Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 09-30-2004, 07:44 PM
mcyates mcyates is offline
 
Join Date: Jan 2003
Location: Middlesbrough, Cleveland
Posts: 798
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default My Forum HACKED for the 3rd time.

Someone keeps on going onto the forum with my account even though I have changed my password to a 16 character password with words and numbers, AND passwords protected the site (admincp) via .htaccess.

Is there anyway i can stop this from happening? e.g. cmod admincp 000 to stop people from accessing the admin or will this give the site some problems which might require files in the admincp?

Please help a.s.a.p
Reply With Quote
  #2  
Old 09-30-2004, 07:50 PM
nexialys
Guest
 
Posts: n/a
Default

this is impossible that you've been hacked that way... you may have something outside the server...

you have admins ?! moderators, supermods, etc... someone else have access to your computer, etc... these are always the same questions you have to answer...

there is not a single possible way to hack Bulletin the way you claim... so it's 100% on your side.
Reply With Quote
  #3  
Old 09-30-2004, 07:53 PM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by mcyates
Someone keeps on going onto the forum with my account even though I have changed my password to a 16 character password with words and numbers, AND passwords protected the site (admincp) via .htaccess.

Is there anyway i can stop this from happening? e.g. cmod admincp 000 to stop people from accessing the admin or will this give the site some problems which might require files in the admincp?

Please help a.s.a.p
Do you allow ANY html ?
Reply With Quote
  #4  
Old 09-30-2004, 07:53 PM
mcyates mcyates is offline
 
Join Date: Jan 2003
Location: Middlesbrough, Cleveland
Posts: 798
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by nexialys
this is impossible that you've been hacked that way... you may have something outside the server...

you have admins ?! moderators, supermods, etc... someone else have access to your computer, etc... these are always the same questions you have to answer...

there is not a single possible way to hack Bulletin the way you claim... so it's 100% on your side.

Ok thanks.

I do have super mods and moderators. I will have to remove some of them.
Reply With Quote
  #5  
Old 09-30-2004, 07:58 PM
mcyates mcyates is offline
 
Join Date: Jan 2003
Location: Middlesbrough, Cleveland
Posts: 798
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zachery
Do you allow ANY html ?
So this can't happen with even hack on the site? I only have the Arcade, Photopost and the last 5 stats (posts) on the main site.
Reply With Quote
  #6  
Old 09-30-2004, 08:06 PM
mcyates mcyates is offline
 
Join Date: Jan 2003
Location: Middlesbrough, Cleveland
Posts: 798
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zachery
Do you allow ANY html ?
I'm sure its all bee3n turned off. One sec though i'll just double check.
Reply With Quote
  #7  
Old 09-30-2004, 08:09 PM
mcyates mcyates is offline
 
Join Date: Jan 2003
Location: Middlesbrough, Cleveland
Posts: 798
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by mcyates
I'm sure its all bee3n turned off. One sec though i'll just double check.
Just [HTML] on the Enabled Built-in BB Codes in the vb admin options. all the other html is turned off.
Reply With Quote
  #8  
Old 09-30-2004, 08:37 PM
mcyates mcyates is offline
 
Join Date: Jan 2003
Location: Middlesbrough, Cleveland
Posts: 798
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by mcyates
Just [HTML] on the Enabled Built-in BB Codes in the vb admin options. all the other html is turned off.
I still have the /install folder on my domain with all the upgrade.php files on will that be a security risk?
Reply With Quote
  #9  
Old 09-30-2004, 09:04 PM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by mcyates
I still have the /install folder on my domain with all the upgrade.php files on will that be a security risk?
No, only the "install.php" does and even then it could only delete the database.

Which version of the arcade?
Reply With Quote
  #10  
Old 09-30-2004, 09:07 PM
mcyates mcyates is offline
 
Join Date: Jan 2003
Location: Middlesbrough, Cleveland
Posts: 798
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zachery
No, only the "install.php" does and even then it could only delete the database.

Which version of the arcade?
the latest one, i only installed last week but this has been happening for about 4 weeks now.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:42 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04720 seconds
  • Memory Usage 2,250KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (8)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (9)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete