Go Back   vb.org Archive > Community Central > Community Lounge

Reply
 
Thread Tools Display Modes
  #11  
Old 01-30-2009, 05:34 PM
UncoderMom UncoderMom is offline
 
Join Date: May 2006
Location: My office chair!
Posts: 567
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Oooh come on now Adrian!! You know me WAY better then to ever think I'd take that advise! LOL Though I do suppose I should uninstall the disabled blog I just dont want to loose that data. VB makes a converter for it now. Just havent had time or money to lay down on it.

Actually I need to do some serious clean up!! Pick through all my directories and remove suspects that are from old mods... I saw a few floating around yesterday. Examine all files that have an old upload dates too. Make sure there are no upgrades to it etc...

Thanks again for your help too Adrian.
Reply With Quote
  #12  
Old 01-30-2009, 05:57 PM
KTBleeding's Avatar
KTBleeding KTBleeding is offline
 
Join Date: Feb 2004
Location: Tooele, UT
Posts: 756
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Take it as a good thing. A surprising amount of "script kiddies" are doing this for your own good. They didn't take down your site with immense damage, and they could have. Easily. Some will even put their email and how to contact them.. I've actually heard of them responding and telling the person how they got in, and how to prevent it.

It's a pain in the neck, of course.. and we would all like a heads up email over the defacement of our sites.. but then again, would we listen to emails or just ignore them? Sometimes it takes something like this to grab our attention and do something about it..
Reply With Quote
  #13  
Old 01-30-2009, 07:03 PM
UncoderMom UncoderMom is offline
 
Join Date: May 2006
Location: My office chair!
Posts: 567
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

uuuh thats like a warped way of looking at it. Its an invasion of privacy. Its like breaking into someones house and waiting for them in the kitchen and saying haha I got in... guess you better use a better lock... I'm doing you a favor.. I could have been a real bad guy. BS LOL No offense. NO ONE, ABSOLUTELY NO ONE has the right to violate some ones server "for there own good". Man I could lay so many analogies on that one but I'll spare you! haha

I dont care if it was for my own good or for sick personal reasons. Someone should put their asses in jail.. that would be for their own good for damaging my goods. Pay me restitution too... yeah that.

haha Now THAT would be good for me. LOL

Anyway... if you google my hackers, you'll see it was anything but to "help me". More like internet terrorism!
Reply With Quote
  #14  
Old 01-30-2009, 07:16 PM
KTBleeding's Avatar
KTBleeding KTBleeding is offline
 
Join Date: Feb 2004
Location: Tooele, UT
Posts: 756
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well, I'm not justifying their actions by any means, I guess I should have made that clear. I'm just saying to take it as a good learning experience. You've now learned from a massive mistake as being an internet real estate holder.

Sure, we can come up with countless amounts of analogies if we want.. but we all know what they're doing isn't right, so it's kind of pointless. The fact that these exist more than someone breaking into your house and robbing you is because of the lovely anonymity of the internet. They can get away with it, and they know it. There's a far greater risk by breaking into someones house.

Leaving xss vulnerabilities in your sites is more than just having a bad lock on your door. It's leaving your door wide open with a HUGE sign above your house that says, "Hey, I am not home right now and I have thousands of dollars worth of crap you can come take."

Again, I'm not justifying these actions.. I've had my site defaced once years ago, and I felt extremely violated, as any normal person would. It is a sad thing that they get away with doing this, but because of them I run my sites with extreme caution and security. I took it as a learning curve, it wasn't as bad as it potentially could have been and for that I was thankful.
Reply With Quote
  #15  
Old 01-30-2009, 07:48 PM
UncoderMom UncoderMom is offline
 
Join Date: May 2006
Location: My office chair!
Posts: 567
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by KTBleeding View Post
Well, I'm not justifying their actions by any means, I guess I should have made that clear. I'm just saying to take it as a good learning experience. You've now learned from a massive mistake as being an internet real estate holder.

Sure, we can come up with countless amounts of analogies if we want.. but we all know what they're doing isn't right, so it's kind of pointless. The fact that these exist more than someone breaking into your house and robbing you is because of the lovely anonymity of the internet. They can get away with it, and they know it. There's a far greater risk by breaking into someones house.

Leaving xss vulnerabilities in your sites is more than just having a bad lock on your door. It's leaving your door wide open with a HUGE sign above your house that says, "Hey, I am not home right now and I have thousands of dollars worth of crap you can come take."

