Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions

Reply
 
Thread Tools Display Modes
  #1  
Old 06-19-2006, 05:06 PM
Krahl Krahl is offline
 
Join Date: Aug 2005
Posts: 95
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default These hackers have me fed up!

Hi folks,

I'm in need of some advice and help, really.

I was having a few issues with someone hacking an admin account (they apparently took control of more than just that one account) on a site I admin which was running 3.5.3. We had a running battle for a few weeks. After I upgraded to 3.5.4, the attacks stopped for a few days. They then started back up. All along, all the person(s) were doing was changing (defacing) forumhome.

That changed finally, as they have now deleted my forum structure and posts as well as defaced the front page, forumhome and I don't know what all else (that seems to be all though). They created three new forums and one post, concerning a muslim political commentary.

I have a backup of the database (one week old) and my host can also restore it from last week if need be. I have the server access logs as well as my ACP logs. The site is currently turned off until I figure out how to stop these attacks.

I'm wondering if anyone has suggestions at this point for what I should do? I might be interested in getting some help as well, perhaps someone to look it over and also help restore the database properly.

Any input would be greatly appreciated.

Reply With Quote
  #2  
Old 06-19-2006, 05:14 PM
Sean S's Avatar
Sean S Sean S is offline
 
Join Date: Jan 2004
Location: Chicago
Posts: 301
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

this post has some good points related to your question, it should help a lot https://vborg.vbsupport.ru/showthread.php?t=118613
Reply With Quote
  #3  
Old 06-19-2006, 05:18 PM
Krahl Krahl is offline
 
Join Date: Aug 2005
Posts: 95
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for the link Sean. I've read through that prior and have done some of the things recommended therein.

I'm having a hard time figuring out how the heck they keep getting control. I would really like to get some resolution wiithout reinstalling the entire board from scratch too, but I'm not sure where to look at this point. I do have the server logs too, but cripes, it's huge and I actually am not even sure what to look for in it.

Reply With Quote
  #4  
Old 06-19-2006, 09:08 PM
GE-Biggs GE-Biggs is offline
 
Join Date: Dec 2005
Posts: 8
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Incase you overlook the new replies to that other thread.

Heres one idea, if you do everything correct, and follow the suggestions given in this thread, and it still happens again, you might try to check you pc for any tojans, keyloggers, etc. that is assuming that you havent already.. You never know it could be something as simple as your PC being compromised, wouldn't be the first time that has happened to someone.
Reply With Quote
  #5  
Old 06-20-2006, 01:22 AM
Ntfu2 Ntfu2 is offline
 
Join Date: Feb 2006
Posts: 1,247
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Move servers, maybe your server is completely unsecure, may i ask who you host with?
Reply With Quote
  #6  
Old 06-20-2006, 01:27 AM
Krahl Krahl is offline
 
Join Date: Aug 2005
Posts: 95
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by GE-Biggs
Incase you overlook the new replies to that other thread.

Heres one idea, if you do everything correct, and follow the suggestions given in this thread, and it still happens again, you might try to check you pc for any tojans, keyloggers, etc. that is assuming that you havent already.. You never know it could be something as simple as your PC being compromised, wouldn't be the first time that has happened to someone.

Thanks for the ideas GE-Biggs.

Ntfu2, I don't think it's the host. I've been using them for a few years with various accounts as well as recommending them to others, who have had no problems. The host I use is midphase.com. They're typically right on top of all service issues I've ever had.

Although, I will say that their fee of $30 for backup restoration has me a bit irked. Is that typical with other hosts?
Reply With Quote
  #7  
Old 06-20-2006, 01:34 AM
FLMom's Avatar
FLMom FLMom is offline
 
Join Date: Feb 2006
Location: Florida
Posts: 386
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

They charged you $30? I had to have mine restored because I goofed it up when I first got it and mine didn't charge me a thing.

I hope someone here can help you get your site more secure..good luck with it.
Reply With Quote
  #8  
Old 06-20-2006, 01:51 AM
Krahl Krahl is offline
 
Join Date: Aug 2005
Posts: 95
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yeah, I think that's a bit cheesy to charge for it. They didn't use to. Only thing I can complain about with their service though.

I haven't had them do it yet though, as I'm trying to figure out how to use my sql database backup (the one from the acp) to sort the site. Can't get that figured out just yet though. I can't find the "browse" button from the SQL area in phpmyadmin. vb docs as well as the tutorial on here say it's there but I simply cannot find it. Frustrating to say the least. Meanwhile time goes by as the site is down. :\

Thanks for the positive thoughts FLMom.
Reply With Quote
  #9  
Old 06-20-2006, 02:00 AM
FLMom's Avatar
FLMom FLMom is offline
 
Join Date: Feb 2006
Location: Florida
Posts: 386
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You are welcome! Wish I could help more, but its all too new to me.
Reply With Quote
  #10  
Old 06-23-2006, 06:12 PM
kira kira is offline
 
Join Date: Oct 2001
Location: NYC
Posts: 160
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

How do you know their religion???
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 03:59 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04290 seconds
  • Memory Usage 2,251KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete