Hacked by Wookie Forum Index

This is an archive of the phpBB 2.0.x support forum. Support for phpBB2 has now ended.
Forum rules
Following phpBB2's EoL, this forum is now archived for reference purposes only.
Please see the following announcement for more information: viewtopic.php?f=14&t=1385785
Locked
User avatar
otseng
Registered User
Posts: 160
Joined: Wed Feb 04, 2004 6:51 pm
Location: Atlanta, GA
Contact:

Hacked by Wookie Forum Index

Post by otseng »

My site got hacked by the "Wookie Forum Index". Anybody have info on how to counter this?

Edit: After looking at my site some more, all the posts also got modified. This guy is malicious.

User avatar
stevemaury
Support Team Member
Support Team Member
Posts: 51191
Joined: Thu Nov 02, 2006 12:21 am
Location: The U.P.
Name: Steve
Contact:

Re: Hacked by Wookie Forum Index

Post by stevemaury »

As you give us no information about what the hack does, what version you are running, nor a link to the forum, it is quite difficult to help you.

EDIT - Is this the forum in your signature? Where does the hack appear?

2d EDIT - I see you have restored a pre-hack backup so no one can now see the code or effects to do much to help. You may want to file a report with http://www.phpbb.com/incidents
For REALLY good and VERY inexpensive hosting CLICK HERE

I can stop all your spam. I can upgrade or update your Board. PM or email me. (Paid support)

User avatar
otseng
Registered User
Posts: 160
Joined: Wed Feb 04, 2004 6:51 pm
Location: Atlanta, GA
Contact:

Re: Hacked by Wookie Forum Index

Post by otseng »

I figured out how the hacker got in.

It is not a problem with the phpbb forum software, but through a mod that I installed. He was able to do some SQL injection to get to my admin account.

I've closed the hole and banned his IP.

User avatar
stevemaury
Support Team Member
Support Team Member
Posts: 51191
Joined: Thu Nov 02, 2006 12:21 am
Location: The U.P.
Name: Steve
Contact:

Re: Hacked by Wookie Forum Index

Post by stevemaury »

Banning his IP will probably not help. Closing the hole will, though.

Were you able to cleanup the database?
For REALLY good and VERY inexpensive hosting CLICK HERE

I can stop all your spam. I can upgrade or update your Board. PM or email me. (Paid support)

User avatar
otseng
Registered User
Posts: 160
Joined: Wed Feb 04, 2004 6:51 pm
Location: Atlanta, GA
Contact:

Re: Hacked by Wookie Forum Index

Post by otseng »

Yeah, it would be easy to use another IP. Can't make it too easy for him to try again though.

And the hole has been closed, sealed, and shut for good. Now we'll see what other hole hackers can find.

I restored the entire database to my last monthly backup. (Thank God the backup worked)

Locked

Return to “2.0.x Support Forum”