Hopelessly compromised board?

Get help with installation and running phpBB 3.3.x here. Please do not post bug reports, feature requests, or extension related questions here.
abrogard
Registered User
Posts: 354
Joined: Tue May 24, 2005 8:32 am
Location: australia
Name: arthur brogard

Hopelessly compromised board?

Post by abrogard »

I have a board I could not get into: mblforum.com

so i used the phpMyadmin query to create admin1 and got in that way.

It was immediately strange: asking me for an email address to reset my password. I gave it one that I know exists within the database and belonging to a user and it moved on to a next screen where it told me that board has no forums.

It did have some data comprising review posts about books. Any chance perhaps of finding them and keeping them?
SQLnovice
Registered User
Posts: 177
Joined: Thu Oct 10, 2019 5:03 am

Re: Hopelessly compromised board?

Post by SQLnovice »

Kind of regardless of what has happened, you could restore your site from backup on the host. Most hosts will automatically back up your Web site, database, and files. If it's a complete loss at this point, simply restore from a most recent backup that has some significant size to it. You should then be able to login using your credentials from that point in time. And if so, reset the passwords for all site founders or better still, remove all founders but yourself and go from there.

Probably not a bad idea to establish some form of 2FA/MFA too.
User avatar
warmweer
Jr. Extension Validator
Posts: 12205
Joined: Fri Jul 04, 2003 6:34 am
Location: somewhere in the space-time continuum

Re: Hopelessly compromised board?

Post by warmweer »

abrogard wrote: Thu Feb 06, 2025 4:35 am I have a board I could not get into: mblforum.com

so i used the phpMyadmin query to create admin1 and got in that way.

It was immediately strange: asking me for an email address to reset my password. I gave it one that I know exists within the database and belonging to a user and it moved on to a next screen where it told me that board has no forums.

It did have some data comprising review posts about books. Any chance perhaps of finding them and keeping them?
The emergency founder account (Admin1) allows you to access the ACP, but no permissions are set, hence the screen: this boards has no forums.
First of all, change the password for Admin 1 so that nobody else can access it.

The point of the emergency Admin account is to allow YOU and only you to access the ACP in order to fix your normal Administrator account, e.g. set a new password so that you can login with your original administrator account.

Once that's done: use your original administrator account to delete Admin1.

As mentioned in one of the other topics you started here: check whether there are other founders and remove founder status from those.
Spelling is freeware, which means you can use it for free.
On the other hand, it is not open source, which means you cannot change it or publish it in a modified form.


Time flies like an arrow, but fruit flies like a banana.
User avatar
invenio
Registered User
Posts: 465
Joined: Wed Dec 09, 2015 1:45 pm
Location: New Hampshire, USA

Re: Hopelessly compromised board?

Post by invenio »

If your admin account was compromised and you are missing posts, it could mean that whoever gained access simply deleted those posts as they would have the administrative capabilities to do that.

At the end of the day, if you are now missing any data, you would want to use your backups to restore the board before the loss. Then make sure your admin account has a very strong password so that another compromise would be unlikely. Make sure your hosting account is maximally protected as well and at the end of the day backup, backup, and backup. Having those backups are critically important.
User avatar
thecoalman
Community Team Member
Community Team Member
Posts: 6708
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.

Re: Hopelessly compromised board?

Post by thecoalman »

One way you can end up with missing posts is restoring an incomplete backup or if it times out while restoring a complete backup.

Both are caused by php's max_execution_time being reached. It's common to see this on posts and search table because they are typically largest tables increasing the chance that is where it will occur.

Easy way to see if the file is truncated is open it with text editor, the last insert statement should be for the phpbb_zebra table. If it's truncated there is no recourse, it's only good for partial restoration. If it's complete backup you need to increase max_execution_time in php.ini or use SSH.
SQLnovice wrote: Thu Feb 06, 2025 6:43 am Kind of regardless of what has happened, you could restore your site from backup on the host.
Caution with this, it's not really your backup but their backup for disaster recovery if for example the server is using RAID5 array and loses two disks. They typically only have one and you could end restoring something that is corrupted depending on when the backup was created.
“Results! Why, man, I have gotten a lot of results! I have found several thousand things that won’t work.”

Attributed - Thomas Edison
abrogard
Registered User
Posts: 354
Joined: Tue May 24, 2005 8:32 am
Location: australia
Name: arthur brogard

Re: Hopelessly compromised board?

Post by abrogard »

