Previous Thread
Next Thread
Print Thread
Hop To
#240110 10/30/2010 11:16 AM
Joined: Mar 2009
Posts: 180
T
member
member
T Offline
Joined: Mar 2009
Posts: 180
I discovered a 'new member' who was able to give himself 'Administrator' status. (Which scares me.)

I demoted this hacker to 'user' status -- banned him and his IP address (proxy).

I'm not sure how this happened nor am i sure how to prevent it in the future. Myself and the other admin are changing our passwords. I changed the CP so that new registrants need Admin approval.

Anything else? Any ideas?

(On a separate note, i'm not sure if this hacker caused our server to crash, https://www.ubbcentral.com/forums/ubbthreads.php/topics/240109.html#Post240109 )

tacks #240111 10/30/2010 11:33 AM
Joined: Mar 2009
Posts: 180
T
member
member
T Offline
Joined: Mar 2009
Posts: 180
I do not believe that a moderator is capable of changing someone's status to "Administrator." So i can rule out their user profiles as suspects.

Am i correct?

Last edited by tacks; 10/30/2010 11:53 AM.
tacks #240112 10/30/2010 11:57 AM
Joined: Mar 2009
Posts: 180
T
member
member
T Offline
Joined: Mar 2009
Posts: 180
If someone with 'administrator' authority has not logged in since two months ago then they could NOT have done any malicious acts this week. Correct?

I can rule them out?

tacks #240113 10/30/2010 3:25 PM
Joined: Feb 2007
Posts: 1,294
Likes: 2
Veteran
Veteran
Joined: Feb 2007
Posts: 1,294
Likes: 2
Well first off, I really pondered responding to this thread as I didn’t care to be lashed out at by members of this or any other community here on the internet.

Now from someone whom use to design firewall software to protect interactive software on line such as the UBB…..

Hacker

<person, jargon> (Originally, someone who makes furniture with an axe)

1. A person who enjoys exploring the details of programmable systems and how to stretch their capabilities, as opposed to most users, who prefer to learn only the minimum necessary.

2. One who programs enthusiastically (even obsessively) or who enjoys programming rather than just theorizing about programming.

3. A person capable of appreciating hack value.

4. A person who is good at programming quickly.

5. An expert at a particular program, or one who frequently does work using it or on it; as in "a Unix hacker". (Definitions 1 through 5 are correlated, and people who fit them congregate.)

6. An expert or enthusiast of any kind. One might be an astronomy hacker, for example.

7. One who enjoys the intellectual challenge of creatively overcoming or circumventing limitations.

8. (Deprecated) A malicious meddler who tries to discover sensitive information by poking around. Hence "password hacker", "network hacker". The correct term is cracker.

Cracker

<jargon> An individual who attempts to gain unauthorized access to a computer system. These individuals are often malicious and have many means at their disposal for breaking into a system. The term was coined ca. 1985 by hackers in defense against journalistic misuse of "hacker". An earlier attempt to establish "worm" in this sense around 1981--82 on Usenet was largely a failure.

Use of both these neologisms reflects a strong revulsion against the theft and vandalism perpetrated by cracking rings. The neologism "cracker" in this sense may have been influenced not so much by the term "safe-cracker" as by the non-jargon term "cracker", which in Middle English meant an obnoxious person (e.g., "What cracker is this same that deafs our ears / With this abundance of superfluous breath?" -- Shakespeare's King John, Act II, Scene I) and in modern colloquial American English survives as a barely gentler synonym for "white trash".

Now with that all said….

You have to know several things to determine what actually happened and how someone gained access to your UBB and or site.

Gaining access to your UBB and making themselves an administrator can easily be done by accessing the MySQL Database and changing a members access value from user to administrator directly in the user database for the UBB users.

This can be done if you have access to the database server through the web site your running on or through another web site with some sort of access to the database through a different software such as “ZenCart” that does not have very many security checks in relation to the database through the software.

Also you may need to know if the server including the MySQL server is running Linux or Windows. This also has a sort of relation on how the database is accessed that your message board aka UBB is using.

Now it is easy for any host, and many of them will for sure, point the finger at the first person whom reports a problem such as yours as the cause of the problem as having the actual problem with the unauthorized access to the site or database. You see it is much easier to just say it was the software on YOUR web site then actually investigate and find out what really happened.

Banning the person or his IP address really is not the fix if the access was gained through someone else’s web site to yours. You need to find out how the access was actually gained and fix that before you can do other things to make your site secure and rid your self of the “cracker” that gained access to your site.

No need to debate here on the terms defined in this post. To bad people are not just to lazy to actually learn something, like the news reporters that make the wrong terms popular, and get off their lazy rear ends and learn something.



tacks #240114 10/30/2010 4:23 PM
Joined: Mar 2009
Posts: 180
T
member
member
T Offline
Joined: Mar 2009
Posts: 180
Wow! Thanks for responding, JAISP! That's a good bit of information!

Can't say that i fully understand it or am familiar with what you're speaking of but i do sincerely appreciate it, none the less.



Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Bots
by Outdoorking - 04/13/2024 5:08 PM
Can you add html to language files?
by Baldeagle - 04/07/2024 2:41 PM
Do I need to rebuild my database?
by Baldeagle - 04/07/2024 2:58 AM
This is not a bug, but a suggestion
by Baldeagle - 04/05/2024 11:25 PM
Is UBB.threads still going?
by Aaron101 - 04/01/2022 8:18 AM
Who's Online Now
1 members (1 invisible), 859 guests, and 196 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20230217)