Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions

Reply
 
Thread Tools Display Modes
  #1  
Old 10-26-2002, 02:38 PM
Rapdis's Avatar
Rapdis Rapdis is offline
 
Join Date: Mar 2002
Posts: 122
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Serious Problem

I have been making posts now and again about bandwidth problems with my forum.

Now there is a SERIOUS PROBLEM

I closed the forum but yet there are 5 guests viewing it, this tells me sum1 has hacked it and leaching bandwidth, there is a security problem with the forum sumwhere.

i only have 700 members and my count is 44gb of bandwith this month.

This is now obvious abuse from a proff hacker.

The admin and tech staff need to get involved and help me, also help others who might experience this problem.

It seems that all members are hacked, i know for instance that bad's back is not on the forum but yet according to the image i have attached, he is viewing it.

and so are a heap of people! but yet the forum is closed!

also notice the IP for the guests, its the same, i banned 208.237.238 but yet they are here.

notice how they are viewing avatars, i got a feeling they are refreshing it thousends of times...

i need help now, asap, i cant afford this, i paid for the licence and now hosting is costing me like £300 a month.

Someone, admin, please help.
Attached Images
File Type: jpg untitled.jpg (146.6 KB, 0 views)
Reply With Quote
  #2  
Old 10-26-2002, 03:33 PM
Rapdis's Avatar
Rapdis Rapdis is offline
 
Join Date: Mar 2002
Posts: 122
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have upgraded version 2.2.4 to 2.2.8

But the people are still there, and the person has changed his IP and still viewing avatars as you can see in the attachment.

also apparant bad's back is viewing a forum too, he is sat right next to me and is viewing nothing, how come all these people are viewing things when i have switched the forum off, there is a BIG problem somewhere.

I have also switched off the option in the usergroups so guests cant view the forum full stop...

What now?
Attached Images
File Type: jpg untitled.jpg (146.6 KB, 0 views)
Reply With Quote
  #3  
Old 10-26-2002, 03:35 PM
Rapdis's Avatar
Rapdis Rapdis is offline
 
Join Date: Mar 2002
Posts: 122
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I deleted misc.php in the meantime so avatars can't be shown
Reply With Quote
  #4  
Old 10-26-2002, 08:19 PM
Erwin's Avatar
Erwin Erwin is offline
 
Join Date: Jan 2002
Posts: 7,604
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

If you are absolutely sure you have closed your forum, then your forum is closed.

When a member tries to access any of the pages of the forum, Who's Online will say that they are looking at that page, but what they are really seeing is the "No Permission" page. So if I was you I wouldn't worry (unless you are certain that your site has been hacked). Even with the forum closed, vB still tells you the number of people who are trying to access each page.

If you're worried, open another window, log out, log in as a registered member on a test account and try any of the pages - see on Who's Online that vB tells you that a member is looking at a page when in reality the member is getting the "No Permission" page.
Reply With Quote
  #5  
Old 10-26-2002, 08:40 PM
NTLDR's Avatar
NTLDR NTLDR is offline
Coder
 
Join Date: Apr 2002
Location: Bristol, UK
Posts: 3,644
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally posted by Rapdis
I deleted misc.php in the meantime so avatars can't be shown
misc.php doesn't deal with displaying avatars, its forum/avatar.php
Reply With Quote
  #6  
Old 10-26-2002, 08:55 PM
Rapdis's Avatar
Rapdis Rapdis is offline
 
Join Date: Mar 2002
Posts: 122
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

but if you look carefully, its diff guests with same IP but with one number changed, and they using 44gb a month, so im sure something is wrong, what can i do?
Reply With Quote
  #7  
Old 10-26-2002, 09:20 PM
NTLDR's Avatar
NTLDR NTLDR is offline
Coder
 
Join Date: Apr 2002
Location: Bristol, UK
Posts: 3,644
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The 2 guests with different IPs could be the same user, if those IPs are proxy's then they may have hopped proxy whislt browsing your site, like AOL does for example.

The best way is to use .htaccess to block avatar.php, attachment.php, .gif, .jpg, .jpeg and .png if you have mod_rewrite enabled on your server.
Reply With Quote
  #8  
Old 10-26-2002, 11:10 PM
N9ne N9ne is offline
 
Join Date: Feb 2002
Posts: 1,495
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It is possible to use up 44GB per month...If you don't have GZIP enabled, allow free use of avatars, sigs, attachments, etc.

The main factor would be GZIP...
Reply With Quote
  #9  
Old 10-27-2002, 02:30 AM
Erwin's Avatar
Erwin Erwin is offline
 
Join Date: Jan 2002
Posts: 7,604
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Same IP means nothing. It could be a popular ISP, with many members of yours using the same proxy server used by that ISP (hence the large bandwidth), so by banning that one IP you are banning all these members.
Reply With Quote
  #10  
Old 10-27-2002, 03:04 PM
Rapdis's Avatar
Rapdis Rapdis is offline
 
Join Date: Mar 2002
Posts: 122
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally posted by NTLDR
The 2 guests with different IPs could be the same user, if those IPs are proxy's then they may have hopped proxy whislt browsing your site, like AOL does for example.

The best way is to use .htaccess to block avatar.php, attachment.php, .gif, .jpg, .jpeg and .png if you have mod_rewrite enabled on your server.
I dont have mod_rewrite enabled, what can i do now? i also think people are leaching images of the site, this might be a thing for V3.0, a inbuilt script that changes the name of the images folder and reflects that change across the forum, that would be fantastic.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:47 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06854 seconds
  • Memory Usage 2,275KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (2)postbit_attachment
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_attachment
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete