The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Can someone do this?
Umm.. I got this completely random voicemail this morning and I'm wondering if what he is saying is true?
http://img159.imageshack.us/my.php?i...icemaileg8.swf Log: Message received at 4 17 am Hello hello David, Parker My name would be, Hairy John Ok and I was just called to let you know that i found a fewwww exploits in ur website a little bit of SQL injection dunno what he says here really umm ill be doing a mb5 hash that will be giving me your admin password i would so kindly be taking that website over in a couple hours if u would like to go on and take a look you have a great day I haven't noticed anything wrong with my forums, and I don't remember installing anything weird. I am not professional at it or anything but I know my way around PHP and vbulletin (so I doubt I messed something up like that). Only thing that has been different in a week or 2 ago I got some vbulletin errors (this was the email.. I got 8 in a row same minute.. All had a different image.. image is users avatars): Quote:
|
#2
|
||||
|
||||
First, how did he get you phone number? Second, if he was really gonna do as he said, he would have done it and THEN maybe called you or left his calling card on your site. Sounds to me like it is someone you know or who knows you.
Who's IP address is that in the error? |
#3
|
||||
|
||||
Quote:
IP: 69.89.55.55 = San Mateo, CA. |
#4
|
||||
|
||||
Would be easy if they have it on their domain record. Private domains are the way to go
|
#5
|
||||
|
||||
we need more info on this
|
#6
|
||||
|
||||
David,
Unless you have any custom code on your server (PHP) then you should be safe from any injection. The DB error is just from a restriction set by your host which you can get around if you have multiple database accounts. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|