Essential Clix
Supreme Member
- Jul 30, 2007
- 1,407
- 3,165
Yes, we've been discussing SMF for a short while now. We were hoping that just switching to a barebones vBulletin (no mods installed) would be enough. Apparently not.
why many other very popular boards using vbulletin never get hacked before?
how come the forum software has not been changed yet?
I am investing some money in software firewall and also another service which costs $600 a year to protect the site from further attacks.
because they are not of value
BHW is a society of brilliant minds
The forum itself is powerful blackbook
We are being hacked for the very same concept you will read on history books
I spoke with one of the guys formally with thelevel, and he says they used a 0day vbulletin hack he wrote without his permission. It was a hack for vbulletin itself, not a mod. More complicated than I originally gave these guys credit for.As far as I'm aware vbulletin out of the box is extremely robust and notoriously difficult to hack. So I'm not entirely sure its the forum software to blame either. Especially since most if not all of the addons have been taken off.
Oh yeah ..and we all smile when the investigators will find our gold mind full with cracked and nulled softwareI think legal means is the only way to go. Look at the various rules and regulations from your ISP to your host have. What they are doing is very criminal and the owner should be handled by legal means as well as the hackers.
If you know the IP number, then could you ban it via htaccess?
That's how I keep hackers off my site...
tsp
What are the passwords like in VB? MD5? If these are MD5 then all you need is a big ass dictionary and a bit of time. Most password will be easily b-forced. Not good, not good at all.
I think legal means is the only way to go. Look at the various rules and regulations from your ISP to your host have. What they are doing is very criminal and the owner should be handled by legal means as well as the hackers.
vBulletin uses salt? I didn't know that. That changes things considerably.vBulletin uses passwords through MD5 and salt.
$hash=MD5(MD5($password)+$salt)