Squatter forum hacked.

Talk about other football teams at all levels. AND ANY Glos City related threads, even if talking about the groundsharing.

Moderators: Admin, Ralph, asl, Robin

User avatar
Malabus
Posts: 13348
Joined: 20 Nov 2009, 12:26
Location: The Death Star.
http://cof.tigerroar.co.uk/showthread.p ... rum-reboot" onclick="window.open(this.href);return false;

Poor regular maintenance and supervision by the administrator is more likely the reason for the site to be attacked by hackers. Thank goodness our Andrew knows how to look after a public forum correctly.
Last edited by Malabus on 18 Sep 2013, 21:23, edited 1 time in total.
User avatar
taxidave
Posts: 3510
Joined: 20 Nov 2009, 09:56
Location: Crewe station buffet, wish I'd stayed there!
http://www.robinsnestforum.co.uk/viewto ... =3&t=14477" onclick="window.open(this.href);return false;
asl
Posts: 6720
Joined: 20 Nov 2009, 09:37
Perhaps they could rent a forum page on the Nest? Best make 'em pay up front, Andy!
User avatar
Malabus
Posts: 13348
Joined: 20 Nov 2009, 12:26
Location: The Death Star.
asl wrote:Perhaps they could rent a forum page on the Nest? Best make 'em pay up front, Andy!
Perhaps they don't bother at all...3 posts added in a normal week.
Ralph
Posts: 4841
Joined: 23 Dec 2009, 01:56
asl wrote:Perhaps they could rent a forum page on the Nest? Best make 'em pay up front, Andy!
good idea.. lets help them.. again :)

i'd suggest Mal being an admin on it too.
RegencyCheltenhamSpa
Posts: 29817
Joined: 21 Nov 2009, 03:27
Hacking...using a site you don't pay for to offer a service below the standard the intended purpose. The on-line equivalent of a ground hire at a Football League club by a Parkball team who don't pay!
Neil
Posts: 286
Joined: 03 Mar 2013, 10:17
Is the proper plural for moron actually mora?
Admin
Site Administrator
Posts: 892
Joined: 19 Nov 2009, 21:34
I actually sympathise here with Neil Im afraid - a lot of hard work goes into running and maintaining a forum and I can say we have had problems with this forum - albeit at the time I was employing the services of someone to look after my business websites and subsequently this one so it was quickly recovered from a recent backup at the time.

Just to let you know though that from (possibly) this weekend I will no longer be Admin / owner / maintaining the forum as plans are in place to move things over soon.

Last nights maintenance unfortunately was required because of new servers by my current hardware host but glad to say things went smoothly by the looks of it.

Good luck Neil in getting things back up and running (after all we dont want you all coming over here and posting :) ).
RegencyCheltenhamSpa
Posts: 29817
Joined: 21 Nov 2009, 03:27
Neil wrote:Is the proper plural for moron actually mora?
No, you're thinking of fora - but that requires more than one forum being operational.
User avatar
taxidave
Posts: 3510
Joined: 20 Nov 2009, 09:56
Location: Crewe station buffet, wish I'd stayed there!
Perhaps Neil's forum has been hit by someone posting pornographic images on it. :roll:
Admin
Site Administrator
Posts: 892
Joined: 19 Nov 2009, 21:34
Neil,

Have you seen this:

http://www.vbulletin.org/forum/showthread.php?t=301904" onclick="window.open(this.href);return false;


Andy.
User avatar
Malabus
Posts: 13348
Joined: 20 Nov 2009, 12:26
Location: The Death Star.
taxidave wrote:Perhaps Neil's forum has been hit by someone posting pornographic images on it. :roll:
At least somebody is posting on there.
Neil
Posts: 286
Joined: 03 Mar 2013, 10:17
Admin wrote:Neil,

Have you seen this:

http://www.vbulletin.org/forum/showthread.php?t=301904" onclick="window.open(this.href);return false;


Andy.
Yep, he's the blighter. It's all well and good trying to tidy up the mess but they also say he's installed a back door so I'm just going to go for a clean start.
Admin
Site Administrator
Posts: 892
Joined: 19 Nov 2009, 21:34
Good luck with it Neil - by a clean install I assume you mean database as well so everyone will have to re-register - only saying that because apparently the hacker manages to set up an admin account within the database by looking at the comments on that thread.
Neil
Posts: 286
Joined: 03 Mar 2013, 10:17
Yep. I'm thinking that that's the only full way of kicking him out.
Admin
Site Administrator
Posts: 892
Joined: 19 Nov 2009, 21:34
If I wasnt so busy with other things (eldest off to Uni, work etc), I would have offered to assist if you needed it but cant sorry.

