Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 My forum has been hacked
 New Topic  Topic Locked
 Printer Friendly
Next Page
Author Previous Topic Topic Next Topic
Page: of 2

lord
Starting Member

Fyro Macedonia
34 Posts

Posted - 06 May 2002 :  14:55:53  Show Profile  Visit lord's Homepage
How can this happends??? Anyone can explane how he hacked my forum ?? Somebady has hacked and delete all topics ..........

http://www.nuneworld.com/forum/default.asp

Please help

Lord


RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 06 May 2002 :  15:03:56  Show Profile
there has been a couple of security bug fixes in the past few months, did you install them?

http://forum.snitz.com/forum/topic.asp?TOPIC_ID=23660

http://forum.snitz.com/forum/topic.asp?TOPIC_ID=25363

http://forum.snitz.com/forum/topic.asp?TOPIC_ID=26770

http://forum.snitz.com/forum/topic.asp?TOPIC_ID=27354
Go to Top of Page

lord
Starting Member

Fyro Macedonia
34 Posts

Posted - 06 May 2002 :  15:16:48  Show Profile  Visit lord's Homepage
hm,

It's to late now , but the question is how he has doit ... nice to know for the next time.. and how can I see when is that happends??

Lord

Go to Top of Page

benliu
Starting Member

4 Posts

Posted - 06 May 2002 :  15:31:14  Show Profile
My forum was hacked as well - what do I need to do (or can I do) to restore the previous topics, etc. Is there files I can download to prevent this from happening again. Thanks

quote:

hm,

It's to late now , but the question is how he has doit ... nice to know for the next time.. and how can I see when is that happends??

Lord





Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 06 May 2002 :  15:34:52  Show Profile  Send ruirib a Yahoo! Message
quote:

My forum was hacked as well - what do I need to do (or can I do) to restore the previous topics, etc. Is there files I can download to prevent this from happening again. Thanks


To restore topics you need to resort to a backup of your database. Hope that you have it.
To prevent this from happening, visit the links posted by Richard above and apply the changes recommended there.

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 06 May 2002 :  15:35:22  Show Profile
If you have not done so already, read the topics that I posted a link to above.

Unless you have backed up your database, there isn't a way to retrieve data that has been deleted.
Go to Top of Page

lord
Starting Member

Fyro Macedonia
34 Posts

Posted - 06 May 2002 :  15:40:39  Show Profile  Visit lord's Homepage
where he attack?? he use some variables (JS OR VB) on this screen or he using same another way??? My forum is still updated you can try to doit what he has done ...


Lord

Go to Top of Page

benliu
Starting Member

4 Posts

Posted - 06 May 2002 :  15:56:13  Show Profile
Thanks for the reply. Fortunately, I think I can get the database restored.

For future reference, where are security fixes/bug fixes posted?

Regardless, the forums have been great, and it was our fault for not updating the files. Thanks for the great product.

Ben

quote:

If you have not done so already, read the topics that I posted a link to above.

Unless you have backed up your database, there isn't a way to retrieve data that has been deleted.



Go to Top of Page

benliu
Starting Member

4 Posts

Posted - 06 May 2002 :  16:19:04  Show Profile
Also, without knowing what the hacker did, after I apply the fixes, will he be able to hack into it again?

Basically, is it possible that he granted himself admin access to a particular user and then can now legitimately log in and delete everything? Any idea? Thanks

Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 06 May 2002 :  16:26:56  Show Profile  Send ruirib a Yahoo! Message
You may want to subscribe to Snitz mailing lists: http://forum.snitz.com/forum/topic.asp?TOPIC_ID=13441

The security fixes are usually posted at the Announcements: Community forum or the Dev Bug Reports forum.

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 06 May 2002 :  16:34:28  Show Profile  Send ruirib a Yahoo! Message
quote:

Also, without knowing what the hacker did, after I apply the fixes, will he be able to hack into it again?

Basically, is it possible that he granted himself admin access to a particular user and then can now legitimately log in and delete everything? Any idea? Thanks


I would say he won't be able to do it, admiting that he used one of the known security issues. You may want to take a look at your server's logs to know what he did.

Regarding the Admin status he may have granted some other user just have a look at the member's list to see if you can find someone who has an Administrator level unduly granted.

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
Go to Top of Page

benliu
Starting Member

4 Posts

Posted - 06 May 2002 :  17:13:58  Show Profile
Thanks for the replies..

Last question:

What exactly was the hacker able to do? Did he actually gain admin access and was he able to change configuration options, etc? Thanks




Go to Top of Page

HandAble.com
Starting Member

15 Posts

Posted - 06 May 2002 :  17:19:58  Show Profile  Visit HandAble.com's Homepage
quote:

What exactly was the hacker able to do? Did he actually gain admin access and was he able to change configuration options, etc? Thanks



Without saying how they did it.. What they did was trick Snitz into displaying all of the passwords for all the members of the system. Therefore, even after applying the fix, you still need to consider your admin passwords to be known and change them.

----
http://HandAble.com
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 06 May 2002 :  17:21:47  Show Profile  Send ruirib a Yahoo! Message
quote:

Thanks for the replies..

Last question:

What exactly was the hacker able to do? Did he actually gain admin access and was he able to change configuration options, etc? Thanks


Admiting that he explored the members.asp security problem quite likely he obtained passwords (quite likely the admin(s) password(s)) and logged in as admin. Whatever he did after you probably can tell. As I told youy before, a look at your Web server's log can be helpful to allow you an overall picture of what he did, including finding his IP. With his IP you can probably report him to his Internet Provider to see if he can get some punishment for what he did...

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs


Edited by - ruirib on 06 May 2002 17:25:01
Go to Top of Page

Cryptik
Starting Member

30 Posts

Posted - 07 May 2002 :  15:04:05  Show Profile
Does the latest release contain all the file changes.


Cryptik

Go to Top of Page

gbu_moon
Starting Member

USA
9 Posts

Posted - 07 May 2002 :  15:57:28  Show Profile  Visit gbu_moon's Homepage  Send gbu_moon an AOL message  Send gbu_moon an ICQ Message  Send gbu_moon a Yahoo! Message
i just did all of the changes but when i finished i went to my forum and here's what i saw:

--------------------------------------------------
Microsoft VBScript compilation error '800a0400'

Expected statement

/forum/inc_functions.asp, line 2

\par
^

--------------------------------------------------

is there any way i can just download the latest 'secure' files:
- inc_functions
- members
- pop_pword

because from the download page i clicked on 'download latest version' and the changes weren't applied to those files.

thanks, [GBU]Moon


Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Next Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.43 seconds. Powered By: Snitz Forums 2000 Version 3.4.07