Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
4 registered (Dj Aero, capnbob, Morgan, id242), 46 Guests and 16 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 04/12/04
Posts: 154
Top Posters (30 Days)
Ruben 49
DennyP 24
Gizmo 23
Dunny 18
SteveS 14
AllenAyres 12
dbremer 10
drkknght00 9
SD 9
driv 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Topic Options
#177219 - 02/03/07 10:38 AM Having a bit of an emergency, help!
luket Offline
member
Registered: 11/09/04
Posts: 191
Okay, this has turned into a bit of a disaster.

In another thread, I explained how SQL keeled over due to 9meg post some moron was able to make. I was able to fix that by editing the post text manually and removing most of the rubbish.
I thenL

1. removed the old tables as instructed.
2. Closed both boards
3. relaunched the import
4. and of now it's still running

BUT
A. The forums are now somehow OPEN:
B. people have loged in
C. me an two other Admins can't login to re close the boards (I suspect those logged in made new accounts)
D. Someone named the forums "I EAT MY OWN POOP" <-- \:\(

What do I do?
_________________________
Member since November 2004
Gold Member since Feb 2008
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#177222 - 02/03/07 11:48 AM Re: Having a bit of an emergency, help! [Re: luket]
Rick Offline
Post-a-holic
Registered: 06/04/06
Posts: 10164
Loc: Aberdeen, WA
Did you already give the URL to the new forums before the import was done? What happens is the very first user to register is the admin user, so someone registered before any of your users were imported and became an admin.

Personally, I'd recommend starting over, either in a new unknown directory, or if that's not possible, put it behind some .htaaccess file that requires authentication before you can get to anything in the directory to keep unwanted people away.
Top
#177223 - 02/03/07 11:48 AM Re: Having a bit of an emergency, help! [Re: luket]
luket Offline
member
Registered: 11/09/04
Posts: 191
I've started all over, with a new home directory for ubb in hopes that posters won't be able to find it.

All I can think is that the permissions we too permissive.
The insteructions say read, write, execute, and delete.
Those are dandy for unix I suppose, but what exactly are the permissions for Windows?

For instance, in windows you have:
Full
Modify
Read & Execute
List Folder Contents
Read
Write


So when the instructions say: read, write, execute, and delete
Is that in Windows terms:

Modify
Read & Execute
List Folder Contents
Read
Write

?

Is Delete modify?
Also, "List Folder Contents" is turned on automatically when you turn on "Read & Execute" ..

So orignally, I had set Modify, Read & Execute, List Folder, Contents, Read, and Write to satisfy the instructions. I however now think that maybe these were too permissive and that's how someone got in there and hacked my board.

Any help here would be greatly appriciated.
_________________________
Member since November 2004
Gold Member since Feb 2008
Top
#177225 - 02/03/07 11:53 AM Re: Having a bit of an emergency, help! [Re: Rick]
luket Offline
member
Registered: 11/09/04
Posts: 191
 Originally Posted By: Rick
Did you already give the URL to the new forums before the import was done? What happens is the very first user to register is the admin user, so someone registered before any of your users were imported and became an admin.


omg! LOL!
Haha .. yeah .. please put that in huge bold somewhere.
If I announce my boards are going offline, and /forums and /ubbthreads are common knowledge, then we can all expect to be hacked.

Better yet, have some file you modify during install to create the admin, or maybe use the database login .. heh, something.

Anywho .. yeah .. I've totally started over, given my home directory a secret name.


Edited by luket (02/03/07 02:03 PM)
_________________________
Member since November 2004
Gold Member since Feb 2008
Top
#177344 - 02/03/07 05:53 PM Re: Having a bit of an emergency, help! [Re: luket]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14994
Loc: Portland, OR; USA
There was a gallery software I used once that required you upload a file with a random string in order to create your admin user...
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#177370 - 02/03/07 06:31 PM Re: Having a bit of an emergency, help! [Re: Gizmo]
luket Offline
member
Registered: 11/09/04
Posts: 191
Yep, that or just force the creation during setup. Then the admin could merge that new account with his old admin account if she was importing *waves hands* ;\)
_________________________
Member since November 2004
Gold Member since Feb 2008
Top



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Custom forum permissions
by ntdoc
05/18/12 02:07 PM
Forum Stats
10489 Members
36 Forums
33841 Topics
181698 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image