cancel
Showing results for 
Search instead for 
Did you mean: 

Forums hijacked again.

nadger
Rising Star
Posts: 4,498
Thanks: 46
Registered: ‎13-04-2007

Forums hijacked again.

Once again my forums have been hijacked and redirected to Turkish sites  Angry
This time I had 2 test forums running - one running phpBB3 RC5 and the other SMF
I've taken simplest way out by deactivating MySQL to clear databases.
I've run my pipexsanctuary site for over 2 years with no problems.
Apart from changing my main password I can't think of anything else - obviously that would change pwd for cgi space.
Puzzled  Huh
2 REPLIES 2
MikeWhitehead
Grafter
Posts: 748
Registered: ‎19-08-2007

Re: Forums hijacked again.

Changing your password shouldn't make any difference (however I could be wrong); the majority of site takeovers are done via SQL injection vulnerabilities/data validation flaws.
phpBB RC5 hasn't been around for that long, so a takeover so quickly is unusual, but the flip side is that it hasn't been around for that long, so may have new bugs that previous release candidates didn't. There was an exploit in I believe RC4 which allowed for site takeover (that was a Turkish-based exploit too), but it could only be run by a user with Moderator status.
Your best bet would possibly be to keep extensive logs on which pages each user are accessing while you are using newly released software. That way you could find out who initiated the attack, and which page they used to do so.
nadger
Rising Star
Posts: 4,498
Thanks: 46
Registered: ‎13-04-2007

Re: Forums hijacked again.

I've had phpBB3 RC3, RC4 and now RC5 hijacked - smf was also hijacked this time.
Sites are only mentioned in a private forum on my sanctuary site and only people who've joined are people I know.
I was assuming (guessing) some form of cgi access but I seem to be the only one who's had this problem.
Fortunately I'm only using my PlusNet space to learn more about forums - I've got a friend who does clever bits for me on my other site.