Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
1 registered (Ruben), 26 Guests and 25 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 08/24/09
Posts: 29
Top Posters (30 Days)
Ruben 47
Bert 26
Gizmo 18
Rob Provencher 10
Rimex 9
SD 6
sw55 5
Eugene 5
Matthias1976 4
BellaOnline 3
Latest Photos
Uhm...
Mayan End of World
Gas Station Disco Video Shoot
Test Pictures
Audrey Kate
Page 1 of 2 1 2 >
Topic Options
#246505 - 10/29/11 05:49 PM Security Breach
Basil Offline
addict
Registered: 08/18/06
Posts: 689
Loc: Southwest US
Not really a "bug" but not sure where else to post this. I am running the latest version with the security patch. Today I was notified that there were some "anonymous" posts showing up in the "Active Topics" that were in a "non-existent" forum. Sure enough, there was a thread in a forum that had long been closed, but somehow someone was posting replies in that thread without being a member. The original thread was a legit thread, but there were dozens of recent replies that all had links to porno sites.
I recorded all the IP addresses and did a search in my server's log file.

Here is an example of what I found associated with one of those IPs:

123.234.47.195 - - [29/Oct/2011:16:30:26 -0400] "POST /xxxxxxx/ubbthreads.php HTTP/1.0" 302 - "http://www.xxxxxxxxxxxx.com/xxxxxxx/ubbthreads.php/topics/235868/2" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"

The permissions in the closed forum would not have (or should not have) allowed anyone not a registered member to post, but somehow someone did. Any thoughts or ideas?
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#246511 - 10/31/11 03:12 PM Re: Security Breach [Re: Basil]
Mike L Offline
member
Registered: 06/05/06
Posts: 101
Can't help much with the breach, but would suggest locking out ALL IP addresses from China. Not likely you have any legit users from there (then again you might, I don't know).

One thing for sure is that China is the source of a LOT of undesired internet traffic. Blocking out the complete range of IP addresses gets rid of the largest source of mischief.
Top
#246545 - 11/03/11 03:32 PM Re: Security Breach [Re: Basil]
JPFolks Offline
journeyman
Registered: 07/21/08
Posts: 52
How do you block all the chinese IPs?

Also, I believe we may have had a password breach on our board. We're still using 7.01 so according to the recent security breach warning, it did not apply to us since we were not 7.3 or after. Who do we talk to about this?

Brian
_________________________
Brian Austin Whitney
Founder
Just Plain Folks Music Organization
www.justplainfolks.org
Top
#246549 - 11/03/11 04:18 PM Re: Security Breach [Re: Basil]
gliderdad Offline
Registered: 06/07/06
Posts: 1475
Loc: NY
If your not comfortable doing the upgrade, I would contact Gizmo

To block countries you would need to do so via an .htaccess file and block ip's

http://www.wizcrafts.net/chinese-blocklist.html

http://www.countryipblocks.net/country-blocks/cidr/?country=KR&view_country_ips=Submit+Query
Top
#246550 - 11/03/11 05:40 PM Re: Security Breach [Re: Basil]
Mike L Offline
member
Registered: 06/05/06
Posts: 101
Yes. A .htaccess file is one way that works for blocking http requests and is the easiest and often the only option if you are on a hosted account.

However iptables/netfilter is best, but is far more complex to configure and is not an option for many (most?). It was beyond my talents before doing a LOT of reading.
Top
#246567 - 11/05/11 01:36 PM Re: Security Breach [Re: Basil]
JPFolks Offline
journeyman
Registered: 07/21/08
Posts: 52
We have an IP ban feature built into 7.01. Would that work? Is there a way to paste in a range of IPs? Russia is the other country we'd like to block. I tried blocking anything that had a .ru but that didn't slow them down. We get 60+ bogus sign up attempts per day.

Is 7.01 at risk? If so they should have said that and not singled out only 7.3 and newer!

Thanks for the help guys,

Brian
_________________________
Brian Austin Whitney
Founder
Just Plain Folks Music Organization
www.justplainfolks.org
Top
#246572 - 11/06/11 07:20 AM Re: Security Breach [Re: Basil]
gliderdad Offline
Registered: 06/07/06
Posts: 1475
Loc: NY
I am guessing you are using an .htaccess or iptables for the ip ban? That has nothing to do with the software and you should be fine.

Any version under the current version could be a risk. Just like your computer, web server software it is strongly recommended and advised to stay up to date with current versions.

If looked at the old change logs, you will see many bugfixes. Those could also have some security security fixes as well. There was a lot changed from v7.01 to v7.3 and probably would have been a lot to find and patch.

I think there should be a time that version numbers reach and EOL for support such as patches and stuff as its harder on the developers to keep so many versions up to date.
Top
#246595 - 11/06/11 07:32 PM Re: Security Breach [Re: Basil]
SD Offline
Registered: 04/19/07
Posts: 4205
Loc: SoCal, USA
i'd highly recommend going to version 7.5.6 with patches, if you are running 7.0.1

you are at risk there, if someone really wants to hack in..
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#246607 - 11/06/11 10:33 PM Re: Security Breach [Re: SD]
Gizmo Offline

Registered: 06/05/06
Posts: 15455
Loc: Portland, OR; USA
Originally Posted By: Sirdude
i'd highly recommend going to version 7.5.6 with patches, if you are running 7.0.1
+1
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime Supporter, Beta Tester & Resident Post-A-Holic.
Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Top
#247052 - 11/26/11 12:44 PM Re: Security Breach [Re: SD]
Basil Offline
addict
Registered: 08/18/06
Posts: 689
Loc: Southwest US
Originally Posted By: Sirdude
i'd highly recommend going to version 7.5.6 with patches, if you are running 7.0.1

you are at risk there, if someone really wants to hack in..


That's what I am running. As I said in my original post running the latest version with the security patch that came out recently.

Update: Never mind. Your post said RE: Basil, but I'm guessing your meant your comment for another user. My bad.


Edited by Basil (11/26/11 12:47 PM)
Top
#247053 - 11/26/11 12:52 PM Re: Security Breach [Re: Mike L]
Basil Offline
addict
Registered: 08/18/06
Posts: 689
Loc: Southwest US
Originally Posted By: Mike L
Can't help much with the breach, but would suggest locking out ALL IP addresses from China.


I've been thinking about that for awhile. Every time I get some bogus user from China sign up, I check what range of IPs their provider is and put the entire range in my iptables on my server. By now I've probably got half the IPs in China blocked. Guess I need to just go get the rest of them in there as well.
Top
Page 1 of 2 1 2 >



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Time zone setup
by skicomau
05/22/13 12:16 AM
Express hosting.
by Ruben
05/16/13 03:54 PM
Level of detail in new user registration emails
by Mitch P.
05/15/13 10:20 PM
Approving users
by Bert
05/15/13 09:22 PM
Users randomly added to other group
by Bert
05/15/13 09:15 PM
Forum Stats
10969 Members
36 Forums
33959 Topics
183413 Posts

Max Online: 978 @ 06/24/07 10:19 PM
Random Image