The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Forum hacked, version 4.0.6 Patch Level 4
Hello,
Just found this morning that my forum was hacked. All IP's in "who is online" point to one and the same IP-address: 194.1.150.194 The last registration attempt comes from this IP. From what I can remember few days ago someone with the same email address was trying to register from a Russian IP address. I am using the advanced IP manager as well as the stop forum spam addon - I banned the initial IP address from registering. Can anyone help please. Thanks Peter |
#2
|
|||
|
|||
I know for one, I would upgrade. Second, have you banned the IP? Also, I usually would ask my host to ban certain countries. I was having issues with turkish spam, so I had the country blocked.
|
#3
|
|||
|
|||
I am running the latest available security patch (for version 4.0.6) so from that end it should be fine.
To ban certain countries won't really help. By using the Tor browser a hacker can attack virtually from any country. |
#4
|
|||
|
|||
The only thing I can think of, is that the version you have is not secure. I know when I was running 3.8.4 with PL. They released 3.8.5 which fixed more security issues that the previous patch level didnt fix. Also do you allow same IP registrations or duplicate registrations?
|
#5
|
|||
|
|||
no duplicate registrations allowed.
|
#6
|
|||
|
|||
My other thought is, did the person actually hack? Like did they get any admin? It could just be the person registering multiple accounts.
|
#7
|
|||
|
|||
No, that user was blocked - no registration.
There must be another loop hole to access the database. |
#8
|
||||
|
||||
Quote:
That said, can you ask your host to check their access logs for around the time of the hack and see what happened and how it did happen? That would help in identifying the point of entry and patch it up. |
#9
|
||||
|
||||
Quote:
Make sure your provider did not make any settings to his proxy, firewall or other network related setup. If IPs are not passed properly, all your users/guests will show as having the IP address of the proxy. |
Благодарность от: | ||
Lynne |
#10
|
|||
|
|||
Quote:
Just contacted the hoster, they are working on the issue. Thanks |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|