I can't stop this hacker ??

Get help with installation and running phpBB 3.0.x here. Please do not post bug reports, feature requests, or MOD-related questions here.
Suggested Hosts
Forum rules
END OF SUPPORT: 1 January 2017 (announcement)
Locked
GiffHost
Registered User
Posts: 230
Joined: Wed Jan 25, 2012 10:03 pm

I can't stop this hacker ??

Post by GiffHost »

Hello,

Someone with a ip of "217.114.61.34" keeps hacking my board. He goes in the ADM and changes stuff. He shows as a random admin account, mine has been used so i know it is not my friend. He changes alot of stuff, then CLEARS the admin log so its really hard to know what he/she/IT done.

Any advice ? I am sick of banned users, mass emails sent, clearing logs, deleting posts.


Thanks
User avatar
KevC
Support Team Member
Support Team Member
Posts: 70438
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK
Contact:

Re: I can't stop this hacker ??

Post by KevC »

That IP belongs to Lancaster University.

What exactly are they doing? If the logs are cleared how do you know they're in there? What are you seeing?
-:|:- Support Request Template -:|:-
Image
Cheap UK Hosting
"In the land of the blind the little green bloke with no pupils is king - init!"
GiffHost
Registered User
Posts: 230
Joined: Wed Jan 25, 2012 10:03 pm

Re: I can't stop this hacker ??

Post by GiffHost »

Kevin Clark wrote:That IP belongs to Lancaster University.

What exactly are they doing? If the logs are cleared how do you know they're in there? What are you seeing?

DAY 1: Sent a mass email (Totaly spam) , Deleted 4 users, Changed the admin users passwords. Cleared logs.

Day 2: Sent mass email (It was like "This board is closing please move to this board xxx.xxx) , Changed admin passwords. Cleared Logs.

Also once i was in the ACP while that IP was in, and seen what he changed then he clears log.

Thanks
User avatar
KevC
Support Team Member
Support Team Member
Posts: 70438
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK
Contact:

Re: I can't stop this hacker ??

Post by KevC »

Go to whois.sc, enter that IP and report it to their abuse email address.

Tell all your admins to change their passwords.

Check you haven't accidentally given the registered users group some admin permissions.
-:|:- Support Request Template -:|:-
Image
Cheap UK Hosting
"In the land of the blind the little green bloke with no pupils is king - init!"
GiffHost
Registered User
Posts: 230
Joined: Wed Jan 25, 2012 10:03 pm

Re: I can't stop this hacker ??

Post by GiffHost »

Thanks. That ip has never been on the forum as a user. I made all admins change password. But still happebs
User avatar
Brf
Support Team Member
Support Team Member
Posts: 52305
Joined: Tue May 10, 2005 7:47 pm
Location: {postrow.POSTER_FROM}
Contact:

Re: I can't stop this hacker ??

Post by Brf »

They would have to be a user.
An unregistered guest would not be able to use the Admin control panel.
CaNNon_
Registered User
Posts: 392
Joined: Wed Apr 29, 2009 2:07 am

Re: I can't stop this hacker ??

Post by CaNNon_ »

I'd check your .htaccess files just to make sure they are in place and functioning.
image45
Registered User
Posts: 168
Joined: Wed Feb 24, 2010 6:05 pm
Name: Robert

Re: I can't stop this hacker ??

Post by image45 »

Do you have a wordpress blog or other such on the same domain name path that has allowed an exploit to be used?

There are a few hacker scripts that can be uploaded onto the servers file system, allowing all sort of anonymous actions to be used.
Pony99CA
Registered User
Posts: 4783
Joined: Thu Sep 30, 2004 3:13 pm
Location: Hollister, CA
Name: Steve
Contact:

Re: I can't stop this hacker ??

Post by Pony99CA »

Kevin Clark wrote:If the logs are cleared how do you know they're in there?
When you clear the logs, a Cleared Log entry is made in the log. You'll always have at least one of those no matter what else you clear (unless the user has database access, of course).

Steve
Silicon Valley Pocket PC (http://www.svpocketpc.com)
Creator of manage_bots and spoof_user (ask me)
Need hosting for a small forum with full cPanel & MySQL access? Contact me or PM me.
Locked

Return to “[3.0.x] Support Forum”