3rd time is a charm?

I second the idea for going with Invision. I have had experience with a hacked forum and migrated to IPB. If I am not mistaken, the cost is about the same as vBulletin. The IPB people were great to me and their customer support is responsive. Not perfect, but very, very good. (I gain nothing from that endorsement. Just giving advice from my own experience.)

Also, I would like to offer a humble suggestion on the psychological level. Hackers who are hell-bent on destroying what others build are lonely, insecure, full of self-esteem issues and have a driving need to prove their own efficacy to themselves. They have a hole inside them that tells them they are worthless and they can never get it filled.

All this adds up to vanity. They are very vain people with a chip on their shoulder and have some tools of destruction available.

So there is nothing really to be gained by getting into a public pissing match about whose schlong is longer with these guys. They are disconnected from reality and imagine that damaging the work of others from an anonymous position because they learned a little code makes them all-powerful. And they cannot escape the fact that they have no audience and will never have one under their own merits. Nobody wants their bullshit. They are big nobodies. That ain't just me saying it, either. That's just the way it is. That makes them dangerous.

So I suggest staying away from the public pissing contests. I am definitely not saying be afraid of the hackers. The people on this forum are more than competent to hold their own against any hacker attack, but why bother? There is a clear division between being afraid and being cautious with a volatile element.

There is no sense in petting a rattle-snake, then smacking it upside the head and pulling back quickly just to show you can do it. Nobody gains anything. Ever. If the rattlesnake is halfway good or you are on an off day, you get bit. That's not even good entertainment.

I think it is better just to let the snake slither on off and go elsewhere. I don't see a way to kill it on the Internet. (Also, I don't think law enforcement is going to be too concerned given the nature of this forum.)
 
To all the admins/mods/ and just about everyone,

You guys are doing a great job to get things back in a good state. Do whatever it takes to make things more secure, like switching to a new forum, etc. Then as snowwhite suggested, make all threads private just in case. It may not do much but at least it deters people away from our forum and keeps us off the SERPs cause there is way too much sensitive and valuable info here that is not meant for prying eyes. Once again, thanks for all the good work and effort that is put in.
 
I'm just glad the board is back up :) I'm not so happy about having to change my passwords though :( I've used the same ones for years. Ahhh well. Onwards and upwards.
 
new post from that topic i posted from thel3vel.

well they black hat is goin down soon apperently so ill wait till a later time

interesting hopefully this doesn't happen again.
 
Had to re-register. Lost a few pms :(

vBulletin uses salt? I didn't know that. That changes things considerably.
Not really. They have the salt. They just can't use regular rainbow tables. They still have the dictionary attack, mask attack, bruteforce, etc etc.
 
Last edited:
I don't think SMF is any more secure than VBulletin. VBulletin is constantly patched and updated. I bet if you could get the hack to them they'll have a patch out in a couple of days. Of course the problem is getting the hack. If you want to switch to IPB I'm willing to do an even exchange. :D I'm dying to get rid of my IPB license (I hate the admin panel).
 
I think we all should chip in some money to make blackhat world more secure instead of just talking about making it secure. We can see lets do this or that all we wan't but the bottom line Dave's already spending a lot of money and if we want to make changes I'm sure helping out by paying for those changes needs to be our first step
 
new post from that topic i posted from thel3vel.


interesting hopefully this doesn't happen again.

good info but keep in mind I'm sure they know we can read their forums too, so take everything you read there with a grain of salt.
 
sometimes the unexplained is just unexplainable.Talent is sometimes hidden.Look back and ask,did I make someone mad,or were they already mad.
Lots of us are in school.Don't underestimate the well schooled.The Internet is a vast Ocean.Beware,my friends,don't make US angry.Be cool.Or we Will Be Back.
The Dark Child:cool:
um wow ok........
 
sometimes the unexplained is just unexplainable.Talent is sometimes hidden.Look back and ask,did I make someone mad,or were they already mad.
Lots of us are in school.Don't underestimate the well schooled.The Internet is a vast Ocean.Beware,my friends,don't make US angry.Be cool.Or we Will Be Back.
The Dark Child:cool:

sigh............why are you angry again ? ive asked this 100 times what your point is exactly but nobody answers me...I dont know you , your group, or care anything about you......and nobody else does either. can you just let us get back to making money now?
 
VB forum is the most easily hackable forum on the planet. See any arab forum and there's software that you simply input the VB site, and few other variables that are easily grabbable, and it returns you the VB's MYSQL database/password info.

Suggestion to admin: Zend/IonCube the file that stores MySQL connection info.

OR

Convert the weakling/joker VB forum to SMF (simplemachines.org). SMF has a auto VB-to-SMF converter. You'll never get a SMF hacked.
 
Well since they had a shell on, they had access to the index file so that means they had access to the vbulletin server files....they could have easily put a "logger" on the login.php so that every time somone logs in it makes the username and pass e-mail them...it's very easy really. I propose backing up the database and attachments then installing smf and converting the database with attachments on a new server just in case if they had root on this one.
 
Well since they had a shell on, they had access to the index file so that means they had access to the vbulletin server files....they could have easily put a "logger" on the login.php so that every time somone logs in it makes the username and pass e-mail them...it's very easy really. I propose backing up the database and attachments then installing smf and converting the database with attachments on a new server just in case if they had root on this one.

don't know you need a new server just i would suggest.

1.) converting vbulletin to smf
2.) backup the fresh smf and converted smf db
3.) reinstall server os
4.) reupload smf and smf db
5.) now were clean.
 
Bingo, but they HAVE to make sure to do a clean format and reinstall the os becuz if they don't and even tho they would have smf...if thel3vel had root there is not stopping them then. But I would suggest going to a new server and just iporting db + attachments
 
Bingo, but they HAVE to make sure to do a clean format and reinstall the os becuz if they don't and even tho they would have smf...if thel3vel had root there is not stopping them then. But I would suggest going to a new server and just iporting db + attachments

agreed, but i think there is something we will both agree on. no matter what happens there needs to be a clean reformat with clean OS reinstall and fresh board software with new admin and root passwords.
 
This is a quick post being made on behalf of the admin.

FirewallScript has been installed.
All users passwords are NOT loose in the wild and there is no particular reason to change passwords for other sites you use. Vbulletin utilizes a salt which is over 4 charachters, so unless your password was 3 charachters or less there is no chance it could be decrypted to plain text.

All future attacks should be stopped now.

Dan - Http://www.firewallscript.com
 
This is a quick post being made on behalf of the admin.

FirewallScript has been installed.
All users passwords are NOT loose in the wild and there is no particular reason to change passwords for other sites you use. Vbulletin utilizes a salt which is over 4 charachters, so unless your password was 3 charachters or less there is no chance it could be decrypted to plain text.

All future attacks should be stopped now.

Dan - Http://www.firewallscript.com

thanks for the info, and a pat on the back goes to diamond dave.
 
Yes BUT if they had or still have a logger on login.php then your screwed. In that case they wouldn't need the DB. Just make an announcement to the members (just to be safe)to change there passwords. Becuase it is most likely they put up a logger. I know how they think...
 
Yes BUT if they had or still have a logger on login.php then your screwed. In that case they wouldn't need the DB. Just make an announcement to the members (just to be safe)to change there passwords. Becuase it is most likely they put up a logger. I know how they think...

yea but if they did a fresh install of vb before they reconnected the db thats all fresh files and no key logger in login.php .
 
Back
Top