Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
2 registered (Gizmo, SteveS), 38 Guests and 14 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 06/07/07
Posts: 4
Top Posters (30 Days)
Ruben 50
DennyP 24
Gizmo 23
Dunny 15
SteveS 13
AllenAyres 12
dbremer 10
SD 10
drkknght00 9
doug 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Page 1 of 3 1 2 3 >
Topic Options
#245600 - 09/21/11 10:12 AM Help: multiple ID alert + spammer?
Chevy454 Offline
journeyman
Registered: 01/24/05
Posts: 74
Got the following mutliple ID alert this morning:

"A user from the IP 222.1.43.10 has logged in to the following accounts: Administration, barthold"

Firstly, "Administration" is member #2, which I believe was the original username used to setup the software many moons ago...but the IP addys listed under that name simply show the 127.0.0.1, which iirc, was changed to all users during an update/import several versions ago.

A quick google of barthold's email (nothingdif@gmail.com) pops up on the "stop forum spam" list, with the same username/email (but different IP) as was registered at our site.

So, can anyone explain how/why I got the alert? Is this user definitely a spammer? Do I need to boot/ban him, and do something with the "Administration" account?
_________________________
www.yenko.net
UBB.Threads 7.5.5
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#245604 - 09/21/11 11:43 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Dunny Offline
addict
Registered: 01/16/08
Posts: 460
Loc: DE USA
Not sure if it is a spammer or not, however I would probably change the admin password as soon as I could just in case.

Admin's usually don't use that default admin (or shouldn't be imo) so changing the password should not affect legitimate admins on your site.

Dunny
_________________________
Dunny

Removed link due to bleedover spammers

Dawn of Iskirra
Top
#245608 - 09/21/11 12:36 PM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
SD Offline
Registered: 04/19/07
Posts: 4056
Loc: SoCal, USA
thats a hack attempt and can be very serious... you need to address the issue and change passwords for Administrator..

also i'd really change the login name for all admins to NOT be same as display name..

that's my #1 rule for all admins..

look @ your ubb admin log for suspicious activity..
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#245676 - 09/22/11 08:45 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
razor_head Offline
member
Registered: 08/05/10
Posts: 108

We have switched to cPanel and have started getting reports of hacker attempts. We only get the IP address, which isn't enough, so I am gonna start a new suggestion thread on cPanel to report what user name was attempted and password used in each attempt.

As SD has said, this is serious. You might want to prowl around in your use group and make sure that the one who broke into your system didn't leave anything behind as a back door in case you discovered what they had done.

Larry
www.marriageadvocates.com
Top
#245834 - 09/24/11 10:52 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Bjab Offline
stranger
Registered: 10/27/09
Posts: 15
Loc: Tilburg, Netherlands
A couple of weeks ago we also had small hack. Our site was closed and had a "hacked by 'some hackuser name'" message on the offline-page. All admin's changed their password (also for ftp-acces). A couple of weeks later our ftp-root was empty after another hacking attempt. If you (sirdude) want to have the logs on this hacking attempt you can mail me. We still don't know where he came in, but since then we have an extra password (via helm control panel) on our admin-directory.

btw: we now have the latest ubb bug/security-fix installed
Top
#245978 - 09/26/11 10:01 AM Re: Help: multiple ID alert + spammer? [Re: SD]
Chevy454 Offline
journeyman
Registered: 01/24/05
Posts: 74
Originally Posted By: Sirdude
thats a hack attempt and can be very serious... you need to address the issue and change passwords for Administrator..

also i'd really change the login name for all admins to NOT be same as display name..

that's my #1 rule for all admins..

look @ your ubb admin log for suspicious activity..

Dumb question, but is it possible to change one's username? Having had the same username across several sites for over a decade now, I'd hate to change my display name, and I would be the other admins will object as well...
_________________________
www.yenko.net
UBB.Threads 7.5.5
Top
#245979 - 09/26/11 11:05 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
You could by database diving... Not sure why this isnt in the control panel though...
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#245982 - 09/26/11 02:00 PM Re: Help: multiple ID alert + spammer? [Re: Gizmo]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
Originally Posted By: Gizmo
You could by database diving... Not sure why this isnt in the control panel though...

You know in light of what has recently happened with the release of the security patch. It should be a option to request and have changed just like the change display name process works.
Then a user could keep the display name or vise versa.
Maybe SD will read this.
_________________________
Blue Man Group
Top
#246000 - 09/26/11 05:53 PM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Mike L Offline
journeyman
Registered: 06/05/06
Posts: 88
Ruben,

I agree, an option for any forum member to change their User name (as opposed to Display name) would be a nice added feature. This is something that need not be subject to any admin/moderator approval.

