Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
  #1  
Old 02-25-2009, 01:21 PM
Tenth Doctor's Avatar
Tenth Doctor Tenth Doctor is offline
 
Join Date: Oct 2008
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default vB 3.7.5 public threads archived by anon

It's not a board I own or run, but one i used to at one point several years ago. there was a bit of a ruckus in the group a few days ago and it split in half, one forming another group, and yesterday/today morning all public threads were archived. but there are no logs to show Admin doing it, no Mods were logged in at the time. and 3SuperMods logged in 2 Hours prior to the incident.

Basically what happened is someone went in an archived all publically visible threads. i haven't found an exploit that could do it, whether SQL or vB. Thought I'd ask here if anyone has any ideas.

Logically, if they wanted maximum damage they'd likely delete all threads if not archive all that are visible to logged in users... if they had all access... so I'm stumped, anyone has any ideas?
Reply With Quote
  #2  
Old 02-25-2009, 01:32 PM
ssslippy ssslippy is offline
 
Join Date: Jan 2006
Posts: 877
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

There is no archive feature in vb. So would need more detail.
Reply With Quote
  #3  
Old 02-25-2009, 01:33 PM
Tenth Doctor's Avatar
Tenth Doctor Tenth Doctor is offline
 
Join Date: Oct 2008
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Sorry. forgot to elaborate on that. basically there's a forum that's closed for new responses, but old threads get tossed in there.
Reply With Quote
  #4  
Old 02-25-2009, 01:45 PM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

What is the URL to this board?
Reply With Quote
  #5  
Old 02-25-2009, 01:51 PM
Tenth Doctor's Avatar
Tenth Doctor Tenth Doctor is offline
 
Join Date: Oct 2008
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I'm not sure. the URL was blocked by my ISP several years ago, I don't know if they've kept it the same or not. If you go to bravofleet.org or bravofleet.com there should be a link to the forums there.
Reply With Quote
  #6  
Old 02-25-2009, 02:27 PM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

This is done with a mass prune. Looking at the forum, i see old stickied threads, normal threads only from the last couple of days. The default for the Mass Prune is "all forums" & "not stickied" and this is how the board is now.

This should be visible in the Admin or Moderator log, unless the log was cleaned (from ACP or manual).
Reply With Quote
  #7  
Old 02-25-2009, 02:56 PM
Tenth Doctor's Avatar
Tenth Doctor Tenth Doctor is offline
 
Join Date: Oct 2008
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The Admins have been working on unarchiving old threads back to where they belong.

Also,, mass prune would catch threads that are visible even if you're logged in (there were things like journals on there , only visible tomembers logged in), this one caught just the threads that were visible to public without logging in.

They've checked the logs, there's nothing to indicate that it was done by an admin or a mod, there is only one admin who has permission to clean logs, and he's as stumped by this one as I am.
Reply With Quote
  #8  
Old 02-25-2009, 03:08 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Have you checked the access_logs from around that time?
Reply With Quote
  #9  
Old 02-25-2009, 03:11 PM
nexialys
Guest
 
Posts: n/a
Default

it's easy to have coded a cronjob with no log at all... no admin access to execute the task...

i've done it already, it's a 30 seconds copy of an existing cron... changing one query and loading it back in the ftp... (so basically, someone with ftp access can edit the daily cron and change it to execute that cleanup, no trace in the logs whatsoever)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 05:49 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04189 seconds
  • Memory Usage 2,218KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (9)post_thanks_box
  • (9)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (9)post_thanks_postbit_info
  • (9)postbit
  • (8)postbit_onlinestatus
  • (9)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete