The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Private forums "hacked"
I have had a security breach on my site.
I have forums that are accessible only to moderators, supermods and admin. somehow, one of my regular members was able to access all the forums and threads in the private section. Apart from permissions in the user profile, or forum permissions, how could this happen? Help. |
#2
|
||||
|
||||
If you used Deny All in the Forums Permissions and only added in the Admin and Mod groups to see it, and if you are not using any access masks to allow users into it, then the only way I can think they got in was to login using an Admin/Mod account or through the database.
|
#3
|
|||
|
|||
Through the database how?
|
#4
|
||||
|
||||
They would be able to do this by using a locally or remotely hosted install of phpMyAdmin or similar software. This software allows you to 'browse' your database.
These methods rely on the user name/password for your PMA folder or database being known - unless PMA is incorrectly configured to allow anyone to gain access. Have you at any point (even if for a short period) had this forum guest enabled? |
#5
|
|||
|
|||
No she has never had access.
It seems that the archives were accessed at server level. |
#6
|
||||
|
||||
The archives show the same posts/forums to a user that they would see on the regular site. If they can't see a forum through the regular site, then they should not be able to see the forum through the archives.
Do a test and create a new user. Put them in the exact same usergroups that this user is in - same Primary group and same Secondary group(s). Now login with that user and try to go to your Mod forum. I'm not talking about trying to 'see' it on your forum home page, but go to the actualy link - www.yousite.com/forum/forumdisplay.php?f=x where x is the forumid of one of the forums they somehow got access to. Then do the same through the archives - www.yoursite.org/forum/archive/index.php/f-x.html Can you see anything? Try each of the forums you think they got access to. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|