Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 10-12-2013, 03:14 AM
HansK HansK is offline
 
Join Date: May 2009
Location: Sedgefield - South Africa
Posts: 7
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default How did a user manage to post to a hidden thread?

A few days ago we found a post in one of the threads that has been set as "hidden", so is not visible to the public or to registered users, only admin's can see this thread.

Is there some known hack or security hole in vBulletin 3 that could be exploited?

We are in some litigation at the moment and this particular post relates to this, so finding out how it was achieved will prove that there is subversive activity on our forum. Only registered users have permission to post and this was posted by a standard, registered user.

Thanks

Hans
Reply With Quote
  #2  
Old 10-12-2013, 03:23 AM
Digital Jedi's Avatar
Digital Jedi Digital Jedi is offline
 
Join Date: Oct 2006
Location: PopCulturalReferenceLand
Posts: 5,171
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I guess it depends on how you "hid" it. Because that's not default vB functionality. Forums can have individual forum permissions, but threads can't. How, exactly, were you hiding such a thread? Was it in an admin only forum, or were you using some kind of modification?
Reply With Quote
Благодарность от:
tbworld
  #3  
Old 10-12-2013, 03:35 AM
HansK HansK is offline
 
Join Date: May 2009
Location: Sedgefield - South Africa
Posts: 7
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It was hidden through the admin area as a thread that we decided not to use anymore. This was done before any actual posts were made to it, so the "sneaky" post is the only one there. The thread has been in existence for a long time, but never used.
Reply With Quote
  #4  
Old 10-12-2013, 03:36 AM
tbworld tbworld is offline
 
Join Date: Oct 2008
Posts: 2,126
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Digital Jedi View Post
I guess it depends on how you "hid" it. Because that's not default vB functionality. Forums can have individual forum permissions, but threads can't. How, exactly, were you hiding such a thread? Was it in an admin only forum, or were you using some kind of modification?
Exactly my thinking, but stated more elegantly by @Digital_Jedi

If you were using a hide hack, it may not have been completely hidden from the outside world.
Reply With Quote
  #5  
Old 10-12-2013, 03:49 AM
HansK HansK is offline
 
Join Date: May 2009
Location: Sedgefield - South Africa
Posts: 7
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

No hack was used at all, the actual "forum" or topic was set to be for Admin only, so suddenly having a new thread in it, was rather surprising.

I apologise for any misinformation earlier, it is actually a "Forum" that was not visible to anyone but Admin, and not a "thread" as I stated earlier.

A new thread was started in the "forum" and I am not sure how that could have happened.

Thanks
Reply With Quote
  #6  
Old 10-12-2013, 04:10 AM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

So you hid this section with forum permissions if so double check then check user make sure he is set to right group and has no extra groups added if he does check to make sure them groups dont have access to this section.
Reply With Quote
  #7  
Old 10-12-2013, 05:33 AM
HansK HansK is offline
 
Join Date: May 2009
Location: Sedgefield - South Africa
Posts: 7
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for the tip, I have checked all the forum permissions and the only group that can see this forum is Admin and Moderators. The user that posted a thread here, was neither of these and all the other groups are set to "No" for all options.

The post is still there and if I am logged in as a regular user or any other group, I get the message:

Invalid Thread specified. If you followed a valid link, please notify the administrator

This user has now been set to a "restricted" group with very few privileges as we suspect that he may have some hacking skills.

Thanks for any help with this so far.

Hans
Reply With Quote
  #8  
Old 10-12-2013, 05:56 AM
Digital Jedi's Avatar
Digital Jedi Digital Jedi is offline
 
Join Date: Oct 2006
Location: PopCulturalReferenceLand
Posts: 5,171
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Seems like a very unusual thing to do for a hacker, but I suppose, not impossible. I would also take a close look at my access logs in the Admin CP to see if anyone had a hand in allowing a registered user access, or if someone goofed adjusting forum permissions. Even if it was just for a moment.
Reply With Quote
  #9  
Old 10-12-2013, 08:39 AM
HansK HansK is offline
 
Join Date: May 2009
Location: Sedgefield - South Africa
Posts: 7
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for the feedback. My suspicion is that it is a hack, as the content is related to current litigation and also uses certain information relating to the law suit.

All those that do have the ability to make any changes, are fully aware of the situation and would never make any changes to this user's access, or settings.

Thanks for the information.

Hans
Reply With Quote
  #10  
Old 10-12-2013, 12:44 PM
Digital Jedi's Avatar
Digital Jedi Digital Jedi is offline
 
Join Date: Oct 2006
Location: PopCulturalReferenceLand
Posts: 5,171
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

That they're aware of. But, if as you suspect, there was some hacking involved, it could be something as simple as hacking the password of an admin account. If one of your accounts is compromised, might be a good idea to double check admin logs. Maybe even to have admins change their passwords to something more secure.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 09:11 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06684 seconds
  • Memory Usage 2,254KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (1)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete