Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 06-24-2008, 07:40 PM
dtv100 dtv100 is offline
 
Join Date: Apr 2007
Location: in the south of the north
Posts: 307
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default weird user maybe a hacker

this morning around 5am i went to who is online and i saw someone using one of my test account on our board and where his ip should be only say server2 then i click on resolve ip and i get 127.0.0.1 i delete the test account and he was trying to login using different admin names from forum leader list .Then I make all admins regular users just to be safe .

this for me is the first time i get someone with a ip like that because 127.0.0.1 should be local host .or I wrong?

any idea where i should look first ?
Attached Images
File Type: jpg HACKER.jpg (14.5 KB, 0 views)
Reply With Quote
  #2  
Old 06-24-2008, 07:44 PM
Jase2 Jase2 is offline
 
Join Date: Dec 2007
Location: USA
Posts: 1,575
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Re-upload all the default vBulletin files to be on the safe side.
Reply With Quote
  #3  
Old 06-24-2008, 07:59 PM
nexialys
Guest
 
Posts: n/a
Default

that IP is simple to use... someone with a website hosted on the same server as you are, using a shelled page... automated login via localhost access... basic, first thing a newbie hacker would do to trick a forum from phpBB...
Reply With Quote
  #4  
Old 06-24-2008, 09:47 PM
cheat-master30's Avatar
cheat-master30 cheat-master30 is offline
 
Join Date: Mar 2007
Location: Information Classified
Posts: 1,715
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well, since there aren't any currently known security issues with vBulletin, as long as your passwords are secure and relatively complex and you follow the basic security tips given out on the official site this user shouldn't succeed...
Reply With Quote
  #5  
Old 06-24-2008, 09:50 PM
Jase2 Jase2 is offline
 
Join Date: Dec 2007
Location: USA
Posts: 1,575
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Not necessarily. The bad guys always find the exploits first... For all you know, there could be an exploit in the new vBulletin, just not yet known
Reply With Quote
  #6  
Old 06-24-2008, 11:08 PM
cheat-master30's Avatar
cheat-master30 cheat-master30 is offline
 
Join Date: Mar 2007
Location: Information Classified
Posts: 1,715
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well if they were trying something tried on phpBB boards, then trying said technique on a vBulletin powered board, despite vBulletin being coded completely differently other than using PHP and MYSQL would not exactly make me think said 'hacker' was too competent.

That and I doubt Jelsoft would leave yet another security problem in vBulletin that somehow went undetected for months despite many great coders having used the software and probably would have reported any security problems they found...
Reply With Quote
  #7  
Old 06-25-2008, 12:12 AM
dtv100 dtv100 is offline
 
Join Date: Apr 2007
Location: in the south of the north
Posts: 307
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by nexialys View Post
that IP is simple to use... someone with a website hosted on the same server as you are, using a shelled page... automated login via localhost access... basic, first thing a newbie hacker would do to trick a forum from phpBB...
is there any way I could ban using that ip I mean 127.0.0.1 with out any side effect to my board?
Reply With Quote
  #8  
Old 06-25-2008, 12:18 AM
King Kovifor's Avatar
King Kovifor King Kovifor is offline
 
Join Date: Nov 2004
Location: PA
Posts: 3,872
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Unless other users use that IP, no.
Reply With Quote
  #9  
Old 06-25-2008, 11:06 AM
Jase2 Jase2 is offline
 
Join Date: Dec 2007
Location: USA
Posts: 1,575
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by cheat-master30 View Post
Well if they were trying something tried on phpBB boards, then trying said technique on a vBulletin powered board, despite vBulletin being coded completely differently other than using PHP and MYSQL would not exactly make me think said 'hacker' was too competent.

That and I doubt Jelsoft would leave yet another security problem in vBulletin that somehow went undetected for months despite many great coders having used the software and probably would have reported any security problems they found...
I never said there is a security issue. I said 'there' could be

As I've said, exploits are always found by the bad guys first. Not every security issue is that noticeable, even with quality coders using vBulletin.
Reply With Quote
  #10  
Old 06-25-2008, 07:49 PM
dtv100 dtv100 is offline
 
Join Date: Apr 2007
Location: in the south of the north
Posts: 307
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

OK today he finally got a hold of my user account since he can only log as a user but cant can to control panel since we have a second password to it .
also he did same thing in our second site .

he post in our staff area that he using a sql injection i am in the process of remove same hacks install in both sites to see if that help.

server login was change ,ftp login was change basically all password was change and i ban ip 127.0.0.1 now will re upload all vb files again .

anything i forgetting ?
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:18 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04098 seconds
  • Memory Usage 2,266KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (1)postbit_attachment
  • (9)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_attachment
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete