Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Community Forums
 Community Discussions (All other subjects)
 Possible Hacker ?
 New Topic  Reply to Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

Webbo
Average Member

United Kingdom
982 Posts

Posted - 07 November 2013 :  18:23:51  Show Profile  Visit Webbo's Homepage  Reply with Quote
I had a look at my 'Active Users' tonight and found several 'Guests' viewing 'Admin Options', more specifically these links:

http://www.mysite.com/forum/post.asp?method=-1%27&forum_id=14
http://www.mysite.com/forum/post.asp?method=-1%27&forum_id=60
http://www.mysite.com/forum/post.asp?method=-1%27&reply_id=1613182&topic_id=163054&forum_id=14
http://www.mysite.com/forum/post.asp?method=-1%27&topic_id=163054&forum_id=14

Their IP addresses were all different, one being 200.215.99.145 which belongs to Brasil Telecommunications and another being 92.77.253.27 which belongs to a German ISP

As far as I'm aware all security fixes are in place and there has been no disruption, but is it something I need to be concerend about or just someone passing through ?

Edited by - Webbo on 07 November 2013 18:30:28

bobby131313
Senior Member

USA
1163 Posts

Posted - 07 November 2013 :  18:54:53  Show Profile  Visit bobby131313's Homepage  Reply with Quote
Log out and see if the admin options, post reply, and new topic links are showing.

Switch the order of your title tags
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 07 November 2013 :  19:24:39  Show Profile  Send ruirib a Yahoo! Message  Reply with Quote
This links do not seem to access admin options. Probably it's just the default info shown by Active Users?

Anyway, even when non authorized users try to access admin options, AU will show them trying, but they cannot actually access them.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Webbo
Average Member

United Kingdom
982 Posts

Posted - 08 November 2013 :  02:23:09  Show Profile  Visit Webbo's Homepage  Reply with Quote
It's the first time I've seen such and they stayed 'active' for up to 2 hours then no more

Bobby, those links don't show when logged out and the 'admin options' only shows on my site when logged in and with admin status (ie mlev=4)

Rui, the links above haven't displayed properly, there was a reference to 'admin... ' in the link which seems to have been filtered out on here, hence the concern
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 08 November 2013 :  03:57:38  Show Profile  Send ruirib a Yahoo! Message  Reply with Quote
Active Users is not really a good reference regarding who accesses what, since it does not determine who had access rejected because of permissions. I have also seen AU just stating Admin Options for other stuff, like the mod that allows draft creations and such.

IMO, it should be nothing to worry about, but try the links while being logged out and see what happens.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

Webbo
Average Member

United Kingdom
982 Posts

Posted - 08 November 2013 :  15:55:27  Show Profile  Visit Webbo's Homepage  Reply with Quote
I've got one now and the link takes you to the default.asp page
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 09 November 2013 :  05:07:12  Show Profile  Send ruirib a Yahoo! Message  Reply with Quote
As I said it would :).


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Reply to Topic
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.1 seconds. Powered By: Snitz Forums 2000 Version 3.4.07