Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Webmaster Password
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

jon123456
Starting Member

United Kingdom
8 Posts

Posted - 03 March 2007 :  15:46:23  Show Profile  Visit jon123456's Homepage
Help!!

I am afraid my forum has been compromised as I can not login as the webmaster with my password.

I have ftp access to the access database on my ISP host's server, so is there any way I can do a reset?

I am running version 3.0.4.3 and it does not have a password reset feature...

Please help!

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 03 March 2007 :  15:51:36  Show Profile  Visit HuwR's Homepage
first thing you need todo is register on the forum with a new username/password, then download your db and take your forum offline.
You can then make this new member an admin by changing the M_LEVEL value to 3 in the FORUM_MEMBERS table, and then delete any other users in the database that have an M_LEVEL of 3.

You should also either upgrade to the current version, or install all security updates and bug fixes from our bug forums

Go to Top of Page

jon123456
Starting Member

United Kingdom
8 Posts

Posted - 03 March 2007 :  15:54:30  Show Profile  Visit jon123456's Homepage
Nice one - I'll give it a go now...
Go to Top of Page

jon123456
Starting Member

United Kingdom
8 Posts

Posted - 03 March 2007 :  15:58:21  Show Profile  Visit jon123456's Homepage
OK - we have definately been hacked as new member registration has been disabled....can someone tell me which table I need to edit to turn this back on please?

@?~!$
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 03 March 2007 :  16:04:13  Show Profile  Send ruirib a Yahoo! Message
You can try this admin password reset mod: http://forum.snitz.com/forum/topic.asp?ARCHIVE=true&TOPIC_ID=37932

Then take the forum down and remove the database and then do as HuwR suggested.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

jon123456
Starting Member

United Kingdom
8 Posts

Posted - 03 March 2007 :  16:28:22  Show Profile  Visit jon123456's Homepage
OMG

Right...the password reset script linked above worked.

I rest webmaster login and found a recent member with a .ru email (russia) that was an administrator . In addition, the forum had been set to disallow new members to register

I am not a happy chap

Thanks to all for your help in getting me back on. Is this a security flaw with Access or just all of Snitz
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 03 March 2007 :  18:19:11  Show Profile  Send ruirib a Yahoo! Message
You'd need to have a look at your server logs to find out how it's done. Anyway, it's always needed to apply the latest security fixes.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

jon123456
Starting Member

United Kingdom
8 Posts

Posted - 03 March 2007 :  18:46:01  Show Profile  Visit jon123456's Homepage
OK.

I've just spent the last hour plus searching this site. Clearly, being on version 3.4.0.3 is not helping when I should be on 3.4.0.6!

I'd rather not bin my existing install as it is heavily MOD'd. However, I can only find the upgrade files for 3.4.0.5 -> 3.4.0.6.

Can anyone provide some advice on a way forward? I think the main mod I have is the Poll MOD - is this a standard feature of 3.4.0.6?

TIA
Jon
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 03 March 2007 :  18:53:05  Show Profile  Send ruirib a Yahoo! Message
No, the poll mod is not present in our 3.4.06 version. Also, almost all files changed from 3.4.03 to 3.4.06.

Regarding security, though, you can just apply all security fixes posted since 3.4.03 came out. Also, you should subscribe to posts in the Announcements: Security Fixes forum.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.91 seconds. Powered By: Snitz Forums 2000 Version 3.4.07