Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 02-09-2008, 12:22 PM
KempoMRK KempoMRK is offline
 
Join Date: Feb 2007
Posts: 29
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default A Hacker Deleted A Load Of Threads

Permanently as well. So there's no way to get them back. But anyway, that's not my question.

The hacker logged in as a supermod on the site and deleted a load of threads that way. Is there anyway to find out how they got the password? Or even if it was just the actual member and now he's lying?

IP's have been checked and whoever did it used a proxy. If it was brute forced would there be logs on the server?

The password was pretty unguessable and it had a number at the end as well, so I don't think it could have been guessed, and the member says that he's never told anyone his password.

Any replies would be appreciated, thanks.
Reply With Quote
  #2  
Old 02-09-2008, 12:49 PM
nexialys
Guest
 
Posts: n/a
Default

when you go to the moderator logs, you see who used the function AND the IP... if the IP fit the old actions, you sure know it is the same person...

this is INTERNAL management... we can't help you deal with your moderators... the simple act of banning him may or may not fix the problem, it's all to you.

there is no brute-force moderator actions in vbulletin, even if you dream of it... it is impossible to hack the system from the database, the data would be incoherent after that.
Reply With Quote
  #3  
Old 02-09-2008, 12:56 PM
KempoMRK KempoMRK is offline
 
Join Date: Feb 2007
Posts: 29
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The IP doesn't fit the actions, they were under a proxy, so it still could have been the same guy. And the mod seems like a cool guy so I'm thinking it's more likely to be a hacker, we just wanna make sure. Also, by brute forcing not working, do you mean from the outside? I meant someone could have tried brute forcing his vBulletin password.

Thanks for your reply man.
Reply With Quote
  #4  
Old 02-10-2008, 11:12 AM
stelthius stelthius is offline
 
Join Date: Jan 2008
Posts: 71
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

i beleive there is a Proxy to real IP mod/hack i say install it and move on wait for next time and in that time up your security htaccess make sure you know who has got that sort of access and keep a close eye on the logs about all you can do really, anyway good luck mate

Rick
Reply With Quote
  #5  
Old 02-10-2008, 11:15 AM
legionofangels's Avatar
legionofangels legionofangels is offline
 
Join Date: Mar 2007
Posts: 485
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I used that add on, and it doesn't always work. Not saying it's bad but we gave up on it.

My advice, only Admins can delete threads or posts, or even better, only admins can permanently remove.

I only allow 2 of 4 admins to permanently remove threads/posts and I'm one of them as owner so that it makes it kind of simple to know if we've been hacked or not.
Reply With Quote
  #6  
Old 02-10-2008, 11:16 AM
MiahBeSmokin420 MiahBeSmokin420 is offline
 
Join Date: May 2007
Location: Ohio
Posts: 311
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

yep proxie to real ip and then add the proxie redirect you will never have another problem again

then add in that one shit whats it called the AE mutipule login dectctor and multiple login ban

you will nerver have another problem with people again ban them and then there gone

ive banned over 25 people from my site fro doing dumb ass shit and the tried for about 2 days to get back on the site and they couldnt get bake on

so ya just search the site for them things and you should be good to go

but i got to go update my vb
Reply With Quote
  #7  
Old 02-10-2008, 04:59 PM
slappy slappy is offline
 
Join Date: Apr 2003
Posts: 97
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Have you considered the possibility of restoring a back-up which might contain the deleted Threads? If you backup on a daily basis, this should be possible. Then you would only loose those threads between the backup time and when you restore the backup.

Just a thought.

Regards,
Reply With Quote
  #8  
Old 02-10-2008, 05:59 PM
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Location: Nottingham, UK
Posts: 23,748
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by legionofangels View Post
I used that add on, and it doesn't always work. Not saying it's bad but we gave up on it.
It only works if the proxy server passes on the original IP details. Hackers would (obviously) use proxy servers that do not.
Reply With Quote
  #9  
Old 02-10-2008, 07:26 PM
KempoMRK KempoMRK is offline
 
Join Date: Feb 2007
Posts: 29
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by slappy View Post
Have you considered the possibility of restoring a back-up which might contain the deleted Threads? If you backup on a daily basis, this should be possible. Then you would only loose those threads between the backup time and when you restore the backup.

Just a thought.

Regards,
The main owner of the site came on and luckily he had a backup from the day before, so all the important stuff was restored.

We still can't work out who did it though. I'll look into the proxy unveiler thingy.

Thanks to everyone else for the replies.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 11:33 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04375 seconds
  • Memory Usage 2,238KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (9)post_thanks_box
  • (9)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (9)post_thanks_postbit_info
  • (9)postbit
  • (8)postbit_onlinestatus
  • (9)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete