Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 05-10-2012, 07:32 AM
pzet pzet is offline
 
Join Date: Jul 2007
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Forum hacked, version 4.0.6 Patch Level 4

Hello,

Just found this morning that my forum was hacked. All IP's in "who is online" point to one and the same IP-address: 194.1.150.194
The last registration attempt comes from this IP. From what I can remember few days ago someone with the same email address was trying to register from a Russian IP address.

I am using the advanced IP manager as well as the stop forum spam addon - I banned the initial IP address from registering.

Can anyone help please.
Thanks
Peter
Reply With Quote
  #2  
Old 05-10-2012, 07:53 AM
deadlySniper deadlySniper is offline
 
Join Date: Dec 2008
Location: New York
Posts: 211
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I know for one, I would upgrade. Second, have you banned the IP? Also, I usually would ask my host to ban certain countries. I was having issues with turkish spam, so I had the country blocked.
Reply With Quote
  #3  
Old 05-10-2012, 08:03 AM
pzet pzet is offline
 
Join Date: Jul 2007
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I am running the latest available security patch (for version 4.0.6) so from that end it should be fine.

To ban certain countries won't really help. By using the Tor browser a hacker can attack virtually from any country.
Reply With Quote
  #4  
Old 05-10-2012, 08:10 AM
deadlySniper deadlySniper is offline
 
Join Date: Dec 2008
Location: New York
Posts: 211
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The only thing I can think of, is that the version you have is not secure. I know when I was running 3.8.4 with PL. They released 3.8.5 which fixed more security issues that the previous patch level didnt fix. Also do you allow same IP registrations or duplicate registrations?
Reply With Quote
  #5  
Old 05-10-2012, 08:29 AM
pzet pzet is offline
 
Join Date: Jul 2007
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

no duplicate registrations allowed.
Reply With Quote
  #6  
Old 05-10-2012, 08:32 AM
deadlySniper deadlySniper is offline
 
Join Date: Dec 2008
Location: New York
Posts: 211
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

My other thought is, did the person actually hack? Like did they get any admin? It could just be the person registering multiple accounts.
Reply With Quote
  #7  
Old 05-10-2012, 08:34 AM
pzet pzet is offline
 
Join Date: Jul 2007
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

No, that user was blocked - no registration.

There must be another loop hole to access the database.
Reply With Quote
  #8  
Old 05-10-2012, 10:12 AM
borbole's Avatar
borbole borbole is offline
 
Join Date: Jan 2010
Posts: 2,559
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pzet View Post
I am running the latest available security patch (for version 4.0.6) so from that end it should be fine.

To ban certain countries won't really help. By using the Tor browser a hacker can attack virtually from any country.
No, it is not fine. As there are many security issues found in the later versions that affect your version as well. The best thing would be to upgrade to the latest stable version.

That said, can you ask your host to check their access logs for around the time of the hack and see what happened and how it did happen? That would help in identifying the point of entry and patch it up.
Reply With Quote
  #9  
Old 05-10-2012, 10:42 AM
cellarius's Avatar
cellarius cellarius is offline
 
Join Date: Aug 2005
Posts: 1,987
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pzet View Post
Hello,

Just found this morning that my forum was hacked. All IP's in "who is online" point to one and the same IP-address: 194.1.150.194
This is an IP address in Great Britain, belonging to Global Gold Network Provider. Any chance you're hosting with them?

Make sure your provider did not make any settings to his proxy, firewall or other network related setup. If IPs are not passed properly, all your users/guests will show as having the IP address of the proxy.
Reply With Quote
Благодарность от:
Lynne
  #10  
Old 05-10-2012, 10:52 AM
pzet pzet is offline
 
Join Date: Jul 2007
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by cellarius View Post
This is an IP address in Great Britain, belonging to Global Gold Network Provider. Any chance you're hosting with them?

Make sure your provider did not make any settings to his proxy, firewall or other network related setup. If IPs are not passed properly, all your users/guests will show as having the IP address of the proxy.
Thanks for your reply. Yes I am hosting my forum with Globalgold.
Just contacted the hoster, they are working on the issue.

Thanks
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:46 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04240 seconds
  • Memory Usage 2,250KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (10)post_thanks_box
  • (1)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete