PDA

View Full Version : WEB Site Hacked..!!!!



The Slug
15-09-2013, 21:47
ATTN....

Today at 17:05 the site was hacked, well the first part of the site was hacked and somehow malicious files were loaded to the Servers using a password bypass.

Our hosting company notified me at 17:07, however having a life, I happened to be out of the house and have only just managed to access our site and take action as requested by our hosting company.

I have changed My passwords as I control the forum, the site, and the way it is uploaded and administered.

I do not believe that any information has been take accessed and the site appears to be stable, however I would urge you all to change your passwords as it may be one of you that has been targeted in order to gain access.

If you do a current search on Google you will see that Vbulletin forums at the moment are being targeted and this is not an isolated attack, however by shutting down the forum now and then and installing the fixes and updates as I did the other night, I hope to keep the site clean and running, so I cant always tell you when this will have to happen so if you get the message the "Forum is currently off-line for updates" please bear with me.

If we have a IT forensic specialist in our midst which I think we have maybe they would contact me.

Thank
Ian

peteracs
22-09-2013, 23:33
Hi Ian

Not sure why a user with normal access would be useful over posting malicious comments and I guess uploading some files, but that does not give them access to the system's O/S or to do anything with the files. Is it more likely that someone with system level access has caused the issue or have the hosting company definitely said that it could be someone with just forum access?

Peter

The Slug
23-09-2013, 00:43
Hi Peter,

Neither Vbulletin, or the hosting company have replied to my questions, these's a surprise.!!
I understand that there is a program currently being used to target vbulletin forums.
I do not believe that they had my password, or there would be no need to create a new admin account, or to write a php script. just as well the hosting company detected the new script.

Paul
23-09-2013, 12:34
When I try to view the forum on my iphone, I see a strange hacker style homepage. This just happened sometime over the weekend. No such issue when viewing on my computer. I wonder is it a problem with my phone or the website?
Paul

][\/][ajor
23-09-2013, 12:45
Try clearing your cache. I just did and it seems to be OK now. I think I was getting the same page as you. Mainly black with red text?

ChrisCar6
23-09-2013, 16:04
[\/][ajor;16081']Try clearing your cache. I just did and it seems to be OK now. I think I was getting the same page as you. Mainly black with red text?

yes, I'm getting that too.

Bernard
23-09-2013, 16:25
Pity we can't find a name and address for this "hacker"........... git

The Slug
23-09-2013, 16:40
For the few of you who can see the site well done don't clear your cache.

I don't know how to fix this and I'm away for the week working in Gatwick so your going to be without a site unless I work it out.

Sorry......

ChrisCar6
23-09-2013, 17:11
HeyHo.
Bollox!

john
23-09-2013, 21:35
HeyHo.
Bollox!

Is that some new "software package"?

The Slug
24-09-2013, 00:34
Right I hope we are back again.....

I'm off to bed!!!!

peteracs
24-09-2013, 08:47
Right I hope we are back again.....

I'm off to bed!!!!

Hi Ian

Yep normal service resumed many thanks for your efforts, I can really see the point in hacking places like this forum, must give them a great sense of power.

Sadly in order to read the message about not clearing the cache, I had to clear the cache...........

Peter

Peter

][\/][ajor
24-09-2013, 14:41
Sadly in order to read the message about not clearing the cache, I had to clear the cache...........

Mint! ;)

ChrisCar6
24-09-2013, 19:51
Thanks for your efforts Ian, much appreciated.

StruanR
24-09-2013, 20:03
Thanks for your efforts Ian, much appreciated.
As always, good work, although I had access all the time wthout any problems, Firefox browser....

The Slug
25-09-2013, 00:03
If you had a shortcut then like me you probably knew nothing about it until you refreshed your browser.

If you tried the main web site screen, or tried to manually typed the link to the forum then this is what you would have seen......

5276

It also played the theme from the Pirate of the Caribbean