Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 I got hacked for the first time
 New Topic  Topic Locked
 Printer Friendly
Next Page
Author Previous Topic Topic Next Topic
Page: of 2

Zenfor
Junior Member

372 Posts

Posted - 30 December 2005 :  08:12:51  Show Profile
OK so I haven't kept up with the security patches but wondering how this could happen. He added a forum and desplayed a big hacked message with a graphic. I deleted it already so I don't have any other details but he did get in as an administrator. Said something about upgrade your software.

Edited by - Zenfor on 30 December 2005 08:13:39

pdrg
Support Moderator

United Kingdom
2897 Posts

Posted - 30 December 2005 :  08:19:41  Show Profile  Send pdrg a Yahoo! Message
This is why it's worth keeping up with the patches - it's sad that people feel the need to tag or damage things, but on the bright side you were hacked by a very considerate hacker if he just advised you to patch and didn't mess up all your community!

I'd just treat this as a learning experience, and silently thank him for bringing this to your attention, and be happy he got you before some little idiot did!

my 2p
Go to Top of Page

Zenfor
Junior Member

372 Posts

Posted - 30 December 2005 :  08:33:12  Show Profile
quote:
Originally posted by pdrg

This is why it's worth keeping up with the patches - it's sad that people feel the need to tag or damage things, but on the bright side you were hacked by a very considerate hacker if he just advised you to patch and didn't mess up all your community!

I'd just treat this as a learning experience, and silently thank him for bringing this to your attention, and be happy he got you before some little idiot did!

my 2p


I didn't see any other problems.

I just downloaded the patches I saw on the security section and subscribed to the emails. Should I do anything else or is this enough. I must be a couple of years without applying any security patches.
Go to Top of Page

dmontague
Starting Member

16 Posts

Posted - 30 December 2005 :  09:41:08  Show Profile  Visit dmontague's Homepage
Hi there,
I just got the same hack as well. Big graphic and no other damage.
What version are you using? I am still using 3.4.04.

I am looking to upgrade, but that will take some time.

Is there a place to find the updates for the 3.4.04 version? I do remember there being more than the 2 that are there currently.

Thanks,
Dave

Dave Montague
Go to Top of Page

Zenfor
Junior Member

372 Posts

Posted - 30 December 2005 :  09:55:31  Show Profile
quote:
Originally posted by dmontague

Hi there,
I just got the same hack as well. Big graphic and no other damage.
What version are you using? I am still using 3.4.04.

I am looking to upgrade, but that will take some time.

Is there a place to find the updates for the 3.4.04 version? I do remember there being more than the 2 that are there currently.

Thanks,
Dave


How do I find out what version I have? I see a copyright on the bottom of 2000-2002.

Anyone know how this happened and how I can prevent it without doing a ton of work? Thanks!

Are they finding my forum through here?
Go to Top of Page

dmontague
Starting Member

16 Posts

Posted - 30 December 2005 :  10:06:41  Show Profile  Visit dmontague's Homepage
If you go to the Admin area and then Main Forum Features.
It is in there.

quote:
Originally posted by Zenfor

quote:
Originally posted by dmontague

Hi there,
I just got the same hack as well. Big graphic and no other damage.
What version are you using? I am still using 3.4.04.

I am looking to upgrade, but that will take some time.

Is there a place to find the updates for the 3.4.04 version? I do remember there being more than the 2 that are there currently.

Thanks,
Dave


How do I find out what version I have? I see a copyright on the bottom of 2000-2002.

Anyone know how this happened and how I can prevent it without doing a ton of work? Thanks!

Are they finding my forum through here?


Dave Montague
Go to Top of Page

Zenfor
Junior Member

372 Posts

Posted - 30 December 2005 :  10:17:34  Show Profile
Using Snitz Forums 2000 Version 3.4.05
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 30 December 2005 :  11:49:25  Show Profile  Send ruirib a Yahoo! Message
Zenfor, you do need to apply the latest security patches. Also, have a look at your server log files, if you can, it could allow you to find out how it was done.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Zenfor
Junior Member

372 Posts

Posted - 30 December 2005 :  12:52:45  Show Profile
quote:
Originally posted by ruirib

Zenfor, you do need to apply the latest security patches. Also, have a look at your server log files, if you can, it could allow you to find out how it was done.


I applied the latest patches you have posted.

I have the server logs, what do I look for? How was he able to add a forum. I don't even see a new user?
Go to Top of Page

MarcelG
Retired Support Moderator

Netherlands
2625 Posts

Posted - 30 December 2005 :  13:22:27  Show Profile  Visit MarcelG's Homepage
Did he try to come in from this IP address ? http://whois.sc/220.175.15.204 ?
Just spotted some unusual activity from that address to my board, with some interesting requested URL's.
Will post more info when available.

portfolio - linkshrinker - oxle - twitter
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 30 December 2005 :  13:28:16  Show Profile  Send ruirib a Yahoo! Message
You'd need to browse the log carefully, looking for actions like loging in to admin options or adding the forum. Like that you could trace the login of that user back to his first action, to figure out what he did.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

MarcelG
Retired Support Moderator

Netherlands
2625 Posts

Posted - 30 December 2005 :  13:28:35  Show Profile  Visit MarcelG's Homepage
He's trying to get in via some SQL injection tricks:

he tried this one: /news.asp news_id=1831'%20and%20char(124)%2Buser%2Bchar(124)=0%20and%20''='|421|8

portfolio - linkshrinker - oxle - twitter
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 30 December 2005 :  13:32:01  Show Profile  Send ruirib a Yahoo! Message
If it was an SQL injection, quite likely it is mod related. AFAIK, the base code has been thoroughly revised to account for those attempts.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Zenfor
Junior Member

372 Posts

Posted - 05 January 2006 :  09:05:44  Show Profile
Hi,

I don't know if it is related but all of a sudden I notice that I am missing the Format Mode and Format buttons, font size, color, etc., on the posting boxes. Appreciate any ideas on how I can fix that.
Go to Top of Page

Zenfor
Junior Member

372 Posts

Posted - 05 January 2006 :  09:16:57  Show Profile
Hi,

I got them back. Looks like they were turned off in the admin. Was this something the hacker did?
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20595 Posts

Posted - 05 January 2006 :  11:53:04  Show Profile  Visit HuwR's Homepage
probably, however you really need to get a copy of your weblogs from the time this happened, otherwise you will not know how they got in and will therefore be unable to prevent them from doing it again
Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Next Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.41 seconds. Powered By: Snitz Forums 2000 Version 3.4.07