Previous Thread
Next Thread
Print Thread
Hop To
Joined: Jun 2008
Posts: 32
newbie
newbie
Joined: Jun 2008
Posts: 32
Hi,

Looks like my board was compromised sometime this morning with all links and images pointing to another website.

http://www.livc.net/ubbthreads/

Just notified my hosting provider.

I'm far from a programmer or code writer but wanted to inquire about how someone can do this and if its fixable by someone that just dabbles with this stuff.

Also, how can I close the board? The close board link also points to the other site.

Joined: Jun 2008
Posts: 32
newbie
newbie
Joined: Jun 2008
Posts: 32
Figured it out from googling around.
config.inc.php was hacked, replaced with backup.

Joined: Jun 2006
Posts: 16,299
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,299
Likes: 116
Well, some security auditing should be in order; just because someone fiddled with the UBB.threads script doesn't necessarily mean that's what was hacked/exploited, you should try and make sure all of the scripts on your site and (if you're on a VPS or Dedicated server) all of the scripts installed on the server as a whole are up to date.


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Jun 2008
Posts: 32
newbie
newbie
Joined: Jun 2008
Posts: 32
Thanks for your response.
Upon further investigation and now that I can get into my CP and see the logs, it looks like a login was made to my CP using an admin user name. It also shows the change made to the database paths and urls/paths and urls page replacing the board info with their info.

IP shows Cairo Egypt. I'm in NY.
Changed password and privileges for the acct in question.
Think that's enough?
Thanks again.

Joined: Apr 2007
Posts: 3,940
Likes: 1
SD Offline
Former Developer
Former Developer
Joined: Apr 2007
Posts: 3,940
Likes: 1
general rules to follow for a board that i suggest:

1. _never_ have an admin username be 'admin'
2. _always_ make the login name _different_ from the display name for all admins (ie: i show Sirdude here, but my login name is gismachie for example)
3. _never_ use a password that is a word or words or date or 123456 ( yes that is one of the most popular passwords! frown )
4. use a strong password and maybe even a tool like Lastpass to remember it for you ( it is free )

this will at least prevent anyone from guessing a login

2c

Joined: Jun 2008
Posts: 32
newbie
newbie
Joined: Jun 2008
Posts: 32

Thanks!


Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Bots
by Outdoorking - 04/13/2024 5:08 PM
Can you add html to language files?
by Baldeagle - 04/07/2024 2:41 PM
Do I need to rebuild my database?
by Baldeagle - 04/07/2024 2:58 AM
This is not a bug, but a suggestion
by Baldeagle - 04/05/2024 11:25 PM
spam issues
by ECNet - 03/19/2024 11:45 PM
Who's Online Now
2 members (Nightcrawler, Ruben), 694 guests, and 214 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20230217)