Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Help - Site Hacked
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

Jim Riley
New Member

United Kingdom
64 Posts

Posted - 08 December 2007 :  14:24:54  Show Profile  Visit Jim Riley's Homepage
www.tutor2u.net/forum/default.asp

Looks like a sql injection hack

I have got into the sql db and found a strcopyright change which redirects the forum user to the hackers website - I thought I has got rid of this, but the hack is still in place

<title>Tutor2u Discussion Forum</title>
<meta name="copyright" content="This Forum code is Copyright (C) 2000-02 Michael Anderson, Pierre Gorissen, Huw Reddick and Richard Kinser, Non-Forum Related code is Copyright (C) Tutor2u LimitedWE ARE LANGSON SECURITY TEAM FROM VIETNAM.YOU SITE HAVE MANY BUG.I TRY CLOSE IT.PLEASE FIX THE BUG AND OPEN AGAIN FOR SECURE.THANK.MYSITE IS www.VIETBACSCHOOL.COM <meta http-equiv="Refresh" content="0;url=http://vietbacschool.com/ls">">
<script language="JavaScript" type="text/javascript">

Any ideas?

Jim

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 08 December 2007 :  14:26:56  Show Profile  Send ruirib a Yahoo! Message
Have you had a look at our Security Bug Fixes forum?

Apply the bug fix, then visit down.asp and get the forum up. Also, don't forget to change the hacker from admin to normal status, and then lock him.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Jim Riley
New Member

United Kingdom
64 Posts

Posted - 08 December 2007 :  14:55:35  Show Profile  Visit Jim Riley's Homepage
I have applied all recent security fixes - but the redirect hack is still there, so I must be missing something.

what is down.asp?

Jim
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 08 December 2007 :  15:10:59  Show Profile  Visit modifichicci's Homepage
have you a backup of your db?

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 08 December 2007 :  15:16:15  Show Profile  Send ruirib a Yahoo! Message
You need to visit www.tutor2u.net/forum/down.asp and insert your admin password. Then get the forum up.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Jim Riley
New Member

United Kingdom
64 Posts

Posted - 09 December 2007 :  07:22:18  Show Profile  Visit Jim Riley's Homepage
This is odd.

I have installed a new version of the latest Snitz files on a new forum directory, calling the directory something other than "forum" (which was hacked). It works fine.

I think I have cleared out all the hacks to the SQL db

But when I create a new version of the old "forum" directory and upload the new snitz files, the redirect hack is still there.

Anyone got any ideas about how this can be happening. I'm happy that there hasnt been any security issue with our ftp settings, so I'm assuming that it must still be something in the sql db?

Jim
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 09 December 2007 :  07:35:38  Show Profile  Send ruirib a Yahoo! Message
Did you visit down.asp as I suggested?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

tooms
Starting Member

Denmark
3 Posts

Posted - 09 December 2007 :  09:09:42  Show Profile  Visit tooms's Homepage
My forum was hacked also, by some one adding them self as a admin user..

this admin user then changed one of the "message" texts to incode a iframe tag there was trying to load the "Remote Data Services Data Control" from a other site..

also seeing alot of "post" request attacks..

Looks like this software need a big security update to make it alow more secure and maybe more content checking, like checking posted urls into forum with url blacklists.

by the way, if you need to fix a hacked forum then use the "Fiddler http debugging proxy" software, that help me alot.

Edited by - tooms on 09 December 2007 09:11:17
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 09 December 2007 :  09:30:04  Show Profile  Send ruirib a Yahoo! Message
We posted a security fix about a week ago, before any hacking occurred. You'd better susbcribe to the Announcements Security Related Bug Fixes forum, so that you can be notified whenever we post a security fix.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Maxime
Average Member

France
521 Posts

Posted - 10 December 2007 :  11:40:50  Show Profile  Visit Maxime's Homepage
I have also been hacked by a Turkish with an image on the forum and no way to become administrators in the options. I think a lot of you have been affected by this hackeur which seems the same person and foudrait complain. Those who are globas.asa on their site can internt blocked the ip to Turkish Here is the code that I had to make you a direction web and put the good ip.

I fully placed under day forum on security and I registered to receive news wagering Updated.


Global.asa

Sub Session_OnStart
If InStr(request.ServerVariables("REMOTE_ADDR"),"201.221.198.") > 0 then
Session.Abandon
Response.redirect("http://www.casserole.fr/")
End If
End Sub

Cordially,
Maxime

Taxation consists in so plucking the goose to get the most out of feathers with the least possible cries.(Jean-Baptiste Colbert)

Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 10 December 2007 :  12:39:32  Show Profile  Visit AnonJr's Homepage
I probably sound like a broken record every time IP blocking comes up, but its worth mentioning again: Its hard, if not impossible, to block someone based on their IP... the short version goes like this: If this individual is working out of a university or stuck (/hiding) behind a proxy, you could be blocking a large number of innocents.

With that said, the IP Gate MOD will also allow you to block IP addresses without the need to set up/modify global.asa - assuming your host allows you to set one up in the first place... which would be why I mention it.
Go to Top of Page

iresprite
Starting Member

1 Posts

Posted - 11 December 2007 :  13:49:00  Show Profile
Hey, guys. I'm helping out with a site that was hacked by the same people. I'm trying to play catch up here-- I applied the patch suggested in the Security Bug Fix setting; what other steps do I need to take? I noticed something about down.asp. Where can I read to get myself clued in?

Thanks!
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 11 December 2007 :  13:51:51  Show Profile  Send ruirib a Yahoo! Message
Make sure you remove all admins that are not supposed to be admins. What other problems are you having? Is the forum running normally now?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

ptrimmer
Starting Member

3 Posts

Posted - 12 December 2007 :  15:13:11  Show Profile
I am unable to get our forum back up. We were hacked by the lovely Turkish fellows. I am also unable to get to the www.tutor2u.net/forum/down.asp site. I am at a loss as to what to do next.
Thanks!
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.48 seconds. Powered By: Snitz Forums 2000 Version 3.4.07