ACP 403 - possibly hacked

Get help with installation and running phpBB 3.3.x here. Please do not post bug reports, feature requests, or extension related questions here.
macron
Registered User
Posts: 6
Joined: Sun Dec 06, 2020 9:20 am

ACP 403 - possibly hacked

Post by macron »

A new user registered from Russia, despite the StopForumSpam filter. I get these alot and delete them asap. When I logged in to do that in and go to the ACP, I now get a 403. I do have access to the database. I have a backup admin user as well. That one also gets a 403 logging in to the ACP.
Does anyone know why I get the 403 and how to restore access?
User avatar
KevC
Support Team Member
Support Team Member
Posts: 72539
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK

Re: ACP 403 - possibly hacked

Post by KevC »

More likely is your hosts have changed something and your admin link is blocked. Ask them first.
-:|:- Support Request Template -:|:-
Image
"Step up to red alert. Sir, are you absolutely sure? It does mean changing the bulb"
macron
Registered User
Posts: 6
Joined: Sun Dec 06, 2020 9:20 am

Re: ACP 403 - possibly hacked

Post by macron »

Having Russians creating a lot of accounts has me a bit in panic mode, no matter how well I try to filter and block them.

For anyone else having this issue:
Just checked the errorlog on my hosting provider and I came across this:
mod_security rule [id "77140992"] at [/etc/modsecurity.d/013_i360_1_infectors.conf:594] triggered!
I checked my website admin panel under Security and disabled the SecRuleEngine. Now I can log in to ACP again. I've notified the host. Hopefully they can fix this.

Thanks.
SuiSSaS
Registered User
Posts: 6
Joined: Sun Jun 18, 2006 2:18 pm

Re: ACP 403 - possibly hacked

Post by SuiSSaS »

I have a similar issue after registering a Russian user.
Now when I try to enter ACP I just get a "Not acceptable" message.
The entire forum works normally, I just don't have access to ACP.

Any solution?
User avatar
KevC
Support Team Member
Support Team Member
Posts: 72539
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK

Re: ACP 403 - possibly hacked

Post by KevC »

You need to ask your hosts. It's likely mod_security on their server has blocked something.
-:|:- Support Request Template -:|:-
Image
"Step up to red alert. Sir, are you absolutely sure? It does mean changing the bulb"

Return to “[3.3.x] Support Forum”