REGISTER or LOGIN to have the annoying ads removed.
Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
pr3sident@whit3house.gov - Joined made himself an admin
Jul 06, 2009, 04:14 PM
Post: #21
RE: pr3sident@whit3house.gov - Joined made himself an admin
haha, awesome. Can't wait when it comes out Big Grin

Visit this user's website Find all posts by this user
Quote this message in a reply

This ad removed for subscribers.
Jul 07, 2009, 07:59 AM
Post: #22
RE: pr3sident@whit3house.gov - Joined made himself an admin
Same advice as everybody else has been given, once you've deleted the admin account, make sure there's no files that shouldn't be there in your ./cache/themes/ folder, and I'd also reupload all the files from the 1.4.8 package.

Click here to download ALL MyBB Central plugins!!
Visit this user's website Find all posts by this user
Quote this message in a reply
Jul 07, 2009, 12:37 PM (This post was last modified: Jul 07, 2009 12:38 PM by MattR.)
Post: #23
RE: pr3sident@whit3house.gov - Joined made himself an admin
If it deletes stuff, your FTP client is setup wrong. It only adds files and updates/replaces ones, it shouldn't delete anything.

If I have 50 files in my ./inc/plugins/ folder, and upload the default MyBB package on top of it, which only includes the hello.php, it won't delete anything else in the folder.

Click here to download ALL MyBB Central plugins!!
Visit this user's website Find all posts by this user
Quote this message in a reply
Jul 07, 2009, 01:29 PM
Post: #24
RE: pr3sident@whit3house.gov - Joined made himself an admin
A better question is why you haven't updated in 3 weeks to fix the exploit. WTF

[Image: mybbsig.php]
Visit this user's website Find all posts by this user
Quote this message in a reply
Jul 07, 2009, 06:16 PM
Post: #25
RE: pr3sident@whit3house.gov - Joined made himself an admin
Ok. here are some simple steps for you to follow:

1. GET ON THE MAILING LIST!!!! I made the same mistake as you by not checking my updates simply because I assumed someone else would do the job. You should get on the mybb mailing list so that when a new version of mybb comes out you'll know by email to update all of your mybb forums. GET ON THIS LIST NOW!!!

http://www.mybboard.net/mailing-list

2. Check your administrator logs and look what that user account did while in admin (AdminCP -> Tools And Maintanence -> Administrator Log) and look what he did and undo it. Most likely, if it's this hacker, he most likely only changed the index page and uploaded a backdoor in the cache directory. It's been mentioned in this thread before, delete it ASAP.

3. Follow the guidelines in this thread to improve your website's security:

http://community.mybboard.net/thread-44977.html

4. DON'T LET THIS GO UN-REPORTED!!! A common mistake people do is they DON'T report incidents like this, which, unfortunately, allows malicious hackers to remain anonymous on the web with very little information, if any at all, about them. This particular hacker I have setup a blog again, you may visit it here: http://www.psinetic.org/nobodycoder

Be sure you report any hacking incidents to the correct people as soon as they happen and include all the details you can, this is what helps with security updates to protect you and others like you from having the same attack again.

5. Use your brain, learn how your forum and site operates and what should be locked up and what shouldn't. If you don't know how your beast behaves, how are you supposed to operate it?

6. Like Labrocca said so eliquently (lmao XD), UPDATE!!!!! http://www.mybboard.net/download/latest

that should help you out.

-Psinetic

Visit this user's website Find all posts by this user
Quote this message in a reply
Jul 08, 2009, 04:45 AM (This post was last modified: Jul 08, 2009 04:46 AM by MattR.)
Post: #26
RE: pr3sident@whit3house.gov - Joined made himself an admin
(Jul 07, 2009 02:43 PM)RPG2 Wrote:  Becuase I didn't check there was an update.

If it's been 3 weeks, the version check in your ACP would have come up, it comes up every 2 weeks... don't say you ignore that when it comes up...

Click here to download ALL MyBB Central plugins!!
Visit this user's website Find all posts by this user
Quote this message in a reply

This ad removed for subscribers.
Post Reply 


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Super Admin password Magnum 8 305 Feb 24, 2010 01:12 PM
Last Post: MattR
  After post users are made guest NzB 0 103 Jan 08, 2010 12:08 PM
Last Post: NzB
  I sometime got prompt on my admin dashboard itsmie 1 190 Nov 09, 2009 01:34 PM
Last Post: itsmie
  Can't change language in admin area komunitasblackberry 1 260 Oct 28, 2009 03:41 AM
Last Post: MattR
  Admin dir rename... s9TeeN 5 231 Oct 26, 2009 12:28 AM
Last Post: s9TeeN

Forum Jump:



icon buffet