Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Security Breach on my 3.4.04 Forum
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

RaveD
Starting Member

7 Posts

Posted - 14 August 2009 :  13:46:47  Show Profile
A hacker has managed to bypass the approval process and create accounts for himself on my forum.

I am running 3.4.04 with the latest security fixes, except for the one just posted for pop_profile.asp, since it applies to 3.4.07 only.

My site is configured to require administrator approval; however, this hacker created several accounts and started posting immediately. I do not know how he bypassed the approval process.

Any suggestions?

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 14 August 2009 :  14:00:11  Show Profile  Send ruirib a Yahoo! Message
The said hacker really hacked the site, or just posted spam. Did he make himself admin?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

RaveD
Starting Member

7 Posts

Posted - 14 August 2009 :  15:07:04  Show Profile
First it seemed he hacked an existing user's account and posted spam.

But then I disabled that account and found several more accounts were created and they posted spam.

It does not appear he gained admin access, or if he did, he did not cause any damage. It seems as if he found a way to bypass the approval process and activate his accounts immediately.
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 14 August 2009 :  15:19:56  Show Profile  Visit HuwR's Homepage
that sounds like some sort of sql injection.

do you have mods installed ?
do you have any other non forum related pages that share the database ?
have you thought of upgrading to the latest version ?
Go to Top of Page

RaveD
Starting Member

7 Posts

Posted - 16 August 2009 :  11:27:28  Show Profile
quote:
Originally posted by HuwR

that sounds like some sort of sql injection.

do you have mods installed ?
do you have any other non forum related pages that share the database ?
have you thought of upgrading to the latest version ?


Have a couple mods installed but frankly I don't remember which. It has been well over a year since I last updated the forum software. There are no other pages that share the database.

Is there a way to determine if it was an SQL attack vs. exploiting some Snitz vulnerability?

I would like to install the latest version but unfortunately do not have any spare time these days to maintain the software of this forum.
Go to Top of Page

Jezmeister
Senior Member

United Kingdom
1141 Posts

Posted - 16 August 2009 :  19:43:45  Show Profile  Visit Jezmeister's Homepage
A lot of bots are clever these days, email activation isn't enough to stop them on its own. Perhaps try turning on 'restrict registration' so that only you can activate accounts?

Of course, if they did hack an existing account then that is aside the issue, I'm just taking from a lack of certainty in your post that that may not have been the case! Also, if you haven't updated it in over a year then you can't be up to date on your security updates, although I have to admit I don't know if any recent ones would be vulnerable to something like that anyway.
Go to Top of Page

RaveD
Starting Member

7 Posts

Posted - 16 August 2009 :  20:41:32  Show Profile
I do have restrict registration turned on.

Honestly it's been awhile since I looked at the forum software, so I can't be sure if this is a MOD or a feature: when a new user registers, I must go to the "Approve pending members" page in order to approve the account. Once approved, the E-mail goes out to the user so they can activate their account.

The issue here is that several accounts were created without this approval process. So it seems like a security flaw being exploited.
Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 16 August 2009 :  23:13:28  Show Profile  Visit AnonJr's Homepage
If its been over a year since you last updated the forum software, then it could be any number of issues... or one of the MODs or some other page that uses the same database. Without knowing more about what has been done (MODs, et al) its hard to say.
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 17 August 2009 :  02:15:51  Show Profile  Visit HuwR's Homepage
quote:
The issue here is that several accounts were created without this approval process. So it seems like a security flaw being exploited.
Which is why you should upgrade to the latest version
Go to Top of Page

RaveD
Starting Member

7 Posts

Posted - 18 August 2009 :  18:40:03  Show Profile
I wish it were so easy to upgrade ... it's been so long I forget what MODs are installed and afraid it might take quite awhile to straighten everything out.

I kept current with security updates so I thought I would be safe...
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 18 August 2009 :  18:55:38  Show Profile  Send ruirib a Yahoo! Message
Probably getting the server logs could allow you to find out the entry point and patch it, as a intermediate solution. Updating to the latest solution is, still, the recommended strategy. Better be safe than sorry.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 19 August 2009 :  01:51:42  Show Profile  Visit HuwR's Homepage
If you are all patched then there is even more reason to upgrade since it may be a MOD at fault not the Snitz base code
Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 19 August 2009 :  12:30:00  Show Profile  Visit AnonJr's Homepage
Or, as mentioned previously, a non-forum page that shares the same database....
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.38 seconds. Powered By: Snitz Forums 2000 Version 3.4.07