/cry hacked again
Miscellaneous Forums/General Discussion//cry hacked again
For the second time in under 12 months :( This time my forums are hit:
http://www.bansheestudios.com/forumsI was just using phpBB2, and I didn't keep the install up too date :(.
Seems this guy is on a role with regards to exploting phpBB forums.
http://www.google.com/search?q=Yusuf+Kara
I must say, he is quite the loser to blow that much time ruining peoples attitudes towards script-kiddies.
I just hope the content of the forum database is intact so that I can get it back.
Following some of the links that Google search brings up looks hopefull as you can get into some of those forums, installing phpBB2 again might solve the problem by replacing the effected files.
Yes, this "Yusuf Kara" appears to be a very large rodent.
Looks like "Mr Kara" is trying to play catch-up/impress his friends.
"iskorpitx", who he greets in his defacements, is somewhat (by a large margin) above him - he has been going after government computers in various countries.
I had a similar problem on my forum. You're probably way ahead of me on this, but here's what I found:
I forget the precise details, but he'd either started a forum topic, or made a user account with some code in the name, so as soon as the index page came up, showing the last topic in each section or newest user or whatever, it ran the code showing the "LOL YOU GOT PWNED" page.
I wasn't hit by the same guy as you, so it might be different.
All I had to do, though, was use PHPMyAdmin to browse the forum SQL database, find the most recent user/topic (I have a feeling it was user, now I think about it) and change their name. Then I could run PHPBB2 normally again, delete the member and upgrade it so it wouldn't happen again.
Hope that's some help.
I've removed his damage, now I just need to install the latest phpBB2 to close the security leak.
The problem was a phpBB cookie that had a security leak allowing him incremental security acess with which he was then able to create a new forum in which he used the forum description to put in html code that displayed his tag.
This was easy to remove with phptoolkit, the update of phpBB to protect against it happening again is going to be more of a pain though...
http://www.bansheestudios.com/forums/viewtopic.php?t=180Just a note on that, its not illegal if the spammer is outside European Union and if the laws where the presumed "spammer" lives doesn't criminalise spamming. For example if in Finland spamming would be legal then I could spam your boards all day long and all you could do is ban me.
The government backs up it's laws with policemen who, if you do not pay your protection racket fee's (tax) come around in force, take you away, and lock you up in a cell thus depriving you contact with the outside world.
The mafia and other syndicates back up their laws with thugs who, if you do not pay your protection racket fee's come around in force, take you away, and chop you into into small pieces.
I back up my laws with PMT.
By all accounts, i'm by far the most dangerous.
I think spamming is illegal in Finland incidentally, but as most spammers are American and Russian it's a moot point (source: spamhous.org)
contact with the outside world.
contact with the outside world... in a lot of cases, a highly overrated passtime... but necessary to acheive some sort of balance and perpective in your life...
I back up my laws with PMT
PMT ??? or did you mean PMS :)
(*** runs and hides from the lawgiving goddess ***)
By all accounts, i'm by far the most dangerous
yes you are... as are all women :) i accept that indisputable fact of life... and live under it's mandates...
:)
hey... good luck getting back online...
guys who do stuff like this are sociopathetic scum... they need a lil 'metal pipe against the knee caps' type of counseling, just to help em see the error of their ways...
--Mike
This is apprently exactly what happened to me. First thing I did: get the very last version of phpbb.
aye, i'm updating phpBB now - which is proving far more difficult than removing the damage done by the hacker. Sadly my first attempt didn't take and so now i'm trying again.
I really should have backed up the database first... oops
most spammers just need a person of their opposite sex to get busy with them once in a blue moon... that or a real job!
most spammers just need a person of their opposite sex to get busy with them once in a blue moon
You misspelled "persons wearing badly-fitting black suits and sunglasses, carrying violin cases"
Have you thought about changing your forum software? phpBB2 gets hacked way more than any other forum software I know.
An excellent free one which is very actively supported is SMF from www.simplemachine.org - It's very secure and updates can be applied via the admin panel automatically without you having to mess around uploading any fixes yourself.
They also have phpBB2 to SMF convertors on the site. It works great :)
*EDIT* should be www.simplemachines.org
Qube:
Following that link gives me the following:
"Notice: Only variables should be assigned by reference in /home/simplem/public_html/smf/Sources/Subs.php on line 232
Notice: Undefined index: is_admin in /home/simplem/public_html/smf/Sources/Security.php on line 552
Notice: Undefined index: permissions in /home/simplem/public_html/smf/Sources/Security.php on line 559
Warning: in_array(): Wrong datatype for second argument in /home/simplem/public_html/smf/Sources/Security.php on line 559
session_start(): Cannot send session cookie - headers already sent by (output started at /home/simplem/public_html/smf/Sources/Subs."
Not exactly instilling a lot of confidence there. :-?
I would rather stick with phpBB2 at the moment (I do now have the latest version) because I like the forums it produces and although the board may get defaced one in a blue moon - at least the forum users themselves are safe as i'm not aware of any malliscious attacks that can be done on them like with some others such as ezboard or that yabbse one.
XL... LOL!!! : )