HACKED and don't know what to do..

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • CSU-CYS
    Member
    • Sep 2002
    • 58

    HACKED and don't know what to do..

    Terrible day for me and our community.
    I run a BB for a non-profit called the Cystinuria Foundation of America, Inc. We're slowly updating our website to reflect the recent incorporation. Just went online today and found that my forum page had been hacked.
    You can visit it (not much to see, really) at www.cystinuria.org/forums

    I'm locked out of my own admin account... and i'm worried that everything's gone. I'm really not the best at this kind of thing, and basically knew enough to set the BB in place and operate it. I am very upset and at a total loss of where to begin fixing this problem. I don't know why someone would hack our little site... we just try and help people with a disease.
    Can anyone please help someone very much in need??
    Rock bottom here... any advice would be so greatly appreciated.
    Kind Regards,
    matt lewis
    www.cystinuria.org
    www.cystinuria.org/forums
  • Mephisteus
    Senior Member
    • Aug 2002
    • 494
    • 3.7.x

    #2
    Can you log into ftp if not can you contact your webhost to reset your login data? Did you keep backups?
    A bullet may have your name on it, but shrapnel is addressed "to whom it may concern"

    Comment

    • CSU-CYS
      Member
      • Sep 2002
      • 58

      #3
      Thank You

      Hi, thank you for the reply.
      I can't get into the ftp for the site, nor can i access Vbulletin by going to www.cystinuria.org/forums/admin. Says my admin logon is incorrect.

      I tried to back up once, but it didn't go so well. I may or may not have a backup at this point. I'm not worried about the posts though, mainly the members. We had a small group (100 exactly), and i'm really hoping that their membership is still active once i get the board back up.

      Ideas?
      Thanks again,
      matt lewis
      www.cystinuria.org
      www.cystinuria.org/forums

      Comment

      • Steve Machol
        Former Customer Support Manager
        • Jul 2000
        • 154488

        #4
        <moving to vB2 forum>

        You are running vB 2.3.0 which has known security holes that this hacker took advantage of. Please read this important announcement about a security issue with your version of vB:

        It has come to our attention that there has been an attack on a number of vBulletin installations that are running older versions of the software. They are taking advantage of a known security flaw that was fixed in subsequent versions. It is extremely important that you keep your software up-to-date in order to protect



        Fill out a support ticket at:


        Be sure to include the login info to your Admin CP, phpMyAdmin and FTP.

        If they have not deleted any data we may be able to restore your forums. Otherwise you will need to restore a backup of the database, if you have one.
        Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
        Change CKEditor Colors to Match Style (for 4.1.4 and above)

        Steve Machol Photography


        Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


        Comment

        • CSU-CYS
          Member
          • Sep 2002
          • 58

          #5
          Thank you Steve, you've always been very helpful and kind.
          I'll get on that as soon as i can get away from my work for a few...

          Thanks again... so very much
          kind regards,
          matt

          p.s. sorry about the wrong forum... thank you for moving
          www.cystinuria.org
          www.cystinuria.org/forums

          Comment

          • Steve Machol
            Former Customer Support Manager
            • Jul 2000
            • 154488

            #6
            If you fill out a support ticket. ask that it be assigned to me. I've worked on a number of these hacked forums and no what to look for.
            Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
            Change CKEditor Colors to Match Style (for 4.1.4 and above)

            Steve Machol Photography


            Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


            Comment

            • CSU-CYS
              Member
              • Sep 2002
              • 58

              #7
              Thank you again Steve.
              Looks like i'll have to renew my licence and add members area access. Will do ASAP.
              www.cystinuria.org
              www.cystinuria.org/forums

              Comment

              • 99Percent
                New Member
                • Sep 2002
                • 11

                #8
                I got hacked. My fault for not upgrading on time.

                The recorded ips are 212.138.47.11, 212.138.47.29, 212.138.47.20, 212.138.47.17, 212.138.47.16 22/JAN/2005 06:32 CST

                He first did a yahoo search for "powered by vbulletin" with the version number
                Last edited by 99Percent; Sat 22 Jan '05, 11:24am.

                Comment

                • teach1st
                  Senior Member
                  • May 2000
                  • 116

                  #9
                  Interesting. I've had 212.138.47 blocked for a long time on both of my boards. I don't remember how I knew to block it.

                  Saudi Arabia, right?
                  Another Fred

                  Comment

                  • 99Percent
                    New Member
                    • Sep 2002
                    • 11

                    #10
                    Can these IP's be spoofed?

                    I also got a couple of hotmail accounts that he used, one for the new member register, and another where he reset the administrator's email, not sure if they are of any use.

                    Comment

                    • DelphiVillage
                      Senior Member
                      • Apr 2002
                      • 1051
                      • 4.1.x

                      #11
                      those are proxy servers a "real hacker" isn't stupid to leave his real ip behind he .... you should contact your host as they are the only one who can properly help you also if possible you should atleast ones a week read vbulletin.com so you know about security holes and howto patch them looks like you have been the victim of a fool who whas trying to be interesting

                      Comment

                      widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                      Working...