Go Back   CodingForums.com > :: Other forums > Forum feedback and announcements

Before you post, read our: Rules & Posting Guidelines

Reply
 
Thread Tools Rate Thread
Enjoy an ad free experience by logging in. Not a member yet? Register.
Old 11-29-2007, 01:44 PM   PM User | #1
WA
Administrator


 
Join Date: Mar 2002
Posts: 2,596
Thanks: 2
Thanked 19 Times in 18 Posts
WA will become famous soon enough
CF was hacked this morning

Early this morning CodingForums was hacked, specifically, the vBulletin software. The hacker added himself as an admin user, and carried out a few tasks such as email all forum members letting them know about it. The user gained entry through a vulnerability in vBulletin, as we weren't using the latest version.

I've been working with our host and believe everything should be back to normal now. The way member passwords are stored, the hacker should not have access to them. FYI having access to an account is different than knowing its password, due to the way vBulletin stores the passwords. Better safe than sorry however, so I urge everyone to go into the USER CP and change their password.
Usually I'm very cautious when it comes to security, but this time laziness got the best of me as I left the vBulletin software unpatched for a while. Sorry about the downtime, and let me know if you experience any problems.
__________________
- George
- JavaScript Kit- JavaScript tutorials and 400+ scripts!
- JavaScript Reference- JavaScript reference you can relate to.

Last edited by WA; 11-29-2007 at 02:17 PM..
WA is offline   Reply With Quote
Old 11-29-2007, 02:02 PM   PM User | #2
bazz
Master Coder

 
Join Date: Apr 2003
Location: in my house
Posts: 5,211
Thanks: 39
Thanked 201 Times in 197 Posts
bazz will become famous soon enoughbazz will become famous soon enough
There's a word for people like that!!

It's working better now but I find that the main index isn't presenting correctly in FF. It's as though the tables of forums needs the clear : all attricute added as the grey adverts immediately above it, push it to the right - off the screen.

XP(1024x768)FF 2.0.0.10

bazz
bazz is offline   Reply With Quote
Old 11-29-2007, 02:08 PM   PM User | #3
WA
Administrator


 
Join Date: Mar 2002
Posts: 2,596
Thanks: 2
Thanked 19 Times in 18 Posts
WA will become famous soon enough
Quote:
It's as though the tables of forums needs the clear
That was it exactly, thanks. Yep, real pain in the ***, having to stay awake the entire night to take care of this.
__________________
- George
- JavaScript Kit- JavaScript tutorials and 400+ scripts!
- JavaScript Reference- JavaScript reference you can relate to.
WA is offline   Reply With Quote
Old 11-29-2007, 02:28 PM   PM User | #4
bazz
Master Coder

 
Join Date: Apr 2003
Location: in my house
Posts: 5,211
Thanks: 39
Thanked 201 Times in 197 Posts
bazz will become famous soon enoughbazz will become famous soon enough
if your still awake, can you find out why I can't edit a post in the MYSQL forum. maybe a mod can delete it. it's called 5th attempt to post - test.

Whilst i was able to post, I havenlt been able to edit it with a real message.

no rush - sleep is necessary lol.

bazz
bazz is offline   Reply With Quote
Old 11-29-2007, 02:37 PM   PM User | #5
WA
Administrator


 
Join Date: Mar 2002
Posts: 2,596
Thanks: 2
Thanked 19 Times in 18 Posts
WA will become famous soon enough
Hmm what happens when you try to edit your thread, by clicking on the "Edit" icon? I tried logging in using a test account, and was able to post then edit a test thread.
__________________
- George
- JavaScript Kit- JavaScript tutorials and 400+ scripts!
- JavaScript Reference- JavaScript reference you can relate to.
WA is offline   Reply With Quote
Old 11-29-2007, 02:41 PM   PM User | #6
bazz
Master Coder

 
Join Date: Apr 2003
Location: in my house
Posts: 5,211
Thanks: 39
Thanked 201 Times in 197 Posts
bazz will become famous soon enoughbazz will become famous soon enough
I tried again to post a new thread and got this.

[big letters] Not Acceptable [/big letters]

An appropriate representation of the requested resource /newthread.php could not be found on this server.

Apache/1.3.37 Server at www.codingforums.com Port 80

I tried to edit the message and got this:

[Big Letters]Not Acceptable[/Big Letters]
An appropriate representation of the requested resource /editpost.php could not be found on this server.

Apache/1.3.37 Server at www.codingforums.com Port 80



So I can't edit the last 'test' message I wrote.

bazz

Strangely, I can edit this message OK.

