Welcome Guest ( Log In | Register )

UploadScript

Check out the FREE chatroom mod for IPB 3.x

> IPB Help

IMPORTANT DISCLAIMER - PLEASE READ

You are currently in an unofficial IPB help forum where members assist other members with Invision Power Board. While you may receive help with your Invision Power Board questions in this forum it is important to note the following:

Note: Let us state again that support provided in IPB Help is provided by the kindness of others. The staff of Invisionize do not officially provide support for Invision Power Board. If you would like official support from Invision Power Services, please open a new support ticket from your Invision Power Services Customer Area page.

 
Reply to this topicStart new topic
I got HACKED! AGAIN!
bart5986
post Jul 16 2006, 11:59 PM
Post #1


Member
**

Group: Members
Posts: 197
Joined: 10-August 04
Member No.: 120,085



A while back I posted that I got hacked

I patched the shoutbox, and I thought all was well.


But now i got hacked again.


He used the SAME method too, I got the password recovery email, and then got hacked.

So what the hell should I do?


I havn't upgraded to 2.1.7 yet, but its impossible that by not upgrading I have made a new security hole.

The only thing i've found out is that both times my cpanel has said "Last login from: 127.0.0.1"

I asked my host and he said there's only two people that could access the server and leave it like that so it couldn't be my host.


So whats going on???

Luckily this time I had the admin cp restrict IP so he couldn't change anything.

But he still could use my super mod powers and go crazy!


I really need some help!


I've done some googling and it appears the IP is a public proxy, which makes sense because last time I got hacked I banned his IP area.

This post has been edited by bart5986: Jul 17 2006, 12:04 AM


--------------------
Go to the top of the page
 
+Quote Post
FuZZyLoGic
post Jul 17 2006, 12:31 AM
Post #2


Newbie
*

Group: Members
Posts: 13
Joined: 29-October 04
Member No.: 130,762
IPB Version: 2.0.x



Well not sure what mods you have installed or what vulnerabilities they have etc. But if you have upgraded your board since the last attack and he is using the same explot successfully it seems to me that your system itself may still be compromised from the last attack.

I would check all your directories for any .php or binary files that clearly should not be there. I would start with the folders that are chmodded 777 (such as your uploads directory). Also make sure there are no users in the database with admin privs and change the passwords on all the legit admin accounts. I would also chang the db pass to be absolutly safe.

If he somehow managed to gain ssh or root on the server itself then your problems are a bit bigger then your website but that would be a problem for your host to solve.

I am sure someone else is better qualified to help you here but there is my suggestions good luck

Go to the top of the page
 
+Quote Post
ssj4gogita4
post Jul 17 2006, 12:50 AM
Post #3


Squidward Tortellini
*******

Group: Members
Posts: 10,677
Joined: 19-February 05
From: Planet Vegeta
Member No.: 145,607
IPB Version: 2.3.x



I think I remember the shoutbox being reported as having an exploit in it. Not entirely sure about that but ask Dean if you need to.


--------------------
Go to the top of the page
 
+Quote Post
bart5986
post Jul 17 2006, 01:12 AM
Post #4


Member
**

Group: Members
Posts: 197
Joined: 10-August 04
Member No.: 120,085



I already fixed the shoutbox exploit.

I have already scanned my ftp directory for virus's using the IPB tool and found nothing.

All the passwords were already changed to 20 character random passwords last time I got hacked.

My server doesn't give SSH access I don't think, I don't have it in my cpanel and its not offered by my host anyway.


I'm convinced this is something to do with the password recovery thing, but i'm not sure.


Also, the guy put this in my sig.

0WN3D BY F3X

<SNIP>


ffs, he has the potential to delete everything by me having supermod powers.

Do I have to demote myself to protect myself?

This post has been edited by sully: Jul 17 2006, 03:57 AM


--------------------
Go to the top of the page
 
+Quote Post
bart5986
post Jul 17 2006, 07:07 AM
Post #5


Member
**

Group: Members
Posts: 197
Joined: 10-August 04
Member No.: 120,085



can anyone help?

I'm not sure what to do...


--------------------
Go to the top of the page
 
+Quote Post
sully
post Jul 17 2006, 09:02 AM
Post #6


Meh!
*******

Group: Members
Posts: 8,085
Joined: 11-April 03
From: Here, There, Everywhere :D
Member No.: 879



Please do not bump your own topic within 24 hours, this is against the Board Guidelines and will get the topic locked if you continue to bump it within 24 hours.

