vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Forum hacked, version 4.0.6 Patch Level 4 (https://vborg.vbsupport.ru/showthread.php?t=282723)

pzet 05-10-2012 07:32 AM

Forum hacked, version 4.0.6 Patch Level 4
 
Hello,

Just found this morning that my forum was hacked. All IP's in "who is online" point to one and the same IP-address: 194.1.150.194
The last registration attempt comes from this IP. From what I can remember few days ago someone with the same email address was trying to register from a Russian IP address.

I am using the advanced IP manager as well as the stop forum spam addon - I banned the initial IP address from registering.

Can anyone help please.
Thanks
Peter

deadlySniper 05-10-2012 07:53 AM

I know for one, I would upgrade. Second, have you banned the IP? Also, I usually would ask my host to ban certain countries. I was having issues with turkish spam, so I had the country blocked.

pzet 05-10-2012 08:03 AM

I am running the latest available security patch (for version 4.0.6) so from that end it should be fine.

To ban certain countries won't really help. By using the Tor browser a hacker can attack virtually from any country.

deadlySniper 05-10-2012 08:10 AM

The only thing I can think of, is that the version you have is not secure. I know when I was running 3.8.4 with PL. They released 3.8.5 which fixed more security issues that the previous patch level didnt fix. Also do you allow same IP registrations or duplicate registrations?

pzet 05-10-2012 08:29 AM

no duplicate registrations allowed.

deadlySniper 05-10-2012 08:32 AM

My other thought is, did the person actually hack? Like did they get any admin? It could just be the person registering multiple accounts.

pzet 05-10-2012 08:34 AM

No, that user was blocked - no registration.

There must be another loop hole to access the database.

borbole 05-10-2012 10:12 AM

Quote:

Originally Posted by pzet (Post 2327929)
I am running the latest available security patch (for version 4.0.6) so from that end it should be fine.

To ban certain countries won't really help. By using the Tor browser a hacker can attack virtually from any country.

No, it is not fine. As there are many security issues found in the later versions that affect your version as well. The best thing would be to upgrade to the latest stable version.

That said, can you ask your host to check their access logs for around the time of the hack and see what happened and how it did happen? That would help in identifying the point of entry and patch it up.

cellarius 05-10-2012 10:42 AM

Quote:

Originally Posted by pzet (Post 2327923)
Hello,

Just found this morning that my forum was hacked. All IP's in "who is online" point to one and the same IP-address: 194.1.150.194

This is an IP address in Great Britain, belonging to Global Gold Network Provider. Any chance you're hosting with them?

Make sure your provider did not make any settings to his proxy, firewall or other network related setup. If IPs are not passed properly, all your users/guests will show as having the IP address of the proxy.

pzet 05-10-2012 10:52 AM

Quote:

Originally Posted by cellarius (Post 2327967)
This is an IP address in Great Britain, belonging to Global Gold Network Provider. Any chance you're hosting with them?

Make sure your provider did not make any settings to his proxy, firewall or other network related setup. If IPs are not passed properly, all your users/guests will show as having the IP address of the proxy.

Thanks for your reply. Yes I am hosting my forum with Globalgold.
Just contacted the hoster, they are working on the issue.

Thanks


All times are GMT. The time now is 04:49 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.00991 seconds
  • Memory Usage 1,730KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete