Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 08-21-2007, 07:21 PM
GoHorns123 GoHorns123 is offline
 
Join Date: Aug 2007
Posts: 22
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Secure database?

We had a admin flip out on us. She deleted a bunch of stuff to our board, and we have gotten all that back. I have a weird feeling that she can still get in our database and need to know what steps I should take to make sure that she can't get in anymore. Can anyone tell me what the first step I should take to make sure that our database is secure?

And I know this is going to sounds kinda out there- but she made a new board has the same software and everything that we do. Is there anyway she could be somehow connected or mirroring us? Everytime we're down, her board goes down to. I didn't know if that was possible, so I though I would just ask the people who might know.
Reply With Quote
  #2  
Old 08-21-2007, 07:46 PM
Kirk Y's Avatar
Kirk Y Kirk Y is offline
 
Join Date: Apr 2005
Location: Tallahassee, Florida
Posts: 2,604
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Change out all the database connection information in your /includes/config.php file, if you use cPanel (or its equivalent) and she had access to that, change the password, etc.
Reply With Quote
  #3  
Old 08-21-2007, 08:29 PM
GoHorns123 GoHorns123 is offline
 
Join Date: Aug 2007
Posts: 22
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I changed all of these in the config file.. Is there anything else in the config file that might need to be changed or is this it? I have also changed the Cpanel passwords.

master database username and password.

USERS WITH ADMIN LOG VIEWING PERMISSIONS

USERS WITH ADMIN LOG PRUNING PERMISSIONS

USERS WITH QUERY RUNNING PERMISSIONS

UNDELETABLE / UNALTERABLE USERS

SUPER ADMINISTRATORS

What should the next step be?

Are there any htaccess passwords I need to change anywhere? I know this girl is sneaky, and want to make sure I cover all by bases.
Reply With Quote
  #4  
Old 08-21-2007, 08:35 PM
Kirk Y's Avatar
Kirk Y Kirk Y is offline
 
Join Date: Apr 2005
Location: Tallahassee, Florida
Posts: 2,604
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Did she have access to your FTP or cPanel before you changed out all the Passwords?
Reply With Quote
  #5  
Old 08-21-2007, 08:37 PM
GoHorns123 GoHorns123 is offline
 
Join Date: Aug 2007
Posts: 22
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yes, she had access to everything. She's the one that installed all the hacks, she ran the board. I'm just learning how to do this since she flipped out.
Reply With Quote
  #6  
Old 08-21-2007, 08:46 PM
Kirk Y's Avatar
Kirk Y Kirk Y is offline
 
Join Date: Apr 2005
Location: Tallahassee, Florida
Posts: 2,604
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It's possible she may have modified any number of your core PHP files; you may want to consider re-uploading fresh copies of them from the vB.com Member's Area.

Keep in mind that in doing this, you could be undoing any modifications to files that may have been required for a modification to function properly.
Reply With Quote
  #7  
Old 08-21-2007, 08:57 PM
GoHorns123 GoHorns123 is offline
 
Join Date: Aug 2007
Posts: 22
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Oh my, sounds like something hard, but I have to make sure that she can't get in anymore. Can I just change the number of the core php files to what they are supposed to be? Or would it be easier to upload the fresh ones?
Reply With Quote
  #8  
Old 08-21-2007, 09:12 PM
Kirk Y's Avatar
Kirk Y Kirk Y is offline
 
Join Date: Apr 2005
Location: Tallahassee, Florida
Posts: 2,604
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Sorry - change the number of the files? Not sure what you mean.
Reply With Quote
  #9  
Old 08-21-2007, 09:17 PM
GoHorns123 GoHorns123 is offline
 
Join Date: Aug 2007
Posts: 22
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

No, it's not you. It's me, sorry.

I thought you were talking about changing the numbers for the change file permissions. Hope I'm making sense.
Reply With Quote
  #10  
Old 08-21-2007, 09:25 PM
Kirk Y's Avatar
Kirk Y Kirk Y is offline
 
Join Date: Apr 2005
Location: Tallahassee, Florida
Posts: 2,604
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Oh, no, I'm not talking about the file permissions - I'm talking about the actual files themselves. If you go into your AdminCP -> Maintenance -> Diagnostics -> Suspect File Versions; you can see any files that aren't native to vBulletin or have been changed from their default form.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 03:15 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04360 seconds
  • Memory Usage 2,246KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete