Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Forums hijacked again.
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Everything else
- :
- Forums hijacked again.
Forums hijacked again.
16-09-2007 8:09 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Once again my forums have been hijacked and redirected to Turkish sites 
This time I had 2 test forums running - one running phpBB3 RC5 and the other SMF
I've taken simplest way out by deactivating MySQL to clear databases.
I've run my pipexsanctuary site for over 2 years with no problems.
Apart from changing my main password I can't think of anything else - obviously that would change pwd for cgi space.
Puzzled

This time I had 2 test forums running - one running phpBB3 RC5 and the other SMF
I've taken simplest way out by deactivating MySQL to clear databases.
I've run my pipexsanctuary site for over 2 years with no problems.
Apart from changing my main password I can't think of anything else - obviously that would change pwd for cgi space.
Puzzled

Message 1 of 3
(1,544 Views)
2 REPLIES 2
Re: Forums hijacked again.
16-09-2007 11:30 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Changing your password shouldn't make any difference (however I could be wrong); the majority of site takeovers are done via SQL injection vulnerabilities/data validation flaws.
phpBB RC5 hasn't been around for that long, so a takeover so quickly is unusual, but the flip side is that it hasn't been around for that long, so may have new bugs that previous release candidates didn't. There was an exploit in I believe RC4 which allowed for site takeover (that was a Turkish-based exploit too), but it could only be run by a user with Moderator status.
Your best bet would possibly be to keep extensive logs on which pages each user are accessing while you are using newly released software. That way you could find out who initiated the attack, and which page they used to do so.
phpBB RC5 hasn't been around for that long, so a takeover so quickly is unusual, but the flip side is that it hasn't been around for that long, so may have new bugs that previous release candidates didn't. There was an exploit in I believe RC4 which allowed for site takeover (that was a Turkish-based exploit too), but it could only be run by a user with Moderator status.
Your best bet would possibly be to keep extensive logs on which pages each user are accessing while you are using newly released software. That way you could find out who initiated the attack, and which page they used to do so.
Message 2 of 3
(382 Views)
Re: Forums hijacked again.
17-09-2007 8:34 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I've had phpBB3 RC3, RC4 and now RC5 hijacked - smf was also hijacked this time.
Sites are only mentioned in a private forum on my sanctuary site and only people who've joined are people I know.
I was assuming (guessing) some form of cgi access but I seem to be the only one who's had this problem.
Fortunately I'm only using my PlusNet space to learn more about forums - I've got a friend who does clever bits for me on my other site.
Sites are only mentioned in a private forum on my sanctuary site and only people who've joined are people I know.
I was assuming (guessing) some form of cgi access but I seem to be the only one who's had this problem.
Fortunately I'm only using my PlusNet space to learn more about forums - I've got a friend who does clever bits for me on my other site.
Message 3 of 3
(382 Views)
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Everything else
- :
- Forums hijacked again.