Hacked! AT 2.3.7

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • RoryF
    New Member
    • Apr 2005
    • 17
    • 3.0.7

    Hacked! AT 2.3.7

    Howdy .

    Obviously by the title there is some serious problem with 2.3.7, as there is a security somehow.

    My forums have been hacked, the CSS has been mucked up, the templates ar e mucked up, the header says very racist words in it. The AdminCP has locked me out, and to everyone eles. However showgroups.php has told me that im still an Head Moderator, (head mods in these forums can access admin).

    Below is an image of what the forums has been changed too




    Has this person exploited the error in Internet Explorer? We are in the process of fixing this with a database backup. Hense why i can't show the URL, because it might be fixed by now, by the hosting administrators.

    Would it be better to upgrade to vb3, if i wish to secure our forums from more attacks?

    Please help me in some form or way.
    Thanks,
    Rory.
  • jamesyfx
    Senior Member
    • Feb 2005
    • 679
    • 3.6.x

    #2
    vBulletin 2 should be just as secure as vB3, I'd think. Since the team still update vB2 with security fixes.

    There are security fixes in 2.3.8, as far as I know. So it's best to just stick with that.

    Comment

    • Steve Machol
      Former Customer Support Manager
      • Jul 2000
      • 154488

      #3
      vBulletin 3.5.1 vBulletin 3.0.10 vBulletin 2.3.8 The original purpose of this release was to provide a regular, scheduled bug-fix / service release for the new 3.5.x series, but newly discovered flaws in Internet Explorer and PHP have necessitated a security release for all three vBulletin branches. The first flaw is in
      Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
      Change CKEditor Colors to Match Style (for 4.1.4 and above)

      Steve Machol Photography


      Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


      Comment

      • RoryF
        New Member
        • Apr 2005
        • 17
        • 3.0.7

        #4
        Originally posted by Steve Machol
        I need more help that a link. I know that there is an upgrade, but i would like to know that was my forums hacked because of the known error in 2.3.7.

        Comment

        • Psionic Vision
          Senior Member
          • May 2005
          • 202
          • 3.6.x

          #5
          The best way to find that out would be to ask the hacker

          Comment

          • Steve Machol
            Former Customer Support Manager
            • Jul 2000
            • 154488

            #6
            Without knowing how you are being hacked it's difficult to stop it. For instance if your server is being compromised then there is nothing in vB that will stop a hacker from taking over.

            Here's some things you can do to increase the level of security for your forums:

            1. Upgrade to the latest stable version.
            2. Do not install any hacks
            3. Password protect your Admin and Mod CPs: http://www.javascriptkit.com/howto/htaccess.shtml
            4. Make sure the getadmin.php (vB2) file is NOWHERE on your website
            5. If you have phpMyAdmin make sure it's password protected.
            6. Inform your host of these hack attempts and ask them to check the logs to see when your account was accessed.
            7. Also ask your host to change the login password for your web account
            8. Change all your Admin and Mod passwords.
            9. Do NOT allow HTML in posts or in sigs.

            Note your forums are only as secure as the passwords you use and the server it is on. If the server is accessed then there's nothing vB can do to prevent potential security violations.
            Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
            Change CKEditor Colors to Match Style (for 4.1.4 and above)

            Steve Machol Photography


            Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


            Comment

            • babolo
              Senior Member
              • Jan 2004
              • 206
              • 3.0.5

              #7
              Make sure when you change the passwords and junk to make sure they are dufficult to guess something like 46Dhj3dj34XZA2jsd89 or 45wSj238xj2Q (don't use these)

              Comment

              • RattleSnake
                Banned
                • Jun 2005
                • 419
                • 3.6.x

                #8
                Yeah. Type up some random keyboard stuff. Make sure its got numbers and letters. and that it is 10 + charecters.

                Comment

                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                Working...