Have you followed the instructions in the pinned topic, in regards to upgrading and checking for files?

Also, there is only one new patch in IPBV2.1.7 and a new feature - Virus Scanner (similar to the tools released earlier by Matt) but its still worth upgrading as outlined in the pinned topics.

Other then that, I cant see how they are still hacking you. mellow.gif


--------------------

Alpha IT Solutions - The IT People
Alpha Design - Professional web & graphic design.
Discover Tramore - Visiting Ireland? Discover Tramore.
Go to the top of the page
 
+Quote Post
athlonkmf
post Jul 17 2006, 09:51 AM
Post #7


Member
**

Group: Members
Posts: 240
Joined: 15-January 04
Member No.: 77,027
IPB Version: Not Applicable



QUOTE(bart5986 @ Jul 17 2006, 07:12 AM) [snapback]1706842[/snapback]

I already fixed the shoutbox exploit.

I have already scanned my ftp directory for virus's using the IPB tool and found nothing.

All the passwords were already changed to 20 character random passwords last time I got hacked.

My server doesn't give SSH access I don't think, I don't have it in my cpanel and its not offered by my host anyway.


I'm convinced this is something to do with the password recovery thing, but i'm not sure.


Also, the guy put this in my sig.

0WN3D BY F3X

<SNIP>


ffs, he has the potential to delete everything by me having supermod powers.

Do I have to demote myself to protect myself?



have you changed your password and used the option, make new salt?

Because it seems that he simply still has the cookie with your loginkey.

But still, without looking into your logs or see the situation ourselves, there isn't much we can do to help you.

This post has been edited by athlonkmf: Jul 17 2006, 09:52 AM


--------------------
Go to the top of the page
 
+Quote Post
Clonxy
post Jul 17 2006, 02:15 PM
Post #8


Advanced Member
***

Group: Members
Posts: 381
Joined: 6-March 06
Member No.: 208,463



use .htacess and protect ur shoutbox folder from being accessed by everyone.
yes, folder, not files, but folder

This post has been edited by Clonxy: Jul 17 2006, 02:15 PM


--------------------
www.stelity.com
Go to the top of the page
 
+Quote Post
bart5986
post Jul 18 2006, 04:55 AM
Post #9


Member
**

Group: Members
Posts: 197
Joined: 10-August 04
Member No.: 120,085



nevermind I found out what it was..

QUOTE
"D21-Shoutbox v1.1 Exploit Admin Password Change"
Orginal Exploit Found by Windak & langtuhaohoa
POC of the exploit was released earlier today, and it works.


--------------------
Go to the top of the page
 
+Quote Post
sully
post Jul 18 2006, 05:05 AM
Post #10


Meh!
*******

Group: Members
Posts: 8,085
Joined: 11-April 03
From: Here, There, Everywhere :D
Member No.: 879



I was just coming here to post that. There is no security patch for the Shoutbox Mod, I dunno where you got that from?

Also; Thats most likely the cause of the problem.


--------------------

Alpha IT Solutions - The IT People
Alpha Design - Professional web & graphic design.
Discover Tramore - Visiting Ireland? Discover Tramore.
Go to the top of the page
 
+Quote Post
JcLusso
post Jul 18 2006, 06:28 AM
Post #11


Newbie
*

Group: Banned
Posts: 76
Joined: 22-June 06
Member No.: 229,645
IPB Version: Not Applicable



Hey if you havent put ips in the ip restirction mod it wont do anything. You have to enter your ip and any other member that you want to have access to the admin cp. Becareful tho because if you put it in wrong you can lock yourself out so and then you have to delete the admin cp and put it back. maybethis guy is hacking your ftp and removing the ip restricition mod if you have ips in it. that is the only posssile way he could be getting in. Also I think you should install the LSS mod Login Security System. I have it and if someone enters the password wrong what ever amount of times you pick you can make it so they are locked out for a certain amount of time or email verfication. I have the email verfication and 4 wrong passwords. If you set it to time it wont really prove it is the real member. Also maybe install the BAX Admin Mod.THis mod shows you how to change the name of the acp so even if one of the admin account that has acp access gets hacked when they click the link it say a not found error for the admin.php. The only weay he can access your acp is if he can figure out the file name but if you make it random it will be very difficult.

Just tought this mite help.

-JcLusso-


--------------------

^ ^ ^ Made For Me By Legend For FREE ^ ^ ^
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



RSS Lo-Fi Version Time is now: 16th March 2010 - 12:26 AM
Invision Skins · IPB Skins