Is this a server level attack or are they hacking the vbulletin login?
Announcement
Collapse
No announcement yet.
Announcement
Collapse
No announcement yet.
Hacking
Collapse
X
-
They were able to install code directly into vBulletin.
I paid $100 to have the host company clean the code out and reinstall a clean backup. We are now verified clean. I also added a $1 a month service that I wasn't aware of that monitors everything in the DB and red flags any code changes.
I blame all of the NSA chatter on this
-
Originally posted by Moonlight J View PostThey were able to install code directly into vBulletin.
I paid $100 to have the host company clean the code out and reinstall a clean backup. We are now verified clean. I also added a $1 a month service that I wasn't aware of that monitors everything in the DB and red flags any code changes.
I blame all of the NSA chatter on this
So I guess they hacked admin level access. Did they tell you how this occurred? Any logs?
Maybe we need to make sure anyone with admin access doesn't have "password" as their password? Could be that simple
Comment
-
There are only 2 admin accounts - myself and Revo. We've both changed our passwords. Mine was always involving letters, numbers, and signs.
There was a 3rd account for siteground admin but I shut them off and disabled all registrations for the next few weeks. The hosting company gave me a log of the code that did it but don't think they can find the actual offender. I'm going to go through and purge a lot of accounts that are showing inactivity.
If people want to volunteer as a mod to help with that, I'm all ears.
Comment
-
FYI, my prior bookmark - http://forum.rotojunkiefix.com/ is now going to a default/coming soon page. I've updated it to http://forum.rotojunkiefix.com/forum.php for now, but just wanted to mention it.
Comment
-
Originally posted by Zupe View PostFYI, my prior bookmark - http://forum.rotojunkiefix.com/ is now going to a default/coming soon page. I've updated it to http://forum.rotojunkiefix.com/forum.php for now, but just wanted to mention it.
Comment
-
We have been upgraded to 4.2.1 -- check out the new "activity stream" feature above.
Again, looking for some volunteers to help with some account cleanup. I basically want to purge all of the inactive accounts, and then limit new registrations to where Revo or myself have to review the account before letting it in.
Comment
-
In reviewing our stats log, we show an unusual amount of traffic from China. Either Trader Mac has nothing better to do during the day, or we have a shit load of fantasy sports fans in China. Either way, we need to trim it back because we're also going over our plan on the hosting environment. Apparently we were causing a lot of issues on the server and we may have to move to a $70 monthly plan instead of the $300 a year plan we're on now.
Comment
-
Can you block all IP's from China? Maybe add an exception for Mac."The Times found no pattern of sexual misconduct by Mr. Biden, beyond the hugs, kisses and touching that women previously said made them uncomfortable." -NY Times
"For a woman to come forward in the glaring lights of focus, nationally, you’ve got to start off with the presumption that at least the essence of what she’s talking about is real, whether or not she forgets facts" - Joe Biden
Comment
-
Originally posted by Moonlight J View PostI can't do it through vBulletin and I'm guessing he's not on a static one where he is. When I looked at the logs, China IP is 3x higher than any other source"The Times found no pattern of sexual misconduct by Mr. Biden, beyond the hugs, kisses and touching that women previously said made them uncomfortable." -NY Times
"For a woman to come forward in the glaring lights of focus, nationally, you’ve got to start off with the presumption that at least the essence of what she’s talking about is real, whether or not she forgets facts" - Joe Biden
Comment
-
Originally posted by cardboardbox View Postcant add an exception or cant block China IP's? If you're looking at going from $300/yr to 840/yr largely due to this.... There's really only one choice.
Originally posted by Moonlight J View PostAgain, looking for some volunteers to help with some account cleanup. I basically want to purge all of the inactive accounts, and then limit new registrations to where Revo or myself have to review the account before letting it in.
Comment
Comment