3rd time is a charm?

Yes, we've been discussing SMF for a short while now. We were hoping that just switching to a barebones vBulletin (no mods installed) would be enough. Apparently not.
 
why many other very popular boards using vbulletin never get hacked before?

because they are not of value
BHW is a society of brilliant minds
The forum itself is powerful blackbook
We are being hacked for the very same concept you will read on history books
 
As far as I'm aware vbulletin out of the box is extremely robust and notoriously difficult to hack. So I'm not entirely sure its the forum software to blame either. Especially since most if not all of the addons have been taken off.
 
I am investing some money in software firewall and also another service which costs $600 a year to protect the site from further attacks.

now I see why you are dabbling with the paid membership idea.
 
because they are not of value
BHW is a society of brilliant minds
The forum itself is powerful blackbook
We are being hacked for the very same concept you will read on history books

Couldn't agree more ..
 
Thank you for that post diamond dave i totally understand the only reason i made this topic was to find out whats happening and how to get things secure! so that this great community can keep thriving off of all the members and info we all share.

either way i still believe we should switch the board software to smf. (as i hear that is the most secure board software as of now.) there are database converters out there to make the switch quite a bit more simple.

thank you again,
 
As far as I'm aware vbulletin out of the box is extremely robust and notoriously difficult to hack. So I'm not entirely sure its the forum software to blame either. Especially since most if not all of the addons have been taken off.
I spoke with one of the guys formally with thelevel, and he says they used a 0day vbulletin hack he wrote without his permission. It was a hack for vbulletin itself, not a mod. More complicated than I originally gave these guys credit for.
 
I think legal means is the only way to go. Look at the various rules and regulations from your ISP to your host have. What they are doing is very criminal and the owner should be handled by legal means as well as the hackers.
 
First of all I ask you to remain calm .. the vbulletin database use MD5 encoded passwords ..so they do not have your passwords .. they have the email , ip and other unimportant infos.. We are black haters and we do not reveal our personal infos right?!

Secondly ..It seems the gay thing pissed them off so they decided to sell the DB .. I understand you guys are mad .. but this is the way this game is played ... You fuck up someone ..you should stay str8 ... as revenge is a powerful resource .. love and revenge can bring up powers you didn't thought you have

Thirdly ..... Shouldn't we pay a server specialist (freelancer) to format the hard drive , install fresh software and latest patches ?! I see big communities way bigger than BHW that are ok ..and I'm sure they get attacked more often than us...
So let's take it as a growing pain ,learn our lesson and move on ..

And as my DDOS hoster advices me ... If you get attacked never piss of the attacker just install better protection :D
 
I think legal means is the only way to go. Look at the various rules and regulations from your ISP to your host have. What they are doing is very criminal and the owner should be handled by legal means as well as the hackers.
Oh yeah ..and we all smile when the investigators will find our gold mind full with cracked and nulled software ;) Smart move
 
If you know the IP number, then could you ban it via htaccess?
That's how I keep hackers off my site...

tsp
 
If you know the IP number, then could you ban it via htaccess?
That's how I keep hackers off my site...

tsp


yea anyone can ban an ip but an ip is just an ip as we all know they can be masked and even changed.
 
I'm sure the IP is just a proxy of sorts, they probably port hopped a dozen times before attacking the server.
 
What are the passwords like in VB? MD5? If these are MD5 then all you need is a big ass dictionary and a bit of time. Most password will be easily b-forced. Not good, not good at all.
 
What are the passwords like in VB? MD5? If these are MD5 then all you need is a big ass dictionary and a bit of time. Most password will be easily b-forced. Not good, not good at all.

vBulletin uses passwords through MD5 and salt.

$hash=MD5(MD5($password)+$salt)
 
Actually, you can use rainbow tables on md5 passwords like that. I'm sure you could decrypt them all in no time. In fact, I'm almost 100% sure they already have.

Again I restate, change your email and paypal passwords -- if its the same password you use to log in to BHW.
 
I think legal means is the only way to go. Look at the various rules and regulations from your ISP to your host have. What they are doing is very criminal and the owner should be handled by legal means as well as the hackers.

I agree with you but from the posts I've read I don't know how much effort they are willing to put into taking legal action (they meaning the host not BHW admin). They seem to offer limited support hours and take their time when it comes to reviving the site after an attack.
 
Back
Top