Welcome, Guest. Please Login or Register.
November 21, 2024, 08:30:55 PM
Home Help Search Log in Register
News: SMF is the next generation in forum software, almost completely re-written from the ground up, make sure you don't fall for cheap imitations that suffer from feature bloat!

YaBB SE Community  |  English User Help  |  English Help  |  Just been hacked :-( « previous next »
Pages: 1 [2] Reply Ignore Print
Author Topic: Just been hacked :-(  (Read 10768 times)
PioneeR
Llama Hunter
YaBB God
*****
Posts: 767


Re:Just been hacked :-(
« Reply #15 on: June 20, 2002, 06:34:29 PM »
Reply with quote

Yeah.. that works...  ;D

Once I have updated the members... will do a ickle update on the message table to point to the right memberid (after being deleted... it got reset to -1)

Logged
andrea
Global Moderator
YaBB God
*****
Posts: 4400


Peace on Earth

WWW
Re:Just been hacked :-(
« Reply #16 on: June 20, 2002, 07:13:45 PM »
Reply with quote

Quote from: PioneeR on June 20, 2002, 06:34:29 PM(after being deleted... it got reset to -1)
Got reset to -1 ? That is strange ...
Logged

PioneeR
Llama Hunter
YaBB God
*****
Posts: 767


Re:Just been hacked :-(
« Reply #17 on: June 20, 2002, 07:16:22 PM »
Reply with quote

yeah, it looks like when a member is deleted... what ever posts they have ever made.. the memberid on that post gets set to -1!?

Is this right??
Logged
PioneeR
Llama Hunter
YaBB God
*****
Posts: 767


Re:Just been hacked :-(
« Reply #18 on: June 20, 2002, 07:57:07 PM »
Reply with quote

I have restored all my members from a recentish backup.

All i have to do know is update the message table with the member_ids!

I am not very good as SQL at all...

How would I go about doing this...

updating yabbse_messages/ID_MEMBER with yabbse_members/ID_MEMBER using  (when yabbse_messages/posterName = yabbse_members/memberName)

if that makes sense?

Logged
PioneeR
Llama Hunter
YaBB God
*****
Posts: 767


Re:Just been hacked :-(
« Reply #19 on: June 20, 2002, 08:20:21 PM »
Reply with quote

This works works ok... just wondered if there was a quicker way to do all members automatically!?

update yabbse_messages set ID_MEMBER=24 where posterName="admin";
Logged
PioneeR
Llama Hunter
YaBB God
*****
Posts: 767


Re:Just been hacked :-(
« Reply #20 on: June 20, 2002, 09:47:12 PM »
Reply with quote

Have restored my board now..

What can i do to make it safer??

Logged
andrea
Global Moderator
YaBB God
*****
Posts: 4400


Peace on Earth

WWW
Re:Just been hacked :-(
« Reply #21 on: June 21, 2002, 05:52:44 AM »
Reply with quote

Quote from: PioneeR on June 20, 2002, 09:47:12 PMHave restored my board now..

What can i do to make it safer??
    [*]First of all: change your passwords (probably you already did). And make sure the following 3 passwords are all *different*:
    - ftp password
    - phpmyadmin password
    - db access password (the one that is in the file "Settings.php")
    The most important is that the password that is written in the file "Settings.php" is *not* equal to either of your ftp password or your phpMyAdmin password.
    Furthermore make sure that the passwords are hard to be guessed.
    [*]backup frequently, make sure you know how to restore (db data and html data)
    [*]check the file protections in your board, reduce them to the minimum that is required to keep the board running
    [*]delete install files such as install.php, archive.ya, converter.php etc.
    [*]make sure that your YaBB SE admin user password is hard to guess and again different from the passwords above. The same for other admin members in your board.
    [*]clean the YaBB SE error log (in the admin menu) after each login failure with your YaBB SE admin user
    [/list]
    « Last Edit: June 21, 2002, 06:44:28 AM by andrea » Logged

    andrea
    Global Moderator
    YaBB God
    *****
    Posts: 4400


    Peace on Earth

    WWW
    Re:Just been hacked :-(
    « Reply #22 on: June 21, 2002, 06:04:51 AM »
    Reply with quote

    Quote from: PioneeR on June 20, 2002, 07:16:22 PMyeah, it looks like when a member is deleted... what ever posts they have ever made.. the memberid on that post gets set to -1!?

    Is this right??
    Question did you delete the "converter.php" after the installation ?  I believe to remember that somebody wrote that it is possible to create an admin account with that if it is not deleted. Not sure if it was referring to the installer or to the converter.
    « Last Edit: June 21, 2002, 06:13:40 AM by andrea » Logged

    Jeff Lewis
    Global Moderator
    YaBB God
    *****
    Posts: 10149


    I'm a llama!

    WWW
    Re:Just been hacked :-(
    « Reply #23 on: June 21, 2002, 12:16:27 PM »
    Reply with quote

    Yes, when a member is deleted, their posts are assigned -1 which is a guest post.
    Logged

    PioneeR
    Llama Hunter
    YaBB God
    *****
    Posts: 767


    Re:Just been hacked :-(
    « Reply #24 on: June 21, 2002, 07:17:54 PM »
    Reply with quote

    Quote from: andrea on June 21, 2002, 06:04:51 AMQuestion did you delete the "converter.php" after the installation ?  I believe to remember that somebody wrote that it is possible to create an admin account with that if it is not deleted. Not sure if it was referring to the installer or to the converter.

    I didnt delete it. But I 'thought' I had done a chmod on it to stop it being run. But I am not 100% sure one that.

    My admin password to my board isnt a common word.. so they must have created an account some how (or at least overwritten my admin account)

    I have deleted install.php/converter.php now though.

    If this is a potential way to hack into a board.. maybe a warning to others to check their yabb directory and make sure they delete the install/setup and convert files.

    Its not much fun restoring... took me 5-6 hours to get my board up and running. Luckily the hacker didnt delete the posts (all 27,000 of them!).

    It seems quite a few hosts dont backup mysql server that often, they rely on RAID etc.

    And with the added inconvience of a 30 second timeout on the execution of any script! I still cant backup my Message table (all others are ok though). The best I can do for the moment, is cope the Message table to another database, better that nothing.

    So if you read this, please be aware of the dangers of leaving your install/setup files live on your server. Delete them now!!
    Logged
    Pages: 1 [2] Reply Ignore Print 
    YaBB SE Community  |  English User Help  |  English Help  |  Just been hacked :-( « previous - next »
     


    Powered by MySQL Powered by PHP YaBB SE Community | Powered by YaBB SE
    © 2001-2003, YaBB SE Dev Team. All Rights Reserved.
    SMF 2.1.4 © 2023, Simple Machines
    Valid XHTML 1.0! Valid CSS

    Page created in 0.023 seconds with 20 queries.