Hope it goes well.

Andy.
ctfc-fan
Posts: 1925
Joined: 06 Jan 2010, 12:00
Admin wrote:Good luck with it Neil - by a clean install I assume you mean database as well so everyone will have to re-register - only saying that because apparently the hacker manages to set up an admin account within the database by looking at the comments on that thread.
You should be able to find one if they have.

Neil if you need any assistance, let me know.
Neil
Posts: 286
Joined: 03 Mar 2013, 10:17
I wouldn't even want to try, most of that language is over my head. I can install and keep the forum up to date but don't see the harm in flushing it now and again.
ctfc-fan
Posts: 1925
Joined: 06 Jan 2010, 12:00
What control panel do you use on your hosting, CPanel?
Neil
Posts: 286
Joined: 03 Mar 2013, 10:17
I believe it is, I don't really play around with it too much.
ctfc-fan
Posts: 1925
Joined: 06 Jan 2010, 12:00
If you haven't sorted it yet, you can easily see if there is an additional db user added in your control panel.
Neil
Posts: 286
Joined: 03 Mar 2013, 10:17
Done that, there were two additional users.
ctfc-fan
Posts: 1925
Joined: 06 Jan 2010, 12:00
Now deleted Neil?

I'm assuming your main password has been changed and to something very strong?

You could also download all the files to your hard drive and then list them by date modified to see what was changed around the date it happened.
Daveangel
Posts: 663
Joined: 15 Dec 2009, 21:24
Well I must say this is all very civil :D
Admin
Site Administrator
Posts: 892
Joined: 19 Nov 2009, 21:34
Makes for an easy first day in charge :D

I think when it comes to football everyone can be friends deep down.
C.V
I think its very admirable of Admin/Paul to offer his help to Neil.
Neil
Posts: 286
Joined: 03 Mar 2013, 10:17
ctfc-fan wrote:Now deleted Neil?

I'm assuming your main password has been changed and to something very strong?

You could also download all the files to your hard drive and then list them by date modified to see what was changed around the date it happened.
They didn't hack my account, they signed up and made themselves administrators through a hack in the forum software.
User avatar
taxidave
Posts: 3510
Joined: 20 Nov 2009, 09:56
Location: Crewe station buffet, wish I'd stayed there!
Why is it down again ??
ctfc-fan
Posts: 1925
Joined: 06 Jan 2010, 12:00
Yes but what they do when they're in to your server is put hidden code within your existing files and new pages in deep folders. That way, when they want to call it, they can use it for further devious purposes, such as distributing viruses etc.

So you need to first update your core code from the developers, remove any offending code, remove him as a forum admin and remove him as a db user.
RegencyCheltenhamSpa
Posts: 29817
Joined: 21 Nov 2009, 03:27
Why would someone want to hack a small football forum?
Andy
RegencyCheltenhamSpa wrote:Why would someone want to hack a small football forum?
Its not always the size of the item attacked but the fact that you have caused complete mass mayhem on a vast amount of forums using the same software - they just write the code for the bot to then search out and attack any site that runs the particular version of forum code you know had a vulnerability.
RegencyCheltenhamSpa
Posts: 29817
Joined: 21 Nov 2009, 03:27
Fair enough.
ctfc-fan
Posts: 1925
Joined: 06 Jan 2010, 12:00
Andy wrote:
RegencyCheltenhamSpa wrote:Why would someone want to hack a small football forum?
Its not always the size of the item attacked but the fact that you have caused complete mass mayhem on a vast amount of forums using the same software - they just write the code for the bot to then search out and attack any site that runs the particular version of forum code you know had a vulnerability.
And the collective damage they could then cause.
Daveangel
Posts: 663
Joined: 15 Dec 2009, 21:24
It's bloody annoying, I'll give it that. Trying to arrange coaches to away games is hard enough as it is without being unable to advertise them properly. Resorting to a bloody great blackboard by the turnstile on Sunday, but knowing our luck the fecking thing will probably get infected with woodworm!
User avatar
Malabus
Posts: 13348
Joined: 20 Nov 2009, 12:26
Location: The Death Star.
Daveangel wrote:Trying to arrange coaches
Why are you using a plural....?
Post Reply