Welcome to the E-Blah Community!
We would like to welcome you to our community and invite you to register an account or login.
Being a registered member is important, as it gives you several advantages over the normal Guest status. After registering you will be able to download files and images, post messages, and access member-only portions of the forum - just to name a few. Registration is quick and simple, and only takes about a minute of your time.

E-Blah Community    Technical Support    Question and Answer  ›  Forum hacked and users deleted
Users Browsing Forum
Googlebot and 4 Guests

Forum hacked and users deleted  This thread currently has 590 views. Print
1 Pages 1 Recommend Thread
pcmantinker
January 5, 2010, 9:07pm Report to Moderator Report to Moderator

It's not what is seen that matters, it's character
Forum Support Team
Posts: 486
Gender: Male
Posts Per Day: 0.25
Reputation: 100.00%
Reputation Score: +11 / -0
Time Online: 3 days 22 hours 25 minutes
Location: Covington, LA
Age: 21
Recently, someone was hacking my forum and setting member data file contents to nothing. This rendered certain user accounts with a position of power on my forum to be disabled. I looked at the size of the data files affected through my FTP client and they said zero bytes. I know that it wasn't a server error because every time I would restore the data files, they would be nullified as soon as the hacker realized that they had been restored. Eventually, I just had to disable the forum overnight and stop fighting with the hacker. My forum is in good health now, but I'm not sure how the person was hacking my forum without FTP access. Is there a way to prevent something like this from happening again?


IGA: International Gamers' Alliance: http://www.iga-home.net/
Social Networking Website for Gamers

Life is so much better sober.
For it is by grace you have been saved, through faith—and this not from yourselves, it is the gift of God—[Eph 2:8]
Logged Offline
Site Site Private Message Private message AIM AIM YIM YIM Windows Live Messenger WLM Skype Skype
iCONICA
January 5, 2010, 10:23pm Report to Moderator Report to Moderator

Forum Moderation
Posts: 1,431
Gender: Male
Posts Per Day: 0.96
Reputation: 98.25%
Reputation Score: +56 / -1
Time Online: 16 days 2 hours 20 minutes
Location: Manchester UK
The only two ways I can think of, being familiar with E-Blah is if they did have FTP access at one point, inserted a file which you'd not noticed and when you (presumably) changed FTP details to try to block him out, he could still use his pre-written file from his browser to delete the files?... Look for any files that shouldn't be there, or try to get him active again and look for running processes on the server, see what's what...


Logged Offline
Site Site Private Message Private message Windows Live Messenger WLM Reply: 1 - 4
evixion
January 6, 2010, 9:36am Report to Moderator Report to Moderator

Web Developer for Hire
Forum Moderation
Posts: 226
Gender: Male
Posts Per Day: 0.19
Reputation: 100.00%
Reputation Score: +6 / -0
Time Online: 7 days 1 hours 34 minutes
Location: Elizabethton, Tennessee
Age: 26
one thing i did as an extra precaution is write a bash script to automatically tar up the cgi-bin part of the forums and the blahdocs part (2 separate operations) and every time the automatic backup is done, it checks for a backup older than 30 days and removes the oldest backup. the only downside is not everyone has ssh access and the other one is the files are saved in a user folder (/home/username) instead of the www directory so all restorations will take a bit of time and patience to tinker with.

i hope this issue is figured out so if it is a major issue, it can be fixed.


Logged Offline
Site Site Private Message Private message Windows Live Messenger WLM Reply: 2 - 4
pcmantinker
January 7, 2010, 4:11pm Report to Moderator Report to Moderator

It's not what is seen that matters, it's character
Forum Support Team
Posts: 486
Gender: Male
Posts Per Day: 0.25
Reputation: 100.00%
Reputation Score: +11 / -0
Time Online: 3 days 22 hours 25 minutes
Location: Covington, LA
Age: 21
Yeah, I have a weekly backup scheduled so that if anything terribly wrong were to happen, I could restore a snapshot of my website. However, it would take a while to restore as it's a snapshot of my whole website which is about 1GB. My webhost is on a Windows server so I'm afraid that bash scripting is not an option to create routine backups of the forum and blahdocs. I may be able to setup something similar with Windows however. I could possibly write a Windows program to login to my FTP account and download the forum on a routine basis and zip the contents. It could run in the background as a service and startup everytime Windows starts. I'll play with some options and see what I can come up with.


IGA: International Gamers' Alliance: http://www.iga-home.net/
Social Networking Website for Gamers

Life is so much better sober.
For it is by grace you have been saved, through faith—and this not from yourselves, it is the gift of God—[Eph 2:8]
Logged Offline
Site Site Private Message Private message AIM AIM YIM YIM Windows Live Messenger WLM Skype Skype Reply: 3 - 4
evixion
January 8, 2010, 3:50pm Report to Moderator Report to Moderator

Web Developer for Hire
Forum Moderation
Posts: 226
Gender: Male
Posts Per Day: 0.19
Reputation: 100.00%
Reputation Score: +6 / -0
Time Online: 7 days 1 hours 34 minutes
Location: Elizabethton, Tennessee
Age: 26
AutoIT or a batch script could possible do either one and maybe make it a scheduled task


Logged Offline
Site Site Private Message Private message Windows Live Messenger WLM Reply: 4 - 4
1 Pages 1 Recommend Thread
Print

E-Blah Community    Technical Support    Question and Answer  ›  Forum hacked and users deleted

Thread Tags
forum,  data,  i,  hacking,  ftp