Welcome, Guest. Please Login or Register.
August 19, 2025, 01:12:29 PM
Home Help Search Log in Register
News: If you are still using YaBB SE, please consider upgrading to SMF as soon as possible.

YaBB SE Community  |  English User Help  |  English Help  |  they hacked my forum ! « previous next »
Pages: [1] 2 Reply Ignore Print
Author Topic: they hacked my forum !  (Read 2975 times)
babylonking
Full Member
***
Posts: 174


Proudly Canadian

WWW
they hacked my forum !
« on: March 22, 2003, 02:41:44 PM »
Reply with quote

some one hacked only my index.php file....this what i saw when i browsed my forum.

<pre>
BUSH IS GAY!!! BUSH IS EVIL

STOP WAR AGAINST, STAY LOVE AND PEACE!!!

By dum.my and tum.my

From Malaysia With LOVE!
</pre>


My index.php was chmod 666   :-\ now i changed to  chmod 664 .........but why in yabbse manual installation i have to chmod 666 the index.php file.
anyone  ???
Logged

Proudly Canadian          
Chris Cromer
The Strange One
Mod Team
YaBB God
*****
Posts: 3152


I am just a figment of your imagination.

WWW
Re:they hacked my forum !
« Reply #1 on: March 22, 2003, 02:48:26 PM »
Reply with quote

What version of YaBBSE are you using?

And did you install the security fix supplied by the YaBBSE Dev Team?
Logged

Chris Cromer

I am not suffering from insanity, I am enjoying every minute of it.
babylonking
Full Member
***
Posts: 174


Proudly Canadian

WWW
Re:they hacked my forum !
« Reply #2 on: March 22, 2003, 02:53:14 PM »
Reply with quote

am using  RC44 build ?

QuoteAnd did you install the security fix supplied by the YaBBSE Dev Team?

Nope  ???
Logged

Proudly Canadian          
babylonking
Full Member
***
Posts: 174


Proudly Canadian

WWW
Re:they hacked my forum !
« Reply #3 on: March 22, 2003, 03:01:01 PM »
Reply with quote

did you mean this fix  ???

Change:

Code:

include_once("$sourcedir/Packer.php");
// verify the user is an administrator
is_admin();


to

Code:

// verify the user is an administrator
is_admin();
include_once("$sourcedir/Packer.php");
Logged

Proudly Canadian          
Chris Cromer
The Strange One
Mod Team
YaBB God
*****
Posts: 3152


I am just a figment of your imagination.

WWW
Re:they hacked my forum !
« Reply #4 on: March 22, 2003, 04:10:18 PM »
Reply with quote

Yeah, but that fix should be installed in 1.5.1. So I guess that isn't how they hacked your index.php file. :-\
Logged

Chris Cromer

I am not suffering from insanity, I am enjoying every minute of it.
babylonking
Full Member
***
Posts: 174


Proudly Canadian

WWW
Re:they hacked my forum !
« Reply #5 on: March 22, 2003, 04:22:21 PM »
Reply with quote

My host they e-mail me this message:

We found your account "babylon" ran the script that allowed all other account to be hacked.  Our data center has closed off your  account entirely. We'll get back to you with further details.  ???


am only running yabbse forum in this host. http://www.berryhost.com/

Logged

Proudly Canadian          
David
Destroyer Dave
Global Moderator
YaBB God
*****
Posts: 5761


I'm not a llama!

WWW
Re:they hacked my forum !
« Reply #6 on: March 22, 2003, 06:23:08 PM »
Reply with quote

Has your host provided you logs surrounding the attack?  If not, please ask for them.  Also please send them to me or one of the other devs so that we can try and find out what happened. My e-mail is [email protected]
« Last Edit: March 22, 2003, 06:24:13 PM by David » Logged

babylonking
Full Member
***
Posts: 174


Proudly Canadian

WWW
Re:they hacked my forum !
« Reply #7 on: March 22, 2003, 09:33:00 PM »
Reply with quote

I sent e-mail asking them to provide me the attack logs and am still waiting for respond. :-\
Logged

Proudly Canadian          
Peter Duggan
Llama Chameleon
Global Moderator
YaBB God
*****
Posts: 1793


You come and go...

WWW
Re:they hacked my forum !
« Reply #8 on: March 22, 2003, 10:22:14 PM »
Reply with quote

Did you remember to delete the installation files after it was originally installed?
Logged

babylonking
Full Member
***
Posts: 174


Proudly Canadian

WWW
Re:they hacked my forum !
« Reply #9 on: March 23, 2003, 12:17:07 AM »
Reply with quote

Yes i deleted the installation file.

Logged

Proudly Canadian          
Chris Cromer
The Strange One
Mod Team
YaBB God
*****
Posts: 3152


I am just a figment of your imagination.

WWW
Re:they hacked my forum !
« Reply #10 on: March 23, 2003, 03:35:41 AM »
Reply with quote

Did you have attachements enabled?

And if they where, did you allow php files to be uploaded? Or did you set it so it didn't even check the file extension. Also did you let members upload attachments?

Just trying to find the source of the problem. ;D
Logged

Chris Cromer

I am not suffering from insanity, I am enjoying every minute of it.
babylonking
Full Member
***
Posts: 174


Proudly Canadian

WWW
Re:they hacked my forum !
« Reply #11 on: March 23, 2003, 03:51:24 AM »
Reply with quote

QuoteDid you have attachements enabled?

And if they where, did you allow php files to be uploaded? Or did you set it so it didn't even check the file extension. Also did you let members upload attachments?

Yabbse attachment enabled only for admin.........but i installed photo gallery mod and enabled picture upload for all members.
Logged

Proudly Canadian          
David
Destroyer Dave
Global Moderator
YaBB God
*****
Posts: 5761


I'm not a llama!

WWW
Re:they hacked my forum !
« Reply #12 on: March 23, 2003, 03:54:55 AM »
Reply with quote

Until your host gives you access logs, all anyone can do is guess.
Logged

Spaceman-Spiff
Mod Team
YaBB God
*****
Posts: 3689


My $txt[228]

Re:they hacked my forum !
« Reply #13 on: March 23, 2003, 04:38:10 AM »
Reply with quote

i think the photo gallery is quite safe, it has a function to clean post and get data, and the function is called everytime, before a page is loaded
but who knows... there might be some other way >_<

did the hacker alter/delete any file?
did he showed that msg through template.php?
Logged

   My mods, ysePak, codes, tutorials
    Support question IMs = bad.
babylonking
Full Member
***
Posts: 174


Proudly Canadian

WWW
Re:they hacked my forum !
« Reply #14 on: March 23, 2003, 03:41:45 PM »
Reply with quote

Quotedid the hacker alter/delete any file?
did he showed that msg through template.php?

They hacked only the index.php file....this what the hacker execute in my index file.

<pre>
BUSH IS GAY!!! BUSH IS EVIL

STOP WAR AGAINST, STAY LOVE AND PEACE!!!

By dum.my and tum.my

From Malaysia With LOVE!
</pre>


Logged

Proudly Canadian          
Pages: [1] 2 Reply Ignore Print 
YaBB SE Community  |  English User Help  |  English Help  |  they hacked my forum ! « previous - next »
 


Powered by MySQL Powered by PHP YaBB SE Community | Powered by YaBB SE
© 2001-2003, YaBB SE Dev Team. All Rights Reserved.
SMF 2.1.4 © 2023, Simple Machines
Valid XHTML 1.0! Valid CSS

Page created in 0.761 seconds with 20 queries.