Again, I'm not justifying these actions.. I've had my site defaced once years ago, and I felt extremely violated, as any normal person would. It is a sad thing that they get away with doing this, but because of them I run my sites with extreme caution and security. I took it as a learning curve, it wasn't as bad as it potentially could have been and for that I was thankful.
It was definitely a learning experience. Well, I've seen it so many times happen to other people I didnt even get all panicky. I guess the only panic was the thought of having to restore the DB LOL. That and i dont "do" shell stuff. LOL Well not that I couldnt just I seem to have some pretty good friends that always seem to do that stuff for me, that and a great host. Perhaps I should have learned that stuff myself... Instead of letting someone bail me out there. LOL

Put that on my list.. Learn to decipher shell logs. haha
Reply With Quote
  #16  
Old 01-30-2009, 08:14 PM
calumn calumn is offline
 
Join Date: Nov 2007
Location: Scotland
Posts: 34
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You should try out bqbackup.

Its rsync and backs up your whole server including databases, files, emails, everything. It can be set to run automatically daily and only moves changed files.

So on my first day it moved about 10gb of all files but after that it was only a little each day and I don't need to do anything. Its only a couple of dollars a month.
Reply With Quote
  #17  
Old 02-01-2009, 12:45 AM
GSeybold GSeybold is offline
 
Join Date: Dec 2007
Posts: 473
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

First Unimomma
I'm super sorry this happened to you and I'm also jealous of your extensive computer knowledge. You go girl!

Second, is there ANY way at all to trace these Mo Fos? My company traced some spammers all the way to a major company so I did have legal recourse if I had elected to file a lawsuit (disruption of ecommerce is a federal felony). I contacted the CEO and had a "friendly" officer to officer chat. Amazingly, this CEO denied any knowledge (cough cough-yeah right), But after that call, all these spammers stopped. Humm.. what a surprise eh? Not!

I know my spammers situation isn't anywhere near as awful as being hacked but can you somehow get some info on these morons?

Could they have found the thread about Joomla and then went to your site you have listed on Vb.org? Could this have been from a vb.org member? I hope to hell not.

Gabby
Reply With Quote
  #18  
Old 02-05-2009, 05:08 PM
GSeybold GSeybold is offline
 
Join Date: Dec 2007
Posts: 473
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hello
I didn't want to make another post but I'm wondering if I've been hacked some how.

My newbie posts are alll moderated but yesterday a newbie posted several times and his posts were'n't moderated and went directly online. I've rechecked all permissions and they are ok.

Can someone advise.

I'm sorry I don't mean to hijack this thread but didn't want to start a new one .

Thanks

Gabby
Reply With Quote
  #19  
Old 02-05-2009, 05:38 PM
UncoderMom UncoderMom is offline
 
Join Date: May 2006
Location: My office chair!
Posts: 567
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Gabby, check this post for help... IS that the same thing you got going on??

https://vborg.vbsupport.ru/showthread.php?t=204103
Reply With Quote
  #20  
Old 02-05-2009, 06:07 PM
GSeybold GSeybold is offline
 
Join Date: Dec 2007
Posts: 473
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thank you Uni

I checked out that thread and my members are staying in their respective catagories but this one member's post aren't being moderated at all and they should be because he's in the moderated catagory. I created a test newbie account and it worked fine, all my test posts went to the mod que but this particular member's posts aren't. . So it's isn't a mod issue either. I asked my three mods if they approved the thread and they all said no. The post doesn't have any record of being approved. I am the only admin as well.

The member also put as a referrer someone who hasn't even been active on the forum in over a year. I watched as the person navigated my forum and they went to many threads and stayed only for a few seconds.

They posted a post which are consistant with my forum's subject but vague.

I'm pretty sure this isn't good and not sure what the next step is for me. I just want to avoid any more hassles.

I'm runing 3.72 pl 1

Gabby

--------------- Added [DATE]1233866440[/DATE] at [TIME]1233866440[/TIME] ---------------

Ok I have another newbie just now, I happened to be looking who's online. It says this person(?) went right to "Private Messages" per who's online. BUT my newbies do not have Private Messaging privledges and PMs don't even come up as an option in a newbie's control panel?

What they heck?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:13 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04422 seconds
  • Memory Usage 2,276KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete