Previous Thread
Next Thread
Print Thread
Hop To
#129135 05/24/2006 12:08 AM
Joined: May 2006
Posts: 15
M
stranger
stranger
M Offline
Joined: May 2006
Posts: 15
My board v. 6.4.1 was hacked tonight, so I upgraded to the latest version. I'm having a few major issues though. When I try to login, all that I get is a black screen. I'm also unable to get rid of the hacker message despite replacing all of the files for the board with the latest versions. Here's the site: http://www.nittanyfootball.com/ubbthreads/ubbthreads.php

If I can get the admin login issue fixed, I think that will be the biggest issue because I'll at least be able to poke around the admin panel. Any help would be greatly appreciated.

Thank,
Mark

Joined: Dec 2003
Posts: 1,798
Likes: 2
Pooh-Bah
Pooh-Bah
Joined: Dec 2003
Posts: 1,798
Likes: 2
It looks ok to me, but you need to go through every file on your site, including .htaccess files. <img src="https://www.ubbcentral.com/boards/images/graemlins/frown.gif" alt="" />


- Allen
- ThreadsDev | PraiseCafe
Joined: May 2006
Posts: 15
M
stranger
stranger
M Offline
Joined: May 2006
Posts: 15
Allen,
Thank...I was up until 1am last night going through everything and finally fixed it...I think. Seems to be working for the most part now.

Joined: Jun 2006
Posts: 869
old hand
old hand
Joined: Jun 2006
Posts: 869
This guy got me good.. <img src="https://www.ubbcentral.com/boards/images/graemlins/frown.gif" alt="" />

[]Yesterday the Turkish cracker going by the handle "Iskorpitx", succesfully hacked 21,549 websites in one shot (plus 17,000 as our last update) and defaced (on a secondary page) all of them with a message showing the Turkish flag (with AtaTurk face on it) and reporting:

"HACKED BY iSKORPiTX

(TURKISH HACKER) [/]

Joined: May 2006
Posts: 15
M
stranger
stranger
M Offline
Joined: May 2006
Posts: 15
I had a different guy...or group. It was just as bad and was the reason I spent 4 hours fixing it and upgrading last night. Jerks.

Joined: Jun 2006
Posts: 16,532
Likes: 150
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,532
Likes: 150
Yeh, my local machine got nailed as well; I didn't bother upgrading it as it's a controlled enviroment, i just nuked the web partition lol...


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Jun 2006
Posts: 869
old hand
old hand
Joined: Jun 2006
Posts: 869
Here is the info

http://www.zone-h.org/news/read/id=206009

BUT it says it is an asp, my server is unix, i thought asp files did not run on unix??

My first infected file was on an older backup ubbthread folder, that was not active. I was not even aware that it could find such a thing. I first thought something was wrong when i ftped into my site and did a sort by day, then saw my old back upfolder was the most current......

live and learn on that one

Joined: Jun 2006
Posts: 16,532
Likes: 150
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,532
Likes: 150
You can install handlers to allow ASP files in Unix; just as you can install PHP on Windows.

Mine was in /private/test/threads where all directories weren't even indexed by apache so i was sort of baffeled as well.


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Jul 2005
Posts: 137
Member
Member
Joined: Jul 2005
Posts: 137
Yup, my site got done as well.
I'm confused as to (a) how it was done, and (b) how i can prevent it happening again.

Did not take too much time to get me back up again, however i have not yet checked every folder to see what else has been hacked, as i run several sites from the same root server.

Any pointers as to what files/directories to look for would be appreciated.

Thanks

Joined: Dec 2003
Posts: 1,798
Likes: 2
Pooh-Bah
Pooh-Bah
Joined: Dec 2003
Posts: 1,798
Likes: 2
a) security hole in a couple scripts allowed hacker to upload scripts to gain root access to server

b) update to latest 6.5.4 files to fix security holes.

Could be any file or directory - I'd first take a closer look at all .php and .pl files - I found one named l.php that gave shell access to the whole server. Another named mysql.php that gave access to databases. Another was dl.pl (or something similar) which was a perl shell app if I remember right. Also check .htaccess files for unusual entries.


- Allen
- ThreadsDev | PraiseCafe
Joined: Jun 2006
Posts: 869
old hand
old hand
Joined: Jun 2006
Posts: 869
rats,,,, I had some files changed this afternoon to the same turkey webpage... with this afternoons time on it...

How can I stop this guy?????


Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
PHP 8 bug in membermanage.tmpl
by phoenix011235 - 09/08/2026 7:47 PM
Are any of these legitmate?
by Baldeagle - 09/06/2026 1:37 PM
After server reboot
by Morgan - 09/02/2026 8:27 AM
8.0.1 Patch Changelog Discussion
by isaac - 11/26/2025 1:34 PM
Who's Online Now
0 members (), 296 guests, and 109 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Ride safe!
Ride safe!
by Morgan, December 7
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Powered by UBB.threads™ PHP Forum Software 8.1.0
(Snapshot build 20260527)