REGISTER or LOGIN to have the annoying ads removed.
Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
pr3sident@whit3house.gov - Joined made himself an admin
Jun 24, 2009, 01:46 AM (This post was last modified: Jun 24, 2009 01:50 AM by ChristianWebmastersUnion.)
Post: #1
Rolleyes pr3sident@whit3house.gov - Joined made himself an admin
oh joy a hacker!

dude joined ,made himself an admin and did nothing else

how can i avoid this, my mybb version is 1.4.7

*edit i had the old version!* patched it now. is there away to get email updates when a new mybb is released?
Find all posts by this user
Quote this message in a reply
Support Forums
This ad removed for subscribers.
Jun 24, 2009, 02:05 AM (This post was last modified: Jun 24, 2009 02:07 AM by labrocca.)
Post: #2
RE: pr3sident@whit3house.gov - Joined made himself an admin
Same email at my site that hacked me but that's not his real email. He signed up under spamcero.com I believe then using the exploit changed both his email and signup IP address. I was able to pull out mysql logs to see the actual queries.

[Image: mybbsig.php]
Visit this user's website Find all posts by this user
Quote this message in a reply
Jun 24, 2009, 09:43 AM
Post: #3
RE: pr3sident@whit3house.gov - Joined made himself an admin
I need to learn more about this kinda stuff... lol

[Image: NewPeacesig.png]
Peace hath more tests of manhood then battle hath ever known.
Find all posts by this user
Quote this message in a reply
Jun 24, 2009, 10:48 AM
Post: #4
RE: pr3sident@whit3house.gov - Joined made himself an admin
(Jun 24, 2009 02:05 AM)labrocca Wrote:  Same email at my site that hacked me but that's not his real email. He signed up under spamcero.com I believe then using the exploit changed both his email and signup IP address. I was able to pull out mysql logs to see the actual queries.

and to think, you encourage this by having a Forums about Hacking
Find all posts by this user
Quote this message in a reply
Jun 24, 2009, 02:49 PM
Post: #5
RE: pr3sident@whit3house.gov - Joined made himself an admin
lmfao He has a forum about computer shit. You might wanna study the site before criticizing it bro! Labrocca himself doesn't really support the act of hacking at all. The site is more about the skills and such hackers have and scripting and such! Seriously check it out before you knock it. Not to mention if it wasn't for hack forums he may not have ever known as much about hacking as he does now which makes it easier for him to protect himself!

[Image: NewPeacesig.png]
Peace hath more tests of manhood then battle hath ever known.
Find all posts by this user
Quote this message in a reply
Jun 24, 2009, 02:54 PM
Post: #6
RE: pr3sident@whit3house.gov - Joined made himself an admin
(Jun 24, 2009 10:48 AM)ridwan sameer Wrote:  
(Jun 24, 2009 02:05 AM)labrocca Wrote:  Same email at my site that hacked me but that's not his real email. He signed up under spamcero.com I believe then using the exploit changed both his email and signup IP address. I was able to pull out mysql logs to see the actual queries.

and to think, you encourage this by having a Forums about Hacking

You're ignorant if you think that's true. Yes I have a forum about hacking but I don't encourage cracking at all. Maybe you should take the time to read my posts at the site.

And btw...I was one of the first exploited sites from this and because of me this exploit was patched very quickly before most sites could be harmed.

http://blog.mybboard.net/2009/06/15/mybb...ty-update/

Quote:Thank you to Jesse Labrocca for alerting us of this vulnerability.

[Image: mybbsig.php]
Visit this user's website Find all posts by this user
Quote this message in a reply
Support Forums
This ad removed for subscribers.
Jun 24, 2009, 03:39 PM
Post: #7
RE: pr3sident@whit3house.gov - Joined made himself an admin
Yup yup! And for those of us who don't know much about MyBB and security features it's good to have you lookin out! lol

[Image: NewPeacesig.png]
Peace hath more tests of manhood then battle hath ever known.
Find all posts by this user
Quote this message in a reply
Jul 03, 2009, 06:35 AM
Post: #8
RE: pr3sident@whit3house.gov - Joined made himself an admin
I got the same guy on my site... and then replaced the index template to display some message about the Iran election... so i sorted a clean install up to 1.4.8 and they managed to use the same exploit to do it again...

Kaitora Designs. We are soon embarking on plugin work for mybb. Please feel free to contact us if you may have any requests.
Visit this user's website Find all posts by this user
Quote this message in a reply
Jul 03, 2009, 06:47 AM
Post: #9
RE: pr3sident@whit3house.gov - Joined made himself an admin
Did you delete themes.php from ./cache/themes/?? Shouldn't be there, that's the backdoor they leave.

MyBB Support Team Lead
Visit this user's website Find all posts by this user
Quote this message in a reply
Jul 03, 2009, 10:28 AM
Post: #10
RE: pr3sident@whit3house.gov - Joined made himself an admin
(Jul 03, 2009 06:35 AM)kaitora Wrote:  I got the same guy on my site... and then replaced the index template to display some message about the Iran election... so i sorted a clean install up to 1.4.8 and they managed to use the same exploit to do it again...

By clean install did you delete all the files and re upload and start with a fresh database and restored it with a back up ?

Or did you just re upload and overwrite the existing files excluding your config file. Like Matt mentioned did you delete that theme.php file ?

Please let us know because now I am starting to worry and another thing is to I wonder if the hacker has read the config file and knows your database name and password. It would not hurt to change the password and user name for the database.
Find all posts by this user
Quote this message in a reply
Post Reply 


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Can't login to admin panel =\ 88power88 11 232 Jun 18, 2010 12:08 PM
Last Post: zahnzi
  Admin .htaccess x:Biohazard:x 1 125 May 16, 2010 11:03 PM
Last Post: MyBB™
  How can i change my admin password? Pk3r_Pjer 2 155 Apr 23, 2010 11:37 AM
Last Post: Pk3r_Pjer
  Admin statistics plugin Snooopy` 0 130 Apr 08, 2010 05:28 PM
Last Post: Snooopy`
  [HELP] Edit & Delete Button Gone For Admin & Mods? virus_c 22 823 Apr 06, 2010 01:41 AM
Last Post: MasterZuFu

Forum Jump:

Web Hosting


icon buffet