Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Cookie problem again
 New Topic  Topic Locked
 Printer Friendly
Next Page
Author Previous Topic Topic Next Topic
Page: of 2

HooH
Starting Member

37 Posts

Posted - 10 December 2002 :  12:41:23  Show Profile
Hi

My page has just been hacked again.

I use Snitz Forums 2000 Version 3.4.03

I have checked the server log, at seems like the guy changed something in the cookie and logged on as a moderator and then deleted a whole topic.

It seems like he uses the same SessionID but he changes the username -
How can I prevent this to happen again?

Anyone got any suggestions?

/HooH

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 10 December 2002 :  12:52:54  Show Profile  Send ruirib a Yahoo! Message
Why do you say he changed something in the cookie? The member level is maintained in the database so there is no way he may have changed any info related to him. What may have happened is that the last time he hacked your forum (this is a presumption based on your statement about being hacked again) he got the access data for a moderator and he is using it now. Did you change all admin and mods passwords after you were hacked the first time?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

HooH
Starting Member

37 Posts

Posted - 10 December 2002 :  13:01:33  Show Profile
The hacker logged on as a moderator that wasnt even a member the last time we got hacked.


Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 10 December 2002 :  13:15:12  Show Profile  Send ruirib a Yahoo! Message
Yes, but did you change the passwords for admins and mods? Otherwise how would he found out the moderator password?
Also do you have the IP used by him? Can you post it here?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

HooH
Starting Member

37 Posts

Posted - 10 December 2002 :  15:53:07  Show Profile
we changed all the passwords for admin and mods.

His IP is 80.198.244.180
Go to Top of Page

HooH
Starting Member

37 Posts

Posted - 10 December 2002 :  16:02:45  Show Profile
do u need anything else...

I can send u some lines of the serverlog, where he logs on.. if that helps
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 10 December 2002 :  16:48:27  Show Profile  Send ruirib a Yahoo! Message
quote:
Originally posted by HooH

do u need anything else...

I can send u some lines of the serverlog, where he logs on.. if that helps


Yeah, I would like that. Can you post a link to a file containing the logs only for this guy, or email me the file?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

HooH
Starting Member

37 Posts

Posted - 11 December 2002 :  04:16:44  Show Profile
I have sent you a mail containing the link to the logfile.

thnx for helping me out!
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 11 December 2002 :  06:54:49  Show Profile  Send ruirib a Yahoo! Message
Going to have a look and let ya know if I find anything.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

HooH
Starting Member

37 Posts

Posted - 11 December 2002 :  09:32:44  Show Profile
thnx
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 11 December 2002 :  09:45:25  Show Profile
see here:

http://forum.snitz.com/forum/topic.asp?TOPIC_ID=39440
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 11 December 2002 :  10:11:26  Show Profile  Send ruirib a Yahoo! Message
HooH, I'm not sure your problem is similar to the one covered by that fix. Read the emails I've sent you, specially the last one regarding that specific moderator. Of course, you should apply the fix, nonetheless.


Snitz 3.4 Readme | Like the support? Support Snitz too

Edited by - ruirib on 11 December 2002 10:12:07
Go to Top of Page

HooH
Starting Member

37 Posts

Posted - 11 December 2002 :  10:37:29  Show Profile
thnx - I have now fixed that problem. I hope that he will stay away now.

Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 11 December 2002 :  10:41:58  Show Profile  Send ruirib a Yahoo! Message
Yes but have you made the inquiry about the moderator password?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

HooH
Starting Member

37 Posts

Posted - 11 December 2002 :  10:42:44  Show Profile
yes I have sent you a mail about it!
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 11 December 2002 :  10:44:09  Show Profile  Send ruirib a Yahoo! Message
Ah, ok. Haven't received it yet, but I'll wait for it.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Next Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.6 seconds. Powered By: Snitz Forums 2000 Version 3.4.07