Quote:
Originally Posted by MrZeropage
Shoutcast is a service installed on your server, if you do not secure this or set it up correctly, it could put a hole in your server...
ibProArcade is being used by >1500 users and online for about one year now in this codebase, so I think if there would be such a problem with it, it would be discovered more early  and again I can state that ibProArcade has no code that writes new accounts in the userDB
You have vBulletin 3.6.1 (or 3.6.2) installed to make sure this is no older vBulletin-Exploit ? You have setup everything correct so that spambots ect. don't have a chance ?
Scott (vBulletin-Support) also told
The Logs you quoted from your Server also give good details:There is some data directly being sent to your register.php which is part of your vBulletin.
Maybe you have some Modification/Hack that is using a PlugIn in register.php then you should check this...
btw I am not offended by your posting, but I want to avoid that anybody looking here and reading this could ever think "Huh, better don't touch ibProArcade, it seems to be unsecure" which it definatly is not 
|
Thanks for the post, as I posted on vbulletin the hacks I have installed on the vbulletin 3.61 are ;
Quote:
ibProArcade for vBulletin 2.5.6 ibProArcade - professional Arcade System for vBulletin
Edit Disable Export Uninstall
Log Logins Hack 2.0 Log Logins Hack
Edit Check Version Disable Export Uninstall
Members who have visited the forum 4.21 Display members who have visited the forum.
Edit Disable Export Uninstall
Miserable Users 2.05 A way to really annoy anyone you don't want visiting your forum.
Edit Disable Export Uninstall
Multiple Login Detector 1.03 Cookie-based multiple account login detector
Edit Disable Export Uninstall
PM Workbench 1.00 Beta 5 Toolset for managing PM's
Edit Disable Export Uninstall
PM Workbench - Performance Pack 1.00 Beta 1 Add extra indexes to your tables to improve performance
Edit Disable Export Uninstall
PM Workbench - Read/Search Private Messages 1.00 Beta 4 PM Workbench module to be able to read and search members Private Messages
Edit Disable Export Uninstall
PM Workbench - Report PM 1.00 Beta 1 Adds the option for members to report an abusive PM.
Edit Disable Export Uninstall
Shoutcast Status Full 1.9 Shoutcast Status Full 1.9
Edit Enable Export Uninstall
vB Spell 0.10.2b vB Spell allows you to provide a spell checking window through your editor interface.
Edit Disable Export Uninstall
vBadvanced CMPS 2.2.0 vBadvanced Content Management & Portal System
Edit Disable Export Uninstall
Welcome Headers 4.1.0 Boost registration and activity rates with more visible guest welcome and member status messages.
|
Since I uninstalled shoutcast and this hack there was one more attempt to registered and they failed. Maybe that is coincidence, as I noticed before they succeded several attempts that failed.
Considering you are a coder, couldd you tell me what hack of the ones posted you would think that intereacts with register.php. Another member on the thread that I posted in vbulletin identified only one hack on both our forums Log Logins Hack 2.0. I just cannot see how they could use this hack to send data to register.php.
Sorry again, just want to get to the bottom of this, if you like send me a pm with your suggestions. That way we do not pollute your thread with off topic stuff.
Thanks