Why are some forums getting hacked? - Posted (2259 Views)
Junior Member
thelodger
Posts: 296
296
I have a successful forum, well in my eyes its successful, over 100,000 posts and 700 members, no one has hacked my forum, I subscribe to the security forum and do as instructed, but it seems to me that forums much smaller than mine are still getting hacked, WHY? Am I just lucky??<
 Sort direction, for dates DESC means newest first  
 Page size 
Posted
Snitz Forums Admin
ruirib
Posts: 26364
26364
The owners do not update the code with the fixes we post, or use mod code that does not properly sanitize input. As of now, we know of no unpatched bug that would alow anyone to hack a base code forum.<
Posted
Junior Member
thelodger
Posts: 296
296
Well it seems to me that the main forum is full of people saying that their forum has been hacked, sort of blaming the software, it’s not a good sight for people who are looking to set up a forum and are deciding if snitz is the one for them, we know that it’s a great forum set up and safe if you follow updates and are careful with what you add, the main forum just doesn’t give that impression at the moment.<
Posted
Snitz Forums Admin
ruirib
Posts: 26364
26364
If you just look at the HACKED word... I just went and had a look - one of the hacks, was not, another resulted from an unsanitized mod, probably just a couple were hacked with a 6 month old hack...
Things are the way they are and we had our share of issues...<
Posted
Support Moderator
Podge
Posts: 3776
3776
In fairness, the problem is not directed at Snitz. There are bots roaming the net trying to insert javascripts and iframes into every text field of your application in order to direct traffic to wherever they want. As Rui says, the only defence is to remain vigilant and update your forum with fixes as they come out.<
Posted
Forum Admin
HuwR
Posts: 20611
20611
Originally posted by thelodger
Well it seems to me that the main forum is full of people saying that their forum has been hacked, sort of blaming the software, it’s not a good sight for people who are looking to set up a forum and are deciding if snitz is the one for them, we know that it’s a great forum set up and safe if you follow updates and are careful with what you add, the main forum just doesn’t give that impression at the moment.

So what do you sugest we do ? delete all the posts with the word hacked or virus in it and let people fend for themselves ?
We can't help it if peoples forums get hacked because they do not have the latest code, but we will help anyone that posts asking for help, even if it is not even related to the forum code, surely that is a good sight ? there are many many support sites I could mention where people make a post and nobody answers them at all.<
Posted
Snitz Forums Admin
ruirib
Posts: 26364
26364
Originally posted by HuwR

We can't help it if peoples forums get hacked because they do not have the latest code, but we will help anyone that posts asking for help, even if it is not even related to the forum code, surely that is a good sight ? there are many many support sites I could mention where people make a post and nobody answers them at all.
That's an excellent point. I doubt that you find a few places where people get the support they get here, on similar situations.<
Posted
Forum Moderator
AnonJr
Posts: 5768
5768
Just to add, it sounds as if you're looking at this like no one else is running into these issues. I bet if you looked at the support forums for just about any forum, CMS, etc. you'll find all sorts of posts from people who haven't kept up to date or have added code that isn't properly secured, or have been hacked by other means and are looking for someone to take the fall. (assuming they aren't hidden for "image" purposes)

As to the thrust of your initial post, in recent months I've had this same conversation with the guy who runs the Eastover Fire Department's site (as there were 2 unsuccessful hack attempts trying to exploit the Dec. issue), and I had it again with the guys over at the Jesus Joshua 24:15 site (as there was 1 unsuccessful hack attempt trying to exploit the Dec. issue), and I had it one more time with the congregation of Hope Fellowship (as the site is relentlessly pounded by spammers trying to get in, and an attempt to exploit the Dec. issue was also adverted).
Why some sites are targeted I cannot say. www.jesusjoshua2415.com gets a lot of traffic, but isn't a very busy forum. But, given the traffic I can see why it might be a target. www.eastoverfd.com doesn't get a lot of traffic, and also isn't a very busy forum, but it was targeted. www.hopefellowship-nc.org is the site I've never gotten right, has almost no traffic, and I'm the only one who posts there - but its my most assaulted site. Go figure.

I suspect that that may be because a successful attack would be more likely to go unnoticed on a site with low traffic. There are a multitude of reasons why they attack a site. There are a number of articles out there that try to explain the ins and outs as to why they do the things they do. Why you in particular haven't been targeted, I can't say. Just be glad and be vigilant. wink<
Posted
Average Member
Maxime
Posts: 521
521
AnonJr, formed to you part of the voluntary sappers firemen of your city in the USA? I was also during 29 years sapper fireman of my city in France like volunteer with the rank of sergeant chief. Unfortunately, I had to resign in January 2000 for reasons of incompatibility with the chief of body which was not very sympatic. But I wish you long year in this function which was pure me a true passion.<
Cordially,
Maxime

Taxation consists in so plucking the goose to get the most out of feathers with the least possible cries.(Jean-Baptiste Colbert)
Posted
Forum Moderator
AnonJr
Posts: 5768
5768
I am not myself a volunteer firefighter. But I do support them every chance I can. smile<
Posted
Average Member
Maxime
Posts: 521
521
It is very quite good continuation<
Cordially,
Maxime

Taxation consists in so plucking the goose to get the most out of feathers with the least possible cries.(Jean-Baptiste Colbert)
You Must enter a message