Previous Thread
Next Thread
Print Thread
Rate Thread
Joined: Apr 2003
Posts: 359
Enthusiast
Enthusiast
Joined: Apr 2003
Posts: 359
I gotta tell ya'll...I'm totally baffled along with my other moderators on this one...

I'm running v6.5 and the other day a member, "sabastian" had registered an account through an email address of "[email protected]" with the following IP information:

Registration / First IP: 03/11/05 01:30 PM - 69.251.71.162
Last Post / IP: 03/11/05 01:53 PM - 69.251.71.162

Turns out that this person managed to get into the Moderator's Lounge and post up some very obscene language to all of us.

Can you all help me understand how someone could have gotten himself registered and within 7 mins of him becoming a registered user of the site get access to our Moderator's Lounge and post?

I'm the only Admin on the site and I had not been on the site for a few days prior to this happening. Another Mod had called me via the phone and told me someone got unauthorized access to the Mod Lounge and I may want to squash it.

Any help on figuring this one out is greatly appreciated.

Mark
www.f-bodyhideout.com

Sponsored Links
Joined: Feb 2002
Posts: 2,286
Veteran
Veteran
Joined: Feb 2002
Posts: 2,286
From memory - I seem to recall this happening to someone else - I have done a search and can't find it straight away. Found one about a mod still getting subscriptions, but am sure that someone actually posted in a hidden forum.

If I find it, I will advise.


Fans Focus - Focusing on Fans of Sport

(Okay - mainly football (the British variety wink at the moment - but expanding all the time....)
Joined: May 2001
Posts: 550
Code Monkey
Code Monkey
Offline
Joined: May 2001
Posts: 550
It sounds like a sql injection exploit.
Remember 6.5.1.1.....

Joined: Oct 2003
Posts: 2,305
Old Hand
Old Hand
Joined: Oct 2003
Posts: 2,305
yeah I was trying to figure out how you inject yourself into the administration area.. you would have to add yourself to the moderator or administrator group. unless the post was added with a sql injection?

Joined: Mar 2000
Posts: 21,079
Likes: 3
I type Like navaho
I type Like navaho
Joined: Mar 2000
Posts: 21,079
Likes: 3
possible a mod just moved the post to the admin forum? We move questionable posts here to the staff forum


- Allen wavey
- What Drives You?
Sponsored Links
Joined: Apr 2003
Posts: 359
Enthusiast
Enthusiast
Joined: Apr 2003
Posts: 359
Eeeck! I'm so sorry for getting some of you worried yourselves as to the security of Threads.

It did turn out that one of our Mods moved this user's post to the Mod Lounge. The Mod had moved the post and did not tell any of us and was off the board for some time.

I'm so sorry to have alerted you all before I got the full scoop on this one....


Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
isaac
isaac
California
Posts: 1,157
Joined: July 2001
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)