The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
Vb 4.2.3 users passwords stolen
I have been reported some of my users had their password stolen and used by a hacker to post shitty topics on the forum
What can I do to avoid that? |
#2
|
|||
|
|||
Were their passwords stolen because of a vulnerability on your forums or from somewhere else?
You first have to find the hole, then patch it, then you should consider resetting the passwords of all users. |
#3
|
||||
|
||||
Well that I don't know.
Seems like the passwords stolen were quite easy to guess |
#4
|
|||
|
|||
Well you will have to find out if it's because of an exploit on your forums or not.
That way we can guide you the right way. |
#5
|
||||
|
||||
Quote:
Anyway I have reset the password not secure (540) |
#6
|
|||
|
|||
Well if the "hacker" didn't tell you that he hacked your forums and extracted user information, the only way would be by looking at the server logs, suspicious hooks or outdated vulnerable plugins.
There's not really a way to tell you exactly where to look at since each hack is unique. |
#7
|
||||
|
||||
AdminCP>Users>Check Vulnerable passwords
|
#8
|
||||
|
||||
|
#9
|
||||
|
||||
How can I change the password to all the users and send it to their email?
|
#10
|
|||
|
|||
It sounds like you may need some help in this matter, if you want some help PM me and we can have a chat.
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|