Welcome, Guest. Please Login or Register.
April 08, 2025, 08:41:59 AM
Home Help Search Log in Register
News: If you are still using YaBB SE, please consider upgrading to SMF as soon as possible.

YaBB SE Community  |  English User Help  |  English Help  |  Hacker hacking me off « previous next »
Pages: [1] Reply Ignore Print
Author Topic: Hacker hacking me off  (Read 327 times)
rkennedy
Noobie
*
Posts: 3


Hacker hacking me off
« on: September 10, 2003, 03:43:24 PM »
Reply with quote

YaBB SE Version: 1.5.4
PHP Version: 4.3.0
MySQL Version: 3.23.x
Server Platform: Unix, Linux, or BSD
Link to Forum:

Problem Description:
For almost two weeks now, I've been manually going out to my site and reloading all the files for our club's YaBB SE message board.  Once a day, all of the source files are deleted (except for the YaBBHelp and YaBBImages directory).

My thinking is that it's an automated process that trees down the directory structure searching for YaBBSE boards because I installed two boards under different directory names, and they were both removed the next day.

I feel confident in saying that they don't know the username/password to the account; otherwise, they would do more damage than this.  This also continued even after I changed the password to the account for Telnet/FTP.

Does anyone know of any security breaches at this time or has anyone else been experiencing these problems over the past couple of weeks?  I don't feel like I'm being singled out, but it's becoming annoying.

Please provide help before I end up switching to a different message board completely!   :'(
Logged
Shadow's Pawn
Support Team
YaBB God
*****
Posts: 597


ich soll nicht toten

ICQ - 8039201shadowpawn@hotmail.com WWW
Re:Hacker hacking me off
« Reply #1 on: September 10, 2003, 04:24:27 PM »
Reply with quote

If this was an issue with the board itself, I can almost guarantee you that it would be an issue with other boards as well.

Have you talked to your host?  Checked your server logs?
Logged

apologize \A*pol"o*gize\, v. i. - To lay the foundation for a future offense.
rkennedy
Noobie
*
Posts: 3


Re:Hacker hacking me off
« Reply #2 on: September 10, 2003, 05:25:04 PM »
Reply with quote

I contacted the host provider a few days after it happened and had them to increase the access-log limit since they were only storing that last 6K for me.  I didn't notice anything out of sorts, but I did discover an IP address hitting the site from Germany which seemed a little odd.  Our site is a local cycling club, so I didn't think it would be anything interesting for someone over there to be viewing.

Here's another odd thing about the problem.  Most of the time, I'll hit the site, and I'll receive an error to the effect of "file not found"; however, there are times, when the board will load except for the icons.  This generally cues to me that the board has been hacked because if I click on anything on the board after receiving this screen, then I receive the "file not found" error.  It's almost as if by me accessing the site that I've destroyed the files myself, but how?

I'll watch the access logs closer and try to supply more specifics tomorrow.  Like I said earlier, this happens once a day, so I'll have to wait for the information...
Logged
Douglas
aka The Bear
Support Team
YaBB God
*****
Posts: 1050


Bears rule! Llamas rule too!

WWW
Re:Hacker hacking me off
« Reply #3 on: September 10, 2003, 06:11:11 PM »
Reply with quote

http://www.yabbse.org/community/index.php?thread=15904

Make DAMN sure that you're doing this, okay.  :)
Logged

Need help? Please SEARCH first.  No need for a bad attitude, we like helping positive minded people.
ComeHit.us Short URL  redirection svcs with YSE powered forums, COMING SOON!
Want to say thanks?  Check out http://comehit.us/?u=3
rkennedy
Noobie
*
Posts: 3


Re:Hacker hacking me off
« Reply #4 on: September 10, 2003, 06:54:24 PM »
Reply with quote

I've already reviewed this document a couple of days ago before posting.  I honestly don't feel like it's anyone infiltrating the system via an username/password.  None of the database data is deleted or manipulated...just the source code files are gone.  My thinking is that someway...somehow...there's a process using one of the PHP files to deliberately remove directories and source code files.
Logged
Douglas
aka The Bear
Support Team
YaBB God
*****
Posts: 1050


Bears rule! Llamas rule too!

WWW
Re:Hacker hacking me off
« Reply #5 on: September 10, 2003, 08:37:21 PM »
Reply with quote

Download your entire FTP area to your hard drive, and put things back one at a time, after checking to make sure that you know what that file does.  Best way to make sure it's not anything within your FTP area.
Logged

Need help? Please SEARCH first.  No need for a bad attitude, we like helping positive minded people.
ComeHit.us Short URL  redirection svcs with YSE powered forums, COMING SOON!
Want to say thanks?  Check out http://comehit.us/?u=3
David
Destroyer Dave
Global Moderator
YaBB God
*****
Posts: 5761


I'm not a llama!

WWW
Re:Hacker hacking me off
« Reply #6 on: September 12, 2003, 02:32:54 PM »
Reply with quote

Ask your host for ftp login logs.  Also what control panel do they use on the server and do they offer ssh access?  If they do not use a jailshell then anyone else on your server could theoretically see and delete any of your files.  Considering YaBB SE has no means to delete files I don't see it as being their point of entry.
Logged

Pages: [1] Reply Ignore Print 
YaBB SE Community  |  English User Help  |  English Help  |  Hacker hacking me off « previous - next »
 


Powered by MySQL Powered by PHP YaBB SE Community | Powered by YaBB SE
© 2001-2003, YaBB SE Dev Team. All Rights Reserved.
SMF 2.1.4 © 2023, Simple Machines
Valid XHTML 1.0! Valid CSS

Page created in 0.172 seconds with 21 queries.