Previous Thread
Next Thread
Print Thread
Hop To
#224986 03/28/2009 9:46 AM
Joined: Jul 2004
Posts: 87
J
journeyman
journeyman
J Offline
Joined: Jul 2004
Posts: 87
Some 'mad' forum member - just arrived post this below:

($0 =~ m,(.*)/[^/]+,) && unshift (@INC, "$1");
# Get the script location: Windows \
($0 =~ m,(.*)\\[^\\]+,) && unshift (@INC, "$1"); $vars_config{CGIPath}/ubb_lib_misc.cgi $ubb eq 'do_login') {
$skip_cookie_check = 'true' &verify_id("$in{username}", "$in{password}");
my $pubname = $user_info[0];
my $dp = $user_info[1];
my $profile_number = $user_info[2];
my $mod_q = $user_info[3]; chomp($mod_q);
$vars_display{MembersOnlyAccess} eq 'YES'config{CGIPath}/ubb_pm.cgi";("$vars_wordlets_err{dead_end}");$cat_number) = split(/:/, $in{f}); should be finished in about 20 mins if i work at it, say bye bye to the forum


Anything to worry about?

Joined: Dec 2003
Posts: 1,796
Pooh-Bah
Pooh-Bah
Joined: Dec 2003
Posts: 1,796
???

Maybe if you are running ubb.classic (an older one at that). Those files he's referencing are from .classic - most likely he's reposting some hacker code that's been on the net for years.


- Allen
- ThreadsDev | PraiseCafe
Joined: Jul 2004
Posts: 87
J
journeyman
journeyman
J Offline
Joined: Jul 2004
Posts: 87
Thanks ;-)

Joined: Jun 2006
Posts: 16,300
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,300
Likes: 116
When you're yelling at him for attempting to hack your forum, you may mention those variables don't even exist, let alone the files he's referenced wink...


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Jun 2006
Posts: 81
M
member
member
M Offline
Joined: Jun 2006
Posts: 81
Script Kiddies are the worst. This one is not even smart enough to be called a Script Kiddy.

Joined: Dec 2003
Posts: 6,562
Likes: 78
Joined: Dec 2003
Posts: 6,562
Likes: 78
Originally Posted by Gizmo
When you're yelling at him for attempting to hack your forum, you may mention those variables don't even exist, let alone the files he's referenced wink...
Why tell him let him keep thinking the code is valid.
Otherwise he will try to develop a new hack.


Blue Man Group
There is no such thing as stupid questions. Just stupid answers
Joined: Jun 2006
Posts: 16,300
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,300
Likes: 116
or surf online for one that may have existed 8+ years ago for 20 minutes before a security release would have been issued tongue


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Dec 2003
Posts: 6,562
Likes: 78
Joined: Dec 2003
Posts: 6,562
Likes: 78
There you go.
Let the sorry dogs work for it.
Thats what I am saying why help them improve.


Blue Man Group
There is no such thing as stupid questions. Just stupid answers
Joined: Jul 2006
Posts: 2,143
Pooh-Bah
Pooh-Bah
Joined: Jul 2006
Posts: 2,143
Did you ever have a UBB.classic on your server? Is it still there?

Because I'm thinking this person maybe found an old UBB.classic and can read it in plain text because .cgi isn't being processed anymore?

Which means the members files are going to show in plain text.

Which means I hope your password isn't the same anymore.

That's all if you actually had a UBB.classic and it's still laying around, broken. If not, there's nothing to worry about at all, you're being bluffed.


This thread for sale. Click here! [Linked Image from navaho.infopop.cc]
Joined: Dec 2003
Posts: 1,796
Pooh-Bah
Pooh-Bah
Joined: Dec 2003
Posts: 1,796
That would be the only caveat (if you ran an .classic before), I'd change passwords on all admin accounts. Then ban the eejit and report him to his ISP for threats.


- Allen
- ThreadsDev | PraiseCafe

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Version 7.7.5 Images suddenly not displaying
by Stovebolt - 05/04/2024 11:19 AM
Bots
by Outdoorking - 04/13/2024 5:08 PM
Can you add html to language files?
by Baldeagle - 04/07/2024 2:41 PM
Do I need to rebuild my database?
by Baldeagle - 04/07/2024 2:58 AM
This is not a bug, but a suggestion
by Baldeagle - 04/05/2024 11:25 PM
Who's Online Now
3 members (Stovebolt, ahmed047, Gizmo), 931 guests, and 151 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20240501)