Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Hacked - any thought people ?
 New Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

pierretopping
Junior Member

United Kingdom
224 Posts

Posted - 20 June 2013 :  09:52:54  Show Profile  Visit pierretopping's Homepage  Reply with Quote
Hi All,

We are running 3.4.05, and thought we had applied all the security fix's, but one user account is still being hacked.

I have checked the log files and got the below...

Any thoughts please

/forum/post_info.asp - 80 - 192.80.186.242 HTTP/1.0 Opera/9.80+(Windows+NT+6.1)+Presto/2.12.388+Version/12.10 ASPSESSIONIDCAASQCAB=MHLLEJHBFOIBOCBBHHCNDNBN http://www.tredegar.co.uk/forum/post.asp?method=Topic&FORUM_ID=29

Carefree
Advanced Member

Philippines
4217 Posts

Posted - 20 June 2013 :  12:14:31  Show Profile
That IP goes to a cloud server, could be anyone from anywhere. Best guess is that if you applied all the posted security fixes, you have a mod somewhere which has a security hole of its own.
Go to Top of Page

pierretopping
Junior Member

United Kingdom
224 Posts

Posted - 20 June 2013 :  12:44:50  Show Profile  Visit pierretopping's Homepage
quote:
Originally posted by Carefree

That IP goes to a cloud server, could be anyone from anywhere. Best guess is that if you applied all the posted security fixes, you have a mod somewhere which has a security hole of its own.



Thanks Carefree.

The only fix I can see for the version I'm running on that effects post_info.asp is for version.07 ?

Would you think it is worth while me checking that I have done fix http://forum.snitz.com/forum/topic.asp?TOPIC_ID=60011

??

Thanks

P.
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 20 June 2013 :  13:54:17  Show Profile  Send ruirib a Yahoo! Message
What type of hacking are you talking about? What exactly has the hacker done?


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

pierretopping
Junior Member

United Kingdom
224 Posts

Posted - 20 June 2013 :  17:26:57  Show Profile  Visit pierretopping's Homepage
Hi, we'll the post appears to be from an existing member,but contains all type of links.

It has only happened to one long standing member of the forum, and he has changed his password, and as carefree said the IP address is from a cloud ,,,,,
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 20 June 2013 :  18:16:46  Show Profile  Send ruirib a Yahoo! Message
So you are saying that hack was a post made by someone using someone else's account?
Hackers usually do not do just that, so it doesn't really seem a hack to me. Have you implemented the fix here (look to the final solution posted): http://forum.snitz.com/forum/topic.asp?TOPIC_ID=67497&SearchTerms=appVarsLoadError ?

I


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

pierretopping
Junior Member

United Kingdom
224 Posts

Posted - 21 June 2013 :  08:03:05  Show Profile  Visit pierretopping's Homepage
quote:
Originally posted by ruirib

So you are saying that hack was a post made by someone using someone else's account?
Hackers usually do not do just that, so it doesn't really seem a hack to me. Have you implemented the fix here (look to the final solution posted): http://forum.snitz.com/forum/topic.asp?TOPIC_ID=67497&SearchTerms=appVarsLoadError ?

I



Hi ruirib,

Thanks for the link, I have now placed that fix in my config.asp file.

It is very strange, I even changed the users name (but kept his member_id the same) and it was stilled spammed.

Very strange how its only the one users account that is being used.

Thanks for your help all

Pierre
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.3 seconds. Powered By: Snitz Forums 2000 Version 3.4.07