Quote:
Originally Posted by AramisErak
Did you remember to change your passwords to both the server and the bbs after the rollback?
If they're changing the unmodifiable users list, it sounds like they hacked into the server, not just the BBS, at which point they could manually hack the config file where you set the umodifiable users.
You may wish to ask your hosting provider to check the server for exploit code as well.
If that config file is set to mod 777, ( -rwxrwxrwx), you probably should log into a terminal to the server, and chmod the file to 555 (-r-xr-xr-x).
|
it's not 777, it was 644, should it be 555?
they hacked the site again. they know the name of the new sql database i made (it was named after the hacker) and his first move was to change my email address (the name he made up referenced the sql db name i made, trying to send a message or whatever) to a yopmail and i presume begin a password reset. config says i, the admin (#1) am an unmodifiable user...
how could he know the db name? should config be 555d?
how do i disable the password reset function in the interim?