Some admins lost permissions after being hacked

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ameen
    Member
    • Aug 2004
    • 34
    • 3.0.3

    Some admins lost permissions after being hacked

    yesterday someone hacked my website but guessing the password .. the pass was so easy so he granted access.

    anyway, after i have changed all the passwords & protected the "admincp" with password & changed the folder name in the ftp & the config.php

    Now, the problem now is the admins can not see the edit buttons so the can edit them or delete them.

    i have checked the administrators group permissions & everything was okay .. so i registered a new user & i made him an administrator, he was able to get access "edit & delete others posts" which means that there is nothing wrong with the group permissions.

    i want to give back the permissions to the old administrator. but i don't know how?!
  • jmurrayhead
    Senior Member
    • Sep 2006
    • 1642

    #2
    Did you check to see if the older admins are still members of the Administrators usergroup?
    No...No...Meester vBulletin, he no work right.

    Comment

    • ameen
      Member
      • Aug 2004
      • 34
      • 3.0.3

      #3
      yes i did that .. also they was protected admins from the config.php & i don't know how he was able to get them edited!

      I'm sure he did not get to any ftp password ONLY he was able to get to one of the admins account

      Comment

      • jmurrayhead
        Senior Member
        • Sep 2006
        • 1642

        #4
        If they were able to edit the config.php file they must have had some sort of access to the server. Regardless, if the users are in the default Administrators group they should have access to edit and delete threads. Are you certain that everything is still set to 'Yes' for the Administrators usergroup? Particularly, the Administrator Permissiosn category?
        No...No...Meester vBulletin, he no work right.

        Comment

        • ameen
          Member
          • Aug 2004
          • 34
          • 3.0.3

          #5
          - yes i check the group permissions & everything is set to yes. it is kind of weird to me!!

          They were not able to access the config.php (i mean the hackes).

          i mentioned the config.php to say that the old admins were protected using "$config['SpecialUsers']['undeletableusers']" but the hackers was able to make something to edit the admins somehow & now they are in "administrators group" & are not able to make any changes to others posts while i created a new user & added him to "administrators group" & he was able to get all the access!!

          Now the question is "Why administrators group permissions applicable only for certain users than the others?"

          Comment

          • sachin
            Member
            • Sep 2006
            • 30

            #6
            what version are you using?

            how do you know that someone hacked your forum?

            it might be a database issue...??
            Hot Wallpapers.:o

            Comment

            • sachin
              Member
              • Sep 2006
              • 30

              #7
              you may want to see this:

              Hot Wallpapers.:o

              Comment

              Related Topics

              Collapse

              Working...