Last edited by bazz; 11-29-2007 at 02:47 PM..
bazz is offline   Reply With Quote
Old 11-29-2007, 02:50 PM   PM User | #7
Inigoesdr
Super Moderator


 
Inigoesdr's Avatar
 
Join Date: Mar 2007
Location: Florida, USA
Posts: 3,601
Thanks: 2
Thanked 397 Times in 390 Posts
Inigoesdr is a jewel in the roughInigoesdr is a jewel in the roughInigoesdr is a jewel in the rough
That explains the login box I got when I tried to load the site this morning. I didn't get the e-mail though. Looks like the mod/admin images are gone.
Inigoesdr is offline   Reply With Quote
Old 11-29-2007, 02:50 PM   PM User | #8
WA
Administrator


 
Join Date: Mar 2002
Posts: 2,596
Thanks: 2
Thanked 19 Times in 18 Posts
WA will become famous soon enough
Quote:
An appropriate representation of the requested resource /newthread.php could not be found on this server.

Apache/1.3.37 Server at www.codingforums.com Port 80
Ok, that issue should be solved now.
__________________
- George
- JavaScript Kit- JavaScript tutorials and 400+ scripts!
- JavaScript Reference- JavaScript reference you can relate to.
WA is offline   Reply With Quote
Old 11-29-2007, 03:17 PM   PM User | #9
_Aerospace_Eng_
Supreme Master coder!


 
_Aerospace_Eng_'s Avatar
 
Join Date: Dec 2004
Location: In a place far, far away...
Posts: 19,293
Thanks: 2
Thanked 1,044 Times in 1,020 Posts
_Aerospace_Eng_ is a glorious beacon of light_Aerospace_Eng_ is a glorious beacon of light_Aerospace_Eng_ is a glorious beacon of light_Aerospace_Eng_ is a glorious beacon of light_Aerospace_Eng_ is a glorious beacon of light
The thank user for post buttons appear twice on each post.
__________________
||||If you are getting paid to do a job, don't ask for help on it!||||
_Aerospace_Eng_ is offline   Reply With Quote
Old 11-29-2007, 03:31 PM   PM User | #10
real30
Banned

 
Join Date: Nov 2007
Posts: 0
Thanks: 0
Thanked 0 Times in 0 Posts
real30 is an unknown quantity at this point
hello dear

our group has found a bug on Vbulletin 3.6.x Serries

with this Bug you easily in less than 2 minutes get the Admin Access to a Registered User.

Not even updating Patches will solve this Priv8 exploit. (admin please dont make urself tired ; )

you can easily hack 97 % of Vbulletin forums.

of you want ? send me Email for deal.

Email John.hendrich [at] yahoo [dot] com
Y!M : john.hendrich


- regards
real30 is offline   Reply With Quote
Old 11-29-2007, 03:34 PM   PM User | #11
matak
Banned

 
Join Date: Apr 2007
Posts: 428
Thanks: 29
Thanked 5 Times in 5 Posts
matak is on a distinguished road
damn hackers.

i will just remind that i also have two "thank you for post" buttons on posts

anyway, sometimes it's good that forum is offlimits, couse i saw sun today, after a long period of time (j/k i didn't saw sun, couse other forums were online )

@aerospace i think someone edited your sig couse it's big
matak is offline   Reply With Quote
Old 11-29-2007, 03:44 PM   PM User | #12
real30
Banned

 
Join Date: Nov 2007
Posts: 0
Thanks: 0
Thanked 0 Times in 0 Posts
real30 is an unknown quantity at this point
Quote:
Originally Posted by matak View Post
damn hackers.

i will just remind that i also have two "thank you for post" buttons on posts

anyway, sometimes it's good that forum is offlimits, couse i saw sun today, after a long period of time (j/k i didn't saw sun, couse other forums were online )

@aerospace i think someone edited your sig couse it's big
please be polite
real30 is offline   Reply With Quote
Old 11-29-2007, 04:02 PM   PM User | #13
bazz
Master Coder

 
Join Date: Apr 2003
Location: in my house
Posts: 5,211
Thanks: 39
Thanked 201 Times in 197 Posts
bazz will become famous soon enoughbazz will become famous soon enough
I agree totally. There is no point in getting annoyed with such inconsequential pieces of pond life who are of absolutely no benefit to anyone.

bazz
bazz is offline   Reply With Quote
Old 11-29-2007, 04:07 PM   PM User | #14
funnymoney
Regular Coder

 
funnymoney's Avatar
 
Join Date: Aug 2007
Posts: 364
Thanks: 17
Thanked 24 Times in 24 Posts
funnymoney is an unknown quantity at this point
you are really a lousy forum admin, you can't even ban people like you are supposed to... ROFL
funnymoney is offline   Reply With Quote
Old 11-29-2007, 04:31 PM   PM User | #15
Inigoesdr
Super Moderator


 
Inigoesdr's Avatar
 
Join Date: Mar 2007
Location: Florida, USA
Posts: 3,601
Thanks: 2
Thanked 397 Times in 390 Posts
Inigoesdr is a jewel in the roughInigoesdr is a jewel in the roughInigoesdr is a jewel in the rough
Who was supposed to be banned?
Inigoesdr is offline   Reply With Quote
Reply

Bookmarks

Jump To Top of Thread


Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 11:05 AM.


Advertisement
Log in to turn off these ads.