Quote:
Originally Posted by CarolSEL
A new member registered at our forum, then somehow made himself an Admin. (Obviously, we banned him and his IP.)
How can that happen? What precautions do we need to take?
|
If the hacker gains access to the database they can alter their membergroup id #, if they have access to ftp (files) they can also assign themselves as a Super-Administrator per the config file - it's easy IF they have access but basically simply FTP access would allow you to also upload a file and interact with the database directly w/o the need for phpmyadmin or similar.