Go Back   vb.org Archive > Community Discussions > Forum and Server Management
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 10-18-2008, 09:52 AM
n95gps n95gps is offline
 
Join Date: Aug 2008
Posts: 41
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

thank you so much guys for replying

well i forget to mention one thing he told me

he said that a friend of his gave hime a shell

i am not familiar with shells but he said he was able to get into the hostmonster server and he said he was browsing every single file in it

not only that ...he was browsing all the site that was hosted by hostmonster in that server

i already spoke to the live help at hostmonster but these guys who are answering question dont seem to care...but now or later on believe me they will lose paying custmors

they told me the secuirty is usr problem you have to hire someone to help you

what a good way of doing buissness!!!!


now i wonder will it be too dificult for the vbulletin to get ride of the config file with something else a more secure way

all these teenager hackers are attacking DB using whatever info they get inside the config file

i CHMD my forum to 1111

things seem working fine


i know to some this might not be a big issue but belive me and i hope this day will never come

talking to each other could lead us in figring out how do they work meaning these hackers and may be stop them for the time been


thanx again guys

--------------- Added [DATE]1224327409[/DATE] at [TIME]1224327409[/TIME] ---------------

by the way i have his e-mail

its a very uniqe e-mail

a three letters e-mail

LOL

he told me he hacked it from someone

some of you may say that i was rescuing my pc when i was talking to him but i was using a puplic pc from an intenet cafe' and a new MSN account


by the way therogueforums

does your site hacker e-mail start with an E

and his name is mr nj?!

--------------- Added [DATE]1224327659[/DATE] at [TIME]1224327659[/TIME] ---------------

Lizard King

where to you move it xactly

more info is needed please

if that will help in my case
Reply With Quote
  #12  
Old 10-18-2008, 10:17 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Marco van Herwaarden View Post
As already mentioned, if the security of your host is below normal, then there is not much you can do.
!!!
Reply With Quote
  #13  
Old 10-18-2008, 11:19 AM
therogueforums's Avatar
therogueforums therogueforums is offline
 
Join Date: Mar 2007
Location: Louisville, KY
Posts: 149
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yes. Mr NJ seems to be quite fond of our forums.
Reply With Quote
  #14  
Old 10-18-2008, 05:08 PM
Alfa1's Avatar
Alfa1 Alfa1 is offline
 
Join Date: Dec 2005
Location: Netherlands
Posts: 3,537
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well that proves that Marco and others are correct: you need to switch hosts ASAP.
Reply With Quote
  #15  
Old 10-18-2008, 05:21 PM
therogueforums's Avatar
therogueforums therogueforums is offline
 
Join Date: Mar 2007
Location: Louisville, KY
Posts: 149
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yeah, OK. Let me just pull out that fat wad of cash I have put back, just to move hosts

I, literally, cannot afford to move hosts right now. In the meantime, I'm just S.O.L.? No way to secure our site?
Reply With Quote
  #16  
Old 10-18-2008, 05:27 PM
SALIMUS SALIMUS is offline
 
Join Date: May 2007
Posts: 14
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

some one hosted in same server allow him tu put a snXXr shell
AND LIKE THAT HE BROWSED all other hosted domaine in the same machine .
i think that its the way how he hacked you .
btw ur haker is amator .
its a classic methode .
wbr
Reply With Quote
  #17  
Old 10-18-2008, 07:07 PM
therogueforums's Avatar
therogueforums therogueforums is offline
 
Join Date: Mar 2007
Location: Louisville, KY
Posts: 149
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thank you. Someone has a theory it might be a shell of some sort. Any way to solve this, other than moving hosts?
Reply With Quote
  #18  
Old 10-18-2008, 07:14 PM
n95gps n95gps is offline
 
Join Date: Aug 2008
Posts: 41
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by therogueforums View Post
Thank you. Someone has a theory it might be a shell of some sort. Any way to solve this, other than moving hosts?
like i said before

he told me its a shell that his friend gave him

and using that shell he was able to get into the hostmonster server

and do his evil act



did you talk to the live support??

and what was thier respond
Reply With Quote
  #19  
Old 10-18-2008, 07:20 PM
therogueforums's Avatar
therogueforums therogueforums is offline
 
Join Date: Mar 2007
Location: Louisville, KY
Posts: 149
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yes, I called. They said that the server had not been compromised, and that the security hole was a flaw in vB itself. Heh. vB says it's the server.
Reply With Quote
  #20  
Old 10-18-2008, 07:46 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Did you tell them that the guy had shell access given to him for one site but was then able to get into files on other sites also? That is a security flaw in the server.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:04 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.10433 seconds
  • Memory Usage 2,255KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete