S 06-19-2006 05:14 PM

this post has some good points related to your question, it should help a lot https://vborg.vbsupport.ru/showthread.php?t=118613 :)

Krahl 06-19-2006 05:18 PM

Thanks for the link Sean. :) I've read through that prior and have done some of the things recommended therein.

I'm having a hard time figuring out how the heck they keep getting control. I would really like to get some resolution wiithout reinstalling the entire board from scratch too, but I'm not sure where to look at this point. I do have the server logs too, but cripes, it's huge and I actually am not even sure what to look for in it.

:confused:

GE-Biggs 06-19-2006 09:08 PM

Incase you overlook the new replies to that other thread.

Heres one idea, if you do everything correct, and follow the suggestions given in this thread, and it still happens again, you might try to check you pc for any tojans, keyloggers, etc. that is assuming that you havent already.. You never know it could be something as simple as your PC being compromised, wouldn't be the first time that has happened to someone.

Ntfu2 06-20-2006 01:22 AM

Move servers, maybe your server is completely unsecure, may i ask who you host with?

Krahl 06-20-2006 01:27 AM

Quote:

Originally Posted by GE-Biggs
Incase you overlook the new replies to that other thread.

Heres one idea, if you do everything correct, and follow the suggestions given in this thread, and it still happens again, you might try to check you pc for any tojans, keyloggers, etc. that is assuming that you havent already.. You never know it could be something as simple as your PC being compromised, wouldn't be the first time that has happened to someone.


Thanks for the ideas GE-Biggs.

Ntfu2, I don't think it's the host. I've been using them for a few years with various accounts as well as recommending them to others, who have had no problems. The host I use is midphase.com. They're typically right on top of all service issues I've ever had.

Although, I will say that their fee of $30 for backup restoration has me a bit irked. Is that typical with other hosts?

FLMom 06-20-2006 01:34 AM

They charged you $30? I had to have mine restored because I goofed it up when I first got it and mine didn't charge me a thing.

I hope someone here can help you get your site more secure..good luck with it.

Krahl 06-20-2006 01:51 AM

Yeah, I think that's a bit cheesy to charge for it. They didn't use to. Only thing I can complain about with their service though.

I haven't had them do it yet though, as I'm trying to figure out how to use my sql database backup (the one from the acp) to sort the site. Can't get that figured out just yet though. I can't find the "browse" button from the SQL area in phpmyadmin. vb docs as well as the tutorial on here say it's there but I simply cannot find it. Frustrating to say the least. Meanwhile time goes by as the site is down. :\

Thanks for the positive thoughts FLMom. :)

FLMom 06-20-2006 02:00 AM

You are welcome! Wish I could help more, but its all too new to me.

kira 06-23-2006 06:12 PM

How do you know their religion???


All times are GMT. The time now is 03:35 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01109 seconds
  • Memory Usage 1,736KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete