Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Forum hacked
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

haai
Starting Member

Belgium
3 Posts

Posted - 14 August 2002 :  05:41:26  Show Profile
I have on my site also a snitz forum running. This was yesterday hacked. The default pasword was changed from the default one (admin / admin if I remember it good)

Is this hacking the continue of a bug in the forum?

You can see the hacked result in this private map: http://www.kvcwesterlo.be/forum-Hernoemd/default.asp

they changed the top-image, deleted all administrators, and changed at the top and buttom some text

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 14 August 2002 :  05:51:44  Show Profile  Visit Gremlin's Homepage
If you never changed the admin password from the default, then this was just waiting to happen.

Please make sure you read and apply all of the bugfixes listed in this forum. Or failing that if you can wait a week or so then there will be a brand new version of snitz (v3.4) available to everyone.

Kiwihosting.Net - The Forum Hosting Specialists
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 14 August 2002 :  05:52:38  Show Profile  Send ruirib a Yahoo! Message
You need to upgrade to Snitz 3.3.05. Read here how it can be done:

http://forum.snitz.com/forum/topic.asp?TOPIC_ID=30741

Make sure you change all admin passwords after restoring the forum.
Watch out, because 3.4 should be out any time now, annd it's worth upgrading again.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

D3mon
Senior Member

United Kingdom
1685 Posts

Posted - 14 August 2002 :  06:27:57  Show Profile  Visit D3mon's Homepage
The fact that the hacker is from Turkey seems to be almost as important as his 'name'!
Is Turkey the place to be for hackers these days?


Snitz 'Speedball' : Site Integration Mod : Friendly Registration Mod
"In war, the victorious strategist only seeks battle after the victory has been won"
Go to Top of Page

D3mon
Senior Member

United Kingdom
1685 Posts

Posted - 14 August 2002 :  06:33:56  Show Profile  Visit D3mon's Homepage
This seems like a silly question but here goes -

How come I can't lock the default 'admin' account?
It's common practice on servers and domains to create a new user account, give them admin rights then disable the admin account to avoid opportunist hacks on 'default' settings.


Snitz 'Speedball' : Site Integration Mod : Friendly Registration Mod
"In war, the victorious strategist only seeks battle after the victory has been won"
Go to Top of Page

davemaxwell
Access 2000 Support Moderator

USA
3020 Posts

Posted - 14 August 2002 :  07:49:11  Show Profile  Visit davemaxwell's Homepage  Send davemaxwell an AOL message  Send davemaxwell an ICQ Message  Send davemaxwell a Yahoo! Message
In v3.4, there is no default account. You MUST create the account at setup time (note: will not affect the upgrades, I don't think). This is to prevent it for when some one doesn't bother to change the original admin password. 90% of the time, this is the cause of most Snitz hacks, and v3.4 takes the steps needed to stop that.

As for why you can't lock the default admin account, it's because that way you are guaranteed to have one account that can't be changed (ie one admin can't delete the original admin account and take over). It's a catch-all to prevent abuse.

Dave Maxwell
Barbershop Harmony Freak
Go to Top of Page

D3mon
Senior Member

United Kingdom
1685 Posts

Posted - 14 August 2002 :  08:02:52  Show Profile  Visit D3mon's Homepage
Ah I C.
Good point and well made.


Snitz 'Speedball' : Site Integration Mod : Friendly Registration Mod
"In war, the victorious strategist only seeks battle after the victory has been won"
Go to Top of Page

haai
Starting Member

Belgium
3 Posts

Posted - 14 August 2002 :  08:16:46  Show Profile
I have changed the default admin-password, that wasn't the reason they could login

I'll wait until next week to update to a new version, but now there must be a (small) bug in the code so they could login yesterday...

or they were really good ;-)
Go to Top of Page

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 14 August 2002 :  08:38:23  Show Profile  Visit Gremlin's Homepage
Check the forum I linked to there was a well publicised bug in members.asp which revealed all users passwords. 3.3.05 Fixes this problem and all others to date as well. But definately wait for 3.4 if you can hold out another week or so.

Kiwihosting.Net - The Forum Hosting Specialists
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.8 seconds. Powered By: Snitz Forums 2000 Version 3.4.07