![]() |
|
|||||||
![]() |
|
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#16 |
|
Flying MUni-ist
Join Date: Oct 2004
Location: Ontario, Canada
Age: 29
Posts: 57
|
Gilby, Thanks for making this forum available to us (even when you have to deal with the unexpected!) Great job...
-Malcolm |
|
|
|
|
|
#17 |
|
Waffle-Tosser, Time-bider and JCTK
Join Date: Feb 2002
Location: the bustling metropolis of Nelspruitia, south africa
Age: 45
Posts: 15,569
|
adding to the chorus of "THANK U's"
|
|
|
|
|
|
#18 |
|
Get up on your roof!
Join Date: May 2004
Location: Glasgow
Age: 34
Posts: 872
|
forum attack
Gilby, there's a guy in my internet class who knows about this kind of thing and he reckons you should:
"Check the full sites DIr structure and check for any PHP or ASP or CGI scripts pages or documents that you dont know. What an attacker will do while attacking a site is gain some sort of access to the site's direcotry, if this is whats happened here then they didnt just get access to the forums, they will have prob uploaded a backdoor .asp,.php.cgi file to the site that will allow them to come back any time they like and change edit delete or upload new pages. They will also prob wait a wee while , this wait allows the site admin, this being you, to feel ok and confident that the attack has been stopped but then in a week or so some pages might start to get changed or files uploaded." This is what he typed in for me, I don't know anything about all this, I just saw your post, said to him and he told me all this. Hope it helps. Thomas.
__________________
"DarkTom of Glasgow, one of the few uni riders here that you really musn't mess with" - GkMac "mondeos can fly" - Pebbles 24" uni for sale koxx/onza trials uni for sale |
|
|
|
|
|
#19 |
|
Freistiel mit Freibier
Join Date: Jan 2003
Location: Dudenhofen, Germany
Posts: 1,313
|
In Fact "vBulletin" stands for Security, and out of my point of view, I see vB as a save Software. So, I dont know what kind fo custom scripts Gilby adds to this, but maybe there was a SQL-Injection possible. And than, it's no problem to gain administrator access. That is a possible reason and an often used exploit on webthings. So, check every SQL-Statement, be sure that the arguments surrounded by Quotes and addslashes is active either by its function or by magic_quotes_runtime :-).
Ride On, gossi |
|
|
|
|
|
#20 |
|
Tetris Master
Join Date: Mar 2004
Location: Ajax Ontario Canada
Age: 26
Posts: 24
|
thanks gilby
who would go and hack the unicyclist forums? i mean honestly its not like we're out to get anyone or do anything harmful to society. do we have any enemies i dont know about?
__________________
"I drink a whisky drink, I drink a vodka drink, and when I have to pee, I use the kitchen sink" |
|
|
|
|
|
#21 |
|
I got infinite skillz
|
no I don´t think so, but many two wheelers sees us as enemies sometimes
|
|
|
|
|
|
#22 |
|
team YAMS member
|
i dont know if this is the same thing but when I go to this site the resent forum topics are gone. I dont know maby its my comp?
__________________
-fat guy in little coat- TOMMY BOY |
|
|
|
|
|
#23 | |
|
The Godfather of the Clan
Join Date: Nov 2004
Location: Camden, Maine, USA
Age: 23
Posts: 436
|
Quote:
-Lee |
|
|
|
|
|
|
#24 |
|
Unicyclist.com Webmaster
Join Date: Feb 2001
Location: Minnesota, USA
Age: 33
Posts: 4,854
|
The vulnerability was in the script that showed the recent topics.
__________________
Get educated about the legitimacy of government. |
|
|
|
![]() |
| Tags |
| back, control, forum, hacked, unicyclistcom |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|