Previous Thread
Next Thread
Print Thread
Hop To
Joined: Jan 2011
Posts: 6
D
stranger
stranger
D Offline
Joined: Jan 2011
Posts: 6
BAD bad news. We got hacked badly: guy got root. We reloaded OS, but out of 3 servers we run our UBB on, 1 is so dang old it can't have the latest plesk, for starters (7 only.) That's not my current issue.

My issue is that even after reloading the OS, I'm told there could have been - things - left behind (back doors, I am no server admin - far from it.)

I have heard there are services available to check servers thoroughly for anything that shouldn't be there. OBVIOUSLY before I update our UBB (which involves a move in hosting first, new servers, MONEY we don't now have but WILL within 2 months) I want what we have now as safe as possible: ergo a service that will 'clean' these servers. Red Hat, Plesk (2 of them: third has some other control panel.)

I -think- SQL injection was involved: we -think- a newer version of Ubb threads was exploited www.aftertherose.com (we may have 6 for our main domain, but my server partner is a genius: you've many times awarded him for the tweaks he's made at www.jokersupdates.com. He has 6 locked down like a bank vault: ergo that and some other ungodly server type crap I'll never understand leads him to think the exploit came from www.aftertherose.com forums.)

Don't care where: want the dang critters cleaned.

I -know- you guys will do the upgrade (I warn you in advance it will be THE worst upgrade you've ever handled: anyone who likes a challenge, a REAL challenge, pm me with rates. 2 months we're ON.) Prior to that, if any of you know anything about security: I heard there's automated stuff that can be used to scan everything on all 3 servers and spot bad crap.

I've done some research: my guy ran some 'somethingtools' thing (sorry, sorry - it's over my head) but we need a much better solution before this - this - *(*^DKJG%^ gets my root again. Which he will do: you don't run a community the size of mine for 10 years and not have, uh, people who are unkindly towards you. 999 out of 1000 the threats are BS: this one wasn't: all he did was create 3 bogus domains (fhj4kl.com, 2 more) but he knew a) it would email me b) I'd freak and know I was owned.

He was right.

But one place he was wrong: might be server-stupid but I know where to find people who aren't!

And where better than the folks who created ubb in the first place? THAT is the domain he's after: the one with ubb 6. So if you have any idea about how to check the servers' safety now: how to clean it and maybe use some tripwire thing I ran across - keep in mind plesk 7 is as far as I can go on one of those servers.

Please lord let there be security specialists here: if not, will you kindly inform me of the best companies who provide such a service? For this I'll find the damn money if I have to hock my soul to the Devil (my luck he'd laugh in my face!)

jokerette gmail and thank you - thank you so much for any help whatsoever.

Joined: Dec 2003
Posts: 6,562
Likes: 78
Joined: Dec 2003
Posts: 6,562
Likes: 78
There is no perfect security scenario.
That is why we have updates here as well as other software vendors.
The jerks always find a way to intrude.

My 2 cents I would guess the issue came from the joker site since it is version 6. But the rose site also is subject to intrusion since it is not version 7.5.7.

Currently it appears that your styles may have been compromised.
For the version 7 series it is stored in the database, even though you have a text file with the settings.

I don't have a clue on the 6x series.
but you could attempt to install a new style and see if it will fix the displayed forum for now.


Last edited by Ruben; 06/17/2013 4:53 PM.

Blue Man Group
There is no such thing as stupid questions. Just stupid answers
Joined: Jun 2006
Posts: 16,299
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,299
Likes: 116
Well, a huge recommendation on the hosting front is that when a user has gained root your best bet is to reinstall the OS on the server...

You should always try your best to keep all scripts up to date; a lot of providers provide release updates via newsletters now adays.

In an ideal world I'd tell you to backup your criticdal files, have the os reinstalled (and try to use the latest release), setup iptables (linux firewall) to allow only mysql, ssh (on a nonstandard port), ftp, and the webserver (including ssl and any ports your control panel of choice requires) then make sure every password on the machine has been changed from what it was in the first place. Then I'd make sure every piece of software and script is up to date with the latest releases.


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Apr 2007
Posts: 3,940
Likes: 1
SD Offline
Former Developer
Former Developer
Joined: Apr 2007
Posts: 3,940
Likes: 1
i'd stay away from plesk, since there is a zero day out there...

2c

or at least a properly patched/upgraded one, if you must

Joined: Jun 2006
Posts: 16,299
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,299
Likes: 116
I don't understand why people install Plesk/CPanel when Webmin/Usermin are free and can imo do the same thing with a smaller footprint...


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Bots
by Outdoorking - 04/13/2024 5:08 PM
Can you add html to language files?
by Baldeagle - 04/07/2024 2:41 PM
Do I need to rebuild my database?
by Baldeagle - 04/07/2024 2:58 AM
This is not a bug, but a suggestion
by Baldeagle - 04/05/2024 11:25 PM
Is UBB.threads still going?
by Aaron101 - 04/01/2022 8:18 AM
Who's Online Now
0 members (), 872 guests, and 248 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20230217)