Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Help! Forums Hacked by Northwind
 New Topic  Topic Locked
 Printer Friendly
Next Page
Author Previous Topic Topic Next Topic
Page: of 2

wcameron
New Member

55 Posts

Posted - 08 May 2002 :  09:22:33  Show Profile  Visit wcameron's Homepage
I guess I'm just the latest hack victim. My forums were hacked by someone calling themself Northwind. At first, it seemed like they simply defaced the site, changing most of my main admin settings to point to a home page at http://selintoktay.gq.nu and forums at http://forum.wardom.com/

In reality, when I changed the admin settings back, the changes were accepted, but nothing changed. I planned on restoring from a backup, and then implementing the security fixes (I know, a little too late now), but nothing seems to help. The forum defacement says "Hacked by Northwind for good", and it seems true. I have gone as far as to completely delete all snitz files, including the database, and uploaded (I think) a clean backup, and yet the defacement remains. Please help.

You can see the problem at www.MountainNature.com/forum.



Edited by - wcameron on 08 May 2002 09:26:15

crash
Advanced Member

Netherlands
2064 Posts

Posted - 08 May 2002 :  09:34:12  Show Profile  Visit crash's Homepage
can you get to the file config.asp? if so, try downloading it and check where the strConnString points to.

if you can set it to another place, do so. i have a script for you that allows you to change the admin password online (DBS file) but you will need to be able to login as admin...



Crash's Site | Crash is from
Go to Top of Page

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 08 May 2002 :  09:35:09  Show Profile  Visit Gremlin's Homepage
Make sure you apply the fixes, your members.asp does not look like its been updated to prevent them from just going back and hacking it again :(

If you go into your admin settings you will see that all they have done is changed the main configuration options, you can change them back pretty easily.

Please please update that members.asp though as soon as possible

www.daoc-halo.com


Edited by - Gremlin on 08 May 2002 09:37:38
Go to Top of Page

crash
Advanced Member

Netherlands
2064 Posts

Posted - 08 May 2002 :  10:08:18  Show Profile  Visit crash's Homepage
yes. update members.asp first, then change/edit config.asp



Crash's Site | Crash is from
Go to Top of Page

gbdg
New Member

73 Posts

Posted - 08 May 2002 :  13:57:22  Show Profile
I got hacked too - www.northbay-tu.org

Can someone on the dev team look at the site and let me know (privately please) if you spot anything I need to update please?

Greg

Go to Top of Page

shahaf
Starting Member

Israel
39 Posts

Posted - 08 May 2002 :  15:35:38  Show Profile
Your forum is a phpBB comunity as I can see so what is the connection between your forum and this forum? or mabye I missed something???
I I didn't miss a thing, you should ask for help in phpBB main comunity!

Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 08 May 2002 :  15:46:01  Show Profile  Send ruirib a Yahoo! Message
quote:

I got hacked too - www.northbay-tu.org

Can someone on the dev team look at the site and let me know (privately please) if you spot anything I need to update please?

Greg



The second post here has a link to the fixes you need to apply to your forum code.

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
Go to Top of Page

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 08 May 2002 :  18:21:09  Show Profile  Visit Gremlin's Homepage
Looks like wcameron has now been rehacked by another group of people .. this really is getting rediculous.

www.daoc-halo.com
Go to Top of Page

gbdg
New Member

73 Posts

Posted - 08 May 2002 :  19:53:56  Show Profile
I caught them in the act, and know how they are doing it. It's a mal-formed URL that reveals *ALL* member passwords, and are walking straight in the front door

Someone from the dev team please contact me - I sent an email to Huw and Mike R.

Go to Top of Page

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 08 May 2002 :  20:16:59  Show Profile  Visit Gremlin's Homepage
Please check the Security Fixes forum, this has been known about for a while and has fixes posted.

http://forum.snitz.com/forum/forum.asp?FORUM_ID=118

www.daoc-halo.com
Go to Top of Page

wcameron
New Member

55 Posts

Posted - 08 May 2002 :  21:51:16  Show Profile  Visit wcameron's Homepage
I've applied the fixes to members.asp and printer_friendly_post.asp. I've also uploaded backup copies of my forum to overwrite the changed files, as well as the snitz database. Nothing changes though. I can't seem to remove the defacements and reclaim control of the forum. I can't log in as an administrator, even though I have manually edited the database (so it should work).

Thanks to all the people that have helped me with this problem.

wcameron

Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 08 May 2002 :  21:56:44  Show Profile  Send ruirib a Yahoo! Message
Are you sure you have put the database where it should be? I ran setup.asp on your forum and most of the graphical looks are back. There are still some things that need to be changed, but needs to be changed in the database.

Hey, this can be fixed. I'm sure there is something that you are not doing right...

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
Go to Top of Page

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 08 May 2002 :  22:08:56  Show Profile  Visit Gremlin's Homepage
Sounds to me like your updating the wrong version of the DB. I've just checked and you've closed up the members.asp bug ok now anyway :) so at least thats something.

www.daoc-halo.com
Go to Top of Page

wcameron
New Member

55 Posts

Posted - 08 May 2002 :  22:37:14  Show Profile  Visit wcameron's Homepage
Hurray! I think I've got it solved. I think part of the problem had to do with the fact that while I was trying to repair one hack, another person was hacking it again. So here lies the challenge. Now that the patches have been applied, should I be safe now? I'm sure new exploits will be developed, but will this protect me on the short term? And yes, I have created entirely new passwords for all of my accounts.

Thanks again,

Ward



Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 08 May 2002 :  22:50:44  Show Profile  Send ruirib a Yahoo! Message
Yes, I think these patched will keep you safe. Anyway remember to back up the database periodically.

-------------------------------------------------
Installation Guide | Do's and Dont's | MODs
Go to Top of Page

gbdg
New Member

73 Posts

Posted - 09 May 2002 :  00:29:32  Show Profile
Now that I fixed the forum that got slammed, I checked other forums I am running. I'm not able to locate code that matches the areas being repaired to block these vulnerabilities. I copied the portion of the url that he used to attack me, and executed it against those sites - no passwords revealed (thank goodness).

Does this mean those other boards are not vulnerable to this threat?

What versions are vulnerable?

How do I determine the version of a board? I looked at config.asp and see no indication.

Thanks, what a long day this became...

Greg

Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Next Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.67 seconds. Powered By: Snitz Forums 2000 Version 3.4.07