forum hacked!
Some damn newb got ahold of an admin password and proceeded to make numerous changes to my forum. I have everything listed in the logs, but it does not say exactly WHAT he did, only the script and action are listed. For example he changed around several user profiles, but it lists the users as numbers, not by name, but the member search does not have an option to search by number! How can I find out who these members are?
He changed forum permissions, altered usergroups, did something with options.php, he modified templates, he also screwed with css.php and cronadmin.php. What the hell feature of the board is cronadmin?
I eliminated all admins except myself, I installed 3.5 RC1 and reverted all the templetes to stock. I think he added some redirect code to snag peoples passwords in the templates. Some of my members were complaining of being sent to another website with IE exploits. I would not have caught him today if he hadn't gotten greedy and given himself an avatar (a privelage for staff only). The templates and css changes I can fix, what worries me is that entry for cronadmin.php and the action was modify. How can I find out what was modified, or where such modifications can be done?
|