Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
2 registered (Gizmo, SteveS), 38 Guests and 14 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 06/07/07
Posts: 4
Top Posters (30 Days)
Ruben 50
DennyP 24
Gizmo 23
Dunny 15
SteveS 13
AllenAyres 12
dbremer 10
SD 10
drkknght00 9
doug 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Topic Options
#245060 - 08/20/11 03:26 PM Report of Suspected Hacking
MikeG Offline
stranger
Registered: 08/20/11
Posts: 11
Loc: SoCal
I'm a retired guy who uses my old company's BB to keep in touch. I think they use your software. The url that appears when I'm logged in is:

http://forums.*****.com/news/ubbthreads.php

It appears someone is loading up the members list with a bot. I don't know if it is an innocent experiment by one of the members, or a malicious Denial of Service attack by an outsider. I've told the IT guys about it at my old company, and they are working it from their end.

Are you aware of anyone hacking member lists at other sites using your software? Do you offer services to detect and shut down the hacker?

If you send me an email address where I can send you the evidence I'll do so. I'd rather not put it on a public forum.

mag


Edited by MikeG (08/20/11 04:04 PM)
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#245062 - 08/20/11 03:48 PM Re: Report of Suspected Hacking [Re: MikeG]
cascadeclimbers Offline

member
Registered: 06/02/04
Posts: 195
Loc: Seattle, WA
Well I didn't go as far as completely registering but it looks like your company has by-passed the UBB registration. Without any CAPTCHA it's possible someone has written a script to bulk register. Why they would do this on a site that isn't public facing is beyond me, but it always amazes me that people spam my board when we clearly no follow our links.
_________________________
Won't you take me to Funkytown?
Top
#245064 - 08/20/11 04:15 PM Re: Report of Suspected Hacking [Re: MikeG]
Alzea Offline
stranger
Registered: 08/16/11
Posts: 14
Loc: Indonesia
Use captcha, and email validation/verification when register.
Top
#245065 - 08/20/11 04:57 PM Re: Report of Suspected Hacking [Re: MikeG]
MikeG Offline
stranger
Registered: 08/20/11
Posts: 11
Loc: SoCal
There's 150000 people registered now, with perhaps 50 more new registrations every day, weekends included. A more plausible number of real registrants would be 1000 people. This make the list so long it takes excessive time to search it, 20 pages at a time. Once the bogus registrar is turned off,

Is it possible to add a column to the users list that stores last time the poster logged in?

Is there a low labor way to erase a class of registrants? The data available now includes number of posts and date registered. Getting rid of all registrants who've been in the system for more that two years, for example, and have never posted, would be a good start. There'd be some innocent victims, but apologies could be sent out.
Top
#245067 - 08/20/11 05:09 PM Re: Report of Suspected Hacking [Re: MikeG]
cascadeclimbers Offline

member
Registered: 06/02/04
Posts: 195
Loc: Seattle, WA
Just determine the IP address, this can't be that sophisticated, and then delete all the records with that IP.

But really you need to address the source of your problem which clearly seems to be that your company has bypassed the registration in an insecure way and the attacker is doing an injection attack.
_________________________
Won't you take me to Funkytown?
Top
#245068 - 08/20/11 06:03 PM Re: Report of Suspected Hacking [Re: MikeG]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
There is also my Stop Forum Spam modification over @ UBBDev that helps thwart malicious registrations.
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#245071 - 08/20/11 06:40 PM Re: Report of Suspected Hacking [Re: MikeG]
cascadeclimbers Offline

member
Registered: 06/02/04
Posts: 195
Loc: Seattle, WA
Gizmo, the problem is they have bypassed the registration system with their own that allows form injection. It's not spam they are dealing with.

Listen, I'm know I'm going to come off as a total ass over this, but your former company choose to modify their board in such a way that compromised it. This is their problem and has absolutely nothing to do with UBB. Only they can address this by securing their code, denying the IP addresses in .htaccess, and removing the malicious registrations. Obviously some script kiddy is trying to prove a point. I wish you guys luck getting it worked out.
_________________________
Won't you take me to Funkytown?
Top
#245074 - 08/20/11 07:21 PM Re: Report of Suspected Hacking [Re: MikeG]
MikeG Offline
stranger
Registered: 08/20/11
Posts: 11
Loc: SoCal
Noted. Thanks.
Top
#245077 - 08/20/11 08:37 PM Re: Report of Suspected Hacking [Re: cascadeclimbers]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
Originally Posted By: cascadeclimbers
Gizmo, the problem is they have bypassed the registration system with their own that allows form injection. It's not spam they are dealing with.
Good call, but they could make some implementation of this system for their registration system too tongue...
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#245080 - 08/20/11 11:04 PM Re: Report of Suspected Hacking [Re: MikeG]
cascadeclimbers Offline

member
Registered: 06/02/04
Posts: 195
Loc: Seattle, WA
Gizmo, I'll be honest I have not checked out your system but I'm sure it's great and might address the result of the problem. I'm just saying they need to address the cause.
_________________________
Won't you take me to Funkytown?
Top



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Temporary Password email not being received
by
05/24/12 10:02 PM
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Forum Stats
10492 Members
36 Forums
33842 Topics
181709 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image