It would allow for those who created an account with the same user/display name to think better of it and introduce a little added security.
Top
#246097 - 09/30/11 10:12 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Chevy454 Offline
journeyman
Registered: 01/24/05
Posts: 74
Just a quick heads up: looks like the security breach added some ads to our forum:

http://www.yenko.net/ubbthreads/ubbthreads.php?ubb=showflat&Number=461721&page=2
_________________________
www.yenko.net
UBB.Threads 7.5.5
Top
#246098 - 09/30/11 10:23 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
gliderdad Offline
Registered: 06/08/06
Posts: 1466
Loc: NY
Contact Giz, he'll be able to help clean your site up wink
Top
#246099 - 09/30/11 10:36 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
SD Offline
Registered: 04/19/07
Posts: 4056
Loc: SoCal, USA
yah you were hacked prior to the security breach -- you will need someone with shell access to fix it

who is your host?
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#246100 - 09/30/11 10:42 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Chevy454 Offline
journeyman
Registered: 01/24/05
Posts: 74
BTW: can anyone tell me where that banner is being called from within UbbT? Is that area from the templates, possibly?
_________________________
www.yenko.net
UBB.Threads 7.5.5
Top
#246101 - 09/30/11 10:52 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Chevy454 Offline
journeyman
Registered: 01/24/05
Posts: 74
Here's what pops up in the source:
Code:
<div align="center">
<script type="text/javascript"><!--
google_ad_client = "pub-9330396700047182";
/* 728x90, ´´½¨ÓÚ 11-9-22 */
google_ad_slot = "3985911273";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">

</script>
_________________________
www.yenko.net
UBB.Threads 7.5.5
Top
#246103 - 09/30/11 10:54 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
gliderdad Offline
Registered: 06/08/06
Posts: 1466
Loc: NY
It should be in showflat.tpl. But as SD said, you will need someone with shell access to find the new hidden files that will add this back after you remove it.
Top
#246104 - 09/30/11 11:01 AM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
SD Offline
Registered: 04/19/07
Posts: 4056
Loc: SoCal, USA
yah, that is the problem

here is what happens.. pre security patch, the hacker leaves backdoors, so he really doesn't need ubb anymore to get in.

he goes away and tries other sites.

comes back and deposits more 'goodies'

so you'll need shell to find the CAUSE and not just treat the SYMPTOMS

wink
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#246105 - 09/30/11 11:11 AM Re: Help: multiple ID alert + spammer? [Re: gliderdad]
Chevy454 Offline
journeyman
Registered: 01/24/05
Posts: 74
Originally Posted By: gliderdad
It should be in showflat.tpl. But as SD said, you will need someone with shell access to find the new hidden files that will add this back after you remove it.

LOL, now ya tell me! I found it right after I posted above, but thanks for the confirmation!

Just as a note to myself, here's the code that was dumped in the header:

Code:
<div align="center">
<script type="text/javascript"><!--
google_ad_client = "pub-9330396700047182";
/* 728x90, ´´½¨ÓÚ 11-9-22 */
google_ad_slot = "3985911273";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>


Footer dump:

Code:
<div align="center">
<script type="text/javascript"><!--
google_ad_client = "pub-9330396700047182";
/* 728x90, ´´½¨ÓÚ 11-9-22 */
google_ad_slot = "3985911273";
google_ad_width = 728;
google_ad_height = 90;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

BTW: anyway to track back these guys via GoogleAds? Would they tell us who was getting paid for them??


Edited by Chevy454 (09/30/11 11:20 AM)
_________________________
www.yenko.net
UBB.Threads 7.5.5
Top
#246107 - 09/30/11 12:14 PM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Chevy454 Offline
journeyman
Registered: 01/24/05
Posts: 74
Anyone know of a way to track back via the google ad client #(pub-9330396700047182)?
_________________________
www.yenko.net
UBB.Threads 7.5.5
Top
#246108 - 09/30/11 12:55 PM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
usrbingeek Offline
member
Registered: 06/05/06
Posts: 105
Loc: Burlington, VT
https://www.google.com/adsense/support/bin/answer.py?answer=18386

Though, they aren't likely to provide any info to you, only law enforcement.
_________________________
All my best,
BowlingCommunity.com
Steve (@usrbingeek)

My Wishlist
Top
#246109 - 09/30/11 12:59 PM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Chevy454 Offline
journeyman
Registered: 01/24/05
Posts: 74
Yeah, I ran across that earlier and filled out the info, but a quick Google(!) search reveals that it doesn't seem anyone ever receives a reply from Google regarding this issue...so I was hoping someone knew of a better way, lol!

And the folks at Google AdSense don't do phone calls, either...unless you consider a looped recording a "resolution". mad
_________________________
www.yenko.net
UBB.Threads 7.5.5
Top
#246110 - 09/30/11 01:05 PM Re: Help: multiple ID alert + spammer? [Re: Chevy454]
Chevy454 Offline
journeyman
Registered: 01/24/05
Posts: 74
BTW: a big THANK YOU to everyone here for the help with this issue, especially Sir Dude!
_________________________
www.yenko.net
UBB.Threads 7.5.5
Top
Page 1 of 3 1 2 3 >



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Temporary Password email not being received
by
05/24/12 10:02 PM
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Forum Stats
10492 Members
36 Forums
33842 Topics
181709 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image