Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 10-28-2011, 03:10 AM
MNNLeafre MNNLeafre is offline
 
Join Date: Sep 2011
Posts: 41
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default My forum is in danger

Alright so I came back to my forum today to found out my pass was changed. I just woke up so I thought maybe it's just me, so I did a password reset.

I then realize there's an ad where there shouldn't be. I look at the script and it is definitely not mine.
I decide to change back the ads to my code.
Later, I realize I see another admin that I certainly did NOT make.

I proceed to delete the user. He then logs another user's account and starts talking on the shoutbox.

He continues to say
"ban me again and I'll do worse"
"[other user] your pass took me 2 min to crack"
At this point I knew he was a threat and proceeded to turn off my forum
Then HE turns it back on and says
"The forum's are fine, i'm going to sleep and in the morning if this account is no longer admin, and the forum looks any different I will wipe it from the web."
"If you turn it off again I'll cause real damage"
He then rambles on that he just wanted to see if he could hack the forum, and he will "leave us alone"
He said "I made [him] a superadmin, want me to remove that?"

So from that, I decide to check the CP Logs, and it seems that the first thing he did was go to market_item.php. This gave me the impression that the Point Market is NOT safe.
I proceed to disable it (should I uninstall instead?).

Now with that said, what do I do to prevent anything like this to happen?
I see he made several changes in templates. I'm going to uninstall then reinstall the styles for safety. as well as reverting everything back in the default style.

But the thing is, how would he be able to make people super Admins? You need FTP access for that, don't you? My login info for the forums is not the same as my FTP info.

When I stated that the market had to be part of the problem, he said "all i did was make one post in the forum, and make a few super admins"
And instantly I thought it was the one forum section I allowed HTML on.
But however I checked the admin logs and saw NOTHING of the user posting, nor any of the admins/mods deleting a post.

My forum is 4.1.6

What else should I do?
Reply With Quote
  #2  
Old 10-28-2011, 03:39 AM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

<a href="https://vborg.vbsupport.ru/showthread.php?t=268208" target="_blank">https://vborg.vbsupport.ru/showthread.php?t=268208</a>
install this and ban his host he wont get back on

remove all custom plugins change ftp password to something hard and long updated version to 4.1.7 get logs from your host see what they say
Reply With Quote
  #3  
Old 10-28-2011, 03:47 AM
MNNLeafre MNNLeafre is offline
 
Join Date: Sep 2011
Posts: 41
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ForceHSS View Post
https://vborg.vbsupport.ru/showthread.php?t=268208
install this and ban his host he wont get back on

remove all custom plugins change ftp password to something hard and long updated version to 4.1.7 get logs from your host see what they say
Thing is, he had 3 different IPs, all from different places.
I'll do the update too.
Reply With Quote
  #4  
Old 10-28-2011, 04:26 AM
wat3v3r wat3v3r is offline
 
Join Date: Jun 2008
Posts: 42
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

What i would have done is:

- Secure my Admin password. (he said he cracked you in 2mins... use special characters,numbers and upper and lower case alphabets so it cannot be brute forced easily)
- Change my DB and FTP passwords.
- If you on a vps or dedicated get CSF firewall installed.
- Open a ticket with your host if you are on a managed host. Giving them the Ip's and asking them to check server logs.
- Rename Admin and Moderator panels.
- Add a password via htaccess for the Admin Panel.
Reply With Quote
  #5  
Old 10-28-2011, 05:25 AM
Gunshot Gunshot is offline
 
Join Date: Feb 2005
Posts: 119
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Open config.php and make sure you are the only superadmin before deleting his accounts
you could also password protect that file
Reply With Quote
  #6  
Old 10-28-2011, 05:55 AM
MNNLeafre MNNLeafre is offline
 
Join Date: Sep 2011
Posts: 41
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Gunshot View Post
Open config.php and make sure you are the only superadmin before deleting his accounts
you could also password protect that file
How?

@wat3v3r Thank you very much! I'll do that
Reply With Quote
  #7  
Old 10-28-2011, 11:18 AM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

make a .htpasswd file
there are many things you can do to stop this from happening start reading up on security
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:29 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04854 seconds
  • Memory Usage 2,220KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (7)post_thanks_box
  • (7)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (7)post_thanks_postbit_info
  • (7)postbit
  • (7)postbit_onlinestatus
  • (7)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete