Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Forums hacked into last night!
 New Topic  Topic Locked
 Printer Friendly
Previous Page | Next Page
Author Previous Topic Topic Next Topic
Page: of 7

JohnC
Junior Member

215 Posts

Posted - 13 December 2007 :  20:03:04  Show Profile
Here's the hacker's tracks in the forums:

2007-12-12 12:15:41 GET /forums/forum.asp ARCHIVE=true&FORUM_ID=101 80 - 195.244.128.16 Mozilla/5.0+(Windows;+U;+Windows+NT+5.1;+en-US;+rv:1.8.1.11)+Gecko/20071127+Firefox/2.0.0.11 200 0 0

- POST /forums/register.asp mode=DoIt
- GET /forums/register.asp actkey=5d39yrr43h
- POST /forums/active.asp |309|80040e14|Incorrect_syntax_near_'_'.
- GET /forums/pop_profile.asp mode=Edit
- GET /forums/admin_login.asp target=admin_home.asp
- POST /forums/admin_login.asp
- POST /forums/admin_config_features.asp
- GET /forums/default.asp |865|80040e14|Incorrect_syntax_near_'_'.
- GET /forums/post.asp method=EditForum&FORUM_ID=61&CAT_ID=12&type=0

Can almost see everything he or she did. Does the first one mean they archived one of the forums?

Edited by - JohnC on 13 December 2007 20:58:54
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 13 December 2007 :  20:03:30  Show Profile  Send ruirib a Yahoo! Message
No problem, you're welcome.

The first one mean they went to check what was available in the archived posts for that forum.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

ellanvannin
Starting Member

3 Posts

Posted - 13 December 2007 :  20:45:06  Show Profile
rui

could you take a look at our forum, we were hacked, and have overwritten the forum from a backup, and we are recieving errors

www.gayinfo.org.im

or you can email me
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 13 December 2007 :  21:17:56  Show Profile  Send ruirib a Yahoo! Message
Hard to say what's going on. Did you restore from a working copy?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

ellanvannin
Starting Member

3 Posts

Posted - 13 December 2007 :  21:52:51  Show Profile
a saved copy from 6 months ago, but now it wont work

if i can give you a password or anything to have a look no probs

kev
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 13 December 2007 :  22:02:44  Show Profile  Send ruirib a Yahoo! Message
Well email me the FTP data and admin username and password and I'll try and have a look. It's about 3 AM here, so can't promise I will do it before the morning, though.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

ellanvannin
Starting Member

3 Posts

Posted - 13 December 2007 :  22:08:19  Show Profile
your a star, the forum is useless at present so no rush

hope the weather in portugal is better than here !

kev
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 13 December 2007 :  22:20:34  Show Profile  Send ruirib a Yahoo! Message
Well, seems like your have a permissions problem (updateable query error). You will need to talk to your host about that. I've provided some more info by email.

I've applied the security fix to stop the forum from being hacked again. Make sure you subscribe to the Announcements Security Related Bug Fixes forum to avoid missing any future security fixes.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Melly1953
Starting Member

2 Posts

Posted - 14 December 2007 :  12:43:45  Show Profile
I was hacked into on Dec 12th as well...same militant Turkish group. I kept trying to logon here..but my username was not accepted. Long story short..used my DIL's email..as I am here visiting..they just had a new baby.

I still cannot login as admin to my forums. It won't accept the new password at all. I registered as a new user..but there is not way for me to get to admin options at all! Please help. I am trying to fix this thing and take care of a very busy 2 year old! :)
Go to Top of Page

weeweeslap
Senior Member

USA
1077 Posts

Posted - 14 December 2007 :  12:48:57  Show Profile  Visit weeweeslap's Homepage  Send weeweeslap an AOL message  Send weeweeslap a Yahoo! Message
what database do you use? Can you log into the database and change the admin account email address to your email account and then use the lost password feature to gain access to the admin account?

coaster crazy
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 14 December 2007 :  12:54:38  Show Profile  Send ruirib a Yahoo! Message
Well, email me the FTP data and forum admin data and I will fix it for you.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Melly1953
Starting Member

2 Posts

Posted - 14 December 2007 :  13:23:28  Show Profile
quote:
Originally posted by weeweeslap

what database do you use? Can you log into the database and change the admin account email address to your email account and then use the lost password feature to gain access to the admin account?



I have no clue what database. I am a novice. I've had the forums up for 16 mos. though and no problems like hacking have ever occured. Sounds like it happened to quite a few on the 12th. Hmmmm.

BTW...your DVD's are expensive. I just bought a new American pie for 5.99.
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 14 December 2007 :  17:35:25  Show Profile  Send ruirib a Yahoo! Message
Melly1953,

Without FTP info there is nothing I can do. Please send me the FTP server address, FTP username and password and I'll deal with it. Otherwise I can't do a thing.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

alltp
Starting Member

36 Posts

Posted - 14 December 2007 :  21:48:23  Show Profile  Visit alltp's Homepage
rui,

i had the same problem and did the security patch but likely have the same iframe problem (which you noticed - by the way thanks for visiting the Buzz).

I've emailed you the db logon info. Appreciate your help - you are AWESOME!

John Hill
www.alltp.com
www.tabletpcbuzz.com
www.tabletpcbuzz.com/3dbuzz
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 15 December 2007 :  00:27:00  Show Profile  Send ruirib a Yahoo! Message
John,

Problem fixed.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page
Page: of 7 Previous Topic Topic Next Topic  
Previous Page | Next Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 2.09 seconds. Powered By: Snitz Forums 2000 Version 3.4.07