Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Jan 2002
Posts: 18
Junior Member
Junior Member
Offline
Joined: Jan 2002
Posts: 18
Someone put this inside image tags in posts on my forum:

[code erased]

and:

[code erased]

It was on my site for a few hours. I changed my moderator passwords after I deleted the hacking attempts. I disable images and censored "x", "x" and "x". I am running UBB 6.2.0. I will be upgrading soon.

Was this a professional hack attempt? Might it have gotten anything? The persons who did it got mad at my forum only in the last day or two. Do they seem to know what they are doing?

Thank you very much.

Sponsored Links
Joined: Mar 2001
Posts: 7,394
LK Offline
Admin / Code Breaker
Admin / Code Breaker
Offline
Joined: Mar 2001
Posts: 7,394
Yes, it is serious. However, 6.3 fixed all these problems, so just upgrade.

Joined: Jun 2001
Posts: 729
Coder
Coder
Offline
Joined: Jun 2001
Posts: 729
CAn you please PM me the code that was used.

Much appreciated...

Joined: Jan 2002
Posts: 18
Junior Member
Junior Member
Offline
Joined: Jan 2002
Posts: 18
I noticed that the code I posted and even the words I censored where deleted. Is there a proper way for me to ask for help about these things in the future? This attack was just one day after these people got mad at my forum. I am worried about what else they will do.

I have now upgraded to 6.3.0. I am turning images back on.

Do you think that they could have gotten any of my members information? Would my members have had to actually push a "submit" button, like the "submit reply" or "edit post" button while logged in? What about members who were not logged in and posted anonymously like I allow? Could their cookies or whatever still have been sent to that place?

Thank you for your help.

Joined: Mar 2001
Posts: 7,394
LK Offline
Admin / Code Breaker
Admin / Code Breaker
Offline
Joined: Mar 2001
Posts: 7,394
Oblomov, I sent you a PM about the members that their cookies got stolen.

I removed the code because I didn't want people to get it here and use it in older versions. I wouldn't mind if you PM it to QuickSI, but it's not the only way. I made some that work myself (some don't even need img).

Anyhow, why 6.3.0 and not 6.3.1? tipsy

Sponsored Links
Joined: Jun 2001
Posts: 729
Coder
Coder
Offline
Joined: Jun 2001
Posts: 729
LK can you also PM me the ones you know about. I would like to button up Hostboard the best I can.

Thanx!

Joined: Mar 2001
Posts: 7,394
LK Offline
Admin / Code Breaker
Admin / Code Breaker
Offline
Joined: Mar 2001
Posts: 7,394
Just look at ubbcgi.pm's unescape (and unescapeHTML) subs, and ubb_lib.cgi urlize and imageize subs (and the subs they refer to; also ubb_lib.cgi's [url] and [img] convertion, that uses urlize and imageize). If you copy them (they don't even have nothing to do with flat file, you can just copy), it will probably fix everything.

Joined: Jan 2002
Posts: 18
Junior Member
Junior Member
Offline
Joined: Jan 2002
Posts: 18
Do they have to be logged on to have their cookies stolen? If not, can cookies from other sites be stolen at the same time?

I have upgraded to 6.3.0 instead of a later version because my one year upgrade thing expired maybe a month ago or so ago and I had downloaded the 6.3.0 a little while before it expired.

Was this attack on my forum a cutting edge professional job? I have reason to believe it is the work of persons who work with cgi scripts. They just got mad at my forum in the last couple of days. I worry that more is coming.

I am very proud of the openness of my forum. I allow people to post to one of my forums without logging in as a member. I would like to see more support for this in UBB. Ideally, some day, I would like to have one of my forums a totally secure no registration forum. I would need to allow only images from my site, and have people load them in. I would need to make sure that any links that people click on would have the referrer logging disabled somehow. (I just realized that wouldn't be good enough. I would need to disallow links or warn people about following them.)

Thank you all for your help.

Joined: Mar 2001
Posts: 7,394
LK Offline
Admin / Code Breaker
Admin / Code Breaker
Offline
Joined: Mar 2001
Posts: 7,394
Yes, they have to be logged in. However, if you have other things with cookies on your UBB domain, it could've been stolen too. (btw, if you have something other than your UBB 6.3.0, ie. guestbooks, etc, I suggest you to close it)


Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Bill B
Bill B
Issaquah, WA
Posts: 87
Joined: December 2001
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20240430)