![]() |
|
Mod Options |
#16
|
|||
|
|||
so basically there is no way to protect yourself against this type of thing - so the culprit wins once again if he has to change his files etc.
Surely there must be some protection from this sort of stuff out there. Remember this affects all of us in the long run not just fordsho No members have liked this post.
|
#17
|
|||
|
|||
Well i just finished upping the new files and well everything seems good for now... i lost my design and some other stuff but ill up those later on. but these guys are serious man i have a fairly decent number of members and what not and this guy just decides to take it from me..... i allready had someone steal my database when it was at 180k... that sucked big time.
No members have liked this post.
|
#18
|
||||
|
||||
Chances are the kid found some vulnerability in a hack somewhere. It might even be one he helped to write and set up for this. This is an isolated case and we don't know all of the details.
No members have liked this post.
|
#19
|
|||
|
|||
well heres the thing. the person doing this was probably one of my old staff who decided to steal the forum for his self and failed miserably...
No members have liked this post.
|
#20
|
||||
|
||||
Well, he didn't get what he was after. And apparently he doesn't have that much access or he would have done more damage. You are lucky this time. If he might have had any other details, now would be a good time to reset all passwords, FTP, ADMIN and MOD CPs. etc.
No members have liked this post.
|
#21
|
||||
|
||||
If he was just opening and closing the forum (e.g. from the adminCP), you can just demote all mods / admins except for yourself to a normal user, double check the rights of all the member groups, and check to make sure you're the only super admin (if you are one at all).
__________________
Admin of the Corsair Memory Forum (AKA the House of Help from back in the day) Admin of Petri's IT Forum / Moderator at webdesignforums.net No members have liked this post.
|
#22
|
||||
|
||||
I'm sure he didn't had access to the admincp either, because he could run custom queries from there to get the user list.
It seems to me he got a way to upload a php file, and by adding an include('includes/config.php') he ran a script that turned the forum down. Now, If he knew what he was doing, he would have included a query in the uploaded file itself to strip the user list. Again, it's just a script kiddie. No members have liked this post.
|
#23
|
|||
|
|||
Just think for yourself: If you where a hacker and had software to gain access to any vBulletin board, why would i target your site, i would go for the sites that get most attention: vb.com & vb.org.
Now how come we are never target to such successfull attacks if it was possible to hack "any vBulletin board".
__________________
Marco van Herwaarden Ex vBulletin.org Coordinator No members have liked this post.
|
#24
|
|||
|
|||
I would seriously reconsider your password and security policy's for staff.
No members have liked this post.
|
#25
|
|||
|
|||
One little question, is your whole webspace down or only your vb board?
If its the whole site (server not reachable anymore), then your provider should update the linux software with a better kernel. I know this kinds of scripts getting your webspace down. No members have liked this post.
|
#26
|
|||
|
|||
His Reply.
![]() This guy is pissing me off... im going to have all my passes rest and then go from there. No members have liked this post.
|
#27
|
||||
|
||||
Resetting the passwords should have been one of the first things you did.
He's bluffing. Ignore him and do not respond to him. The chat remark gives him away. Most sites that have a chat on them have a chat directory. Also, if he had your FTP, you would be seeing some phantom pages by now. He's bluffing to try and get you to give in. And with language like he is using, I'm guessing he isn't 15 yet. Look there first at any staff you have had in the past. No members have liked this post.
|
#28
|
||||
|
||||
Originally Posted by fordsho
All I can say is: he's working more your mind than your board... RELAX! and learn ![]()
![]() No members have liked this post.
|
#29
|
|||
|
|||
As Iogames stated, he's playing mind games.
Don't give in, put on your poker face ![]() Also, my pass is 40 chars long consisting of letters numbers and an alot code. Maybe you should do the same,so you don't have to worry about some little cracking attempts. Btw, if he does have your database already, all he has to do is crack your hash and he has your forum password. So your best off to change it. No members have liked this post.
|
#30
|
|||
|
|||
how is he getting in touch with u - if its by way of emails then he is leaving a trace etc - act upon it
No members have liked this post.
|
![]() |
«
Previous Mod
|
Next Mod
»
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
Mod Options | |
|
|
New To Site? | Need Help? |
All times are GMT. The time now is 21:13.