PDA

View Full Version : Security Flaw?


Ophelia
Fri 12th Jan '07, 2:52am
On a site that I post at, the following was posted.

Ther server techies finally figured out that we were malicoiusly sabbotaged.

We have a huge database and some person or persons who are registered members (guests don't have access to the methods they used) found a glitch in the system that locked up the database.

It's called a denial of service attack. It's an internet crime. We are contacting the server and VBulletin to see if there's a way to trace IPs or something and get a definite person responsible.

Unfortunately the database had to be reset to Jan 10th. We are hoping that wasn't corrupted. If it was the boards will have to be reset to last week. We are taking precautions to make sure this doesn't happen again and to find the guilty party/parties.

And yes, we do know that this was deliberate and intentional. It was not a fluke or a glitch or some other benign incident. This was malicious and purposeful.

They are running: Powered by vBulletin® Version 3.6.4

Do I need to be worried about my vBulletin?

Gunshot
Fri 12th Jan '07, 4:31am
a DDOS is an attack from an outside source using a multitude od PC's controlled by the attacker by Trojans or other methods..

generally the worst that will happen is the Server will slow to a crawl or you will get a "too many connections" database error till the attack subsides.

you either misunderstood or got some bad info that this was done from within your board

Colin F
Fri 12th Jan '07, 4:42am
A DOS attack can be launched on any page, with the aim to use tons of server resources and make the site lag.

This is something that should be stopped on the server level, before it even reaches vBulletin, but we have also protected the most resource-intensive pages, to further prevent this.
That's why you generally need to wait 30 seconds between searches, and why guests need to enter a captcha image when searching.

Gunshot
Fri 12th Jan '07, 5:00am
seems like a pretty risky way to attack a site from a hackers prospective...
register and then attack the site?

Distance
Fri 12th Jan '07, 5:08am
Because they are mindless morons