Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Possible hack attack
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

clj
Junior Member

145 Posts

Posted - 20 December 2004 :  08:49:27  Show Profile
Hi everyone

Last night, all the topics in my forum were deleted. The archives remained intact, as did the 'Riding' area of the forum.

We do not know who did this, how or why.

We have looked at the IIS web logs at the time of the deletion and no-one accessed the admin_forums.asp page.

The SQL Server logs don't reveal anything nor do the server event logs.

Does anyone have any ideas how this might have happened or what we can check to track it down?

Do you think it's possible it was a database corruption?

Thanks
Clare

EDIT: Just to add, the topic/post counts were not reset to zero, they still read as high numbers (general had 892 topics I think). I performed 'update post counts' in the admin to get them correct.

Edited by - clj on 18 July 2005 10:42:52

Jorrit787
Average Member

Netherlands
681 Posts

Posted - 20 December 2004 :  08:56:21  Show Profile  Visit Jorrit787's Homepage  Send Jorrit787 an AOL message  Send Jorrit787 a Yahoo! Message
If the topic counts weren't updated it is likely that the topics were removed directly from the database... Sorry to hear this, I hope you have a backup you can restore. I suggest you make sure you change all your passwords before uploading again.

eXtremeGossip
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20584 Posts

Posted - 20 December 2004 :  09:22:10  Show Profile  Visit HuwR's Homepage
As Jorrit stated, if the topic count was intact, then it was not done via the forum code, however I notie that you are running an older version of the forum code which does have some security issues, so they probably used some kind of SQL injection hack to delete your topics, you should re-check your IIS logs, but you are not looking for access to the admin pages, look for anything that looks like a suspicious query string
Go to Top of Page

clj
Junior Member

145 Posts

Posted - 20 December 2004 :  09:38:04  Show Profile
Thanks for your replies

Could you give me any more info on SQL injection? Wouldn't they have to know the DB password to do that?

I'm looking in the IIS logs again but they are so huge the only feasible thing to do is search them, I've searched for the table names and 'delete' at about the time it happened but nothing's come up (just the delete icon) - what else can I search for?

Thanks!
Clare
Go to Top of Page

Podge
Support Moderator

Ireland
3775 Posts

Posted - 20 December 2004 :  13:03:08  Show Profile  Send Podge an ICQ Message  Send Podge a Yahoo! Message
Search your logs for delete+

Are you using SQL Server? It may be possible to restore your database to a particular point in time
(i.e. just before the attack).

Podge.

The Hunger Site - Click to donate free food | My Blog | Snitz 3.4.05 AutoInstall (Beta!)

My Mods: CAPTCHA Mod | GateKeeper Mod
Tutorial: Enable subscriptions on your board

Warning: The post above or below may contain nuts.
Go to Top of Page

clj
Junior Member

145 Posts

Posted - 20 December 2004 :  13:27:29  Show Profile
Thanks Podge

I've searched through for delete+ to no avail

I'm on SQL Server yes but I'm not too bothered about restoring the db, I just want to prevent it happening again!

I've installed all the bug fixes here http://forum.snitz.com/forum/topic.asp?TOPIC_ID=35210

Is there anything else I can do?
Thanks
Clare
Go to Top of Page

Podge
Support Moderator

Ireland
3775 Posts

Posted - 20 December 2004 :  13:59:39  Show Profile  Send Podge an ICQ Message  Send Podge a Yahoo! Message
Its a good step. The only way you will be 100% sure that you can prevent it is by finding out how it was done in the first place. It happened to me recently and I used this - http://www.sqlfe.com/downloads.asp to search the transaction logs and find out exactly how it happened.

Podge.

The Hunger Site - Click to donate free food | My Blog | Snitz 3.4.05 AutoInstall (Beta!)

My Mods: CAPTCHA Mod | GateKeeper Mod
Tutorial: Enable subscriptions on your board

Warning: The post above or below may contain nuts.
Go to Top of Page

clj
Junior Member

145 Posts

Posted - 22 December 2004 :  10:53:41  Show Profile
Thanks for helping Podge

I've recently got to the bottom of what happened - an admin gave out his password and unfortunately forgot to change it. Someone has now owned up to using his password and deleting all the topics.

Thanks for all your time and help. My forum is certainly more secure now anyway!!

Clare
Go to Top of Page

PeeWee.Inc
Senior Member

United Kingdom
1893 Posts

Posted - 22 December 2004 :  11:50:48  Show Profile  Visit PeeWee.Inc's Homepage
what did you do to the person/member who did this and the admin?

De Priofundus Calmo Ad Te Damine
Go to Top of Page

D3mon
Senior Member

United Kingdom
1685 Posts

Posted - 22 December 2004 :  14:17:44  Show Profile  Visit D3mon's Homepage
they may not want to say for legal reasons!


Snitz 'Speedball' : Site Integration Mod : Friendly Registration Mod
"In war, the victorious strategist only seeks battle after the victory has been won"
Go to Top of Page

PeeWee.Inc
Senior Member

United Kingdom
1893 Posts

Posted - 22 December 2004 :  16:17:28  Show Profile  Visit PeeWee.Inc's Homepage

De Priofundus Calmo Ad Te Damine
Go to Top of Page

Podge
Support Moderator

Ireland
3775 Posts

Posted - 22 December 2004 :  17:07:33  Show Profile  Send Podge an ICQ Message  Send Podge a Yahoo! Message
Its always safer to have one admin, yourself.

Podge.

The Hunger Site - Click to donate free food | My Blog | Snitz 3.4.05 AutoInstall (Beta!)

My Mods: CAPTCHA Mod | GateKeeper Mod
Tutorial: Enable subscriptions on your board

Warning: The post above or below may contain nuts.
Go to Top of Page

PeeWee.Inc
Senior Member

United Kingdom
1893 Posts

Posted - 22 December 2004 :  17:15:27  Show Profile  Visit PeeWee.Inc's Homepage
yeah, only yourself, a back-up account and someone you REALLY trust should be Admins. Loads of Mods, they cant really do alot of harm.

De Priofundus Calmo Ad Te Damine
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.62 seconds. Powered By: Snitz Forums 2000 Version 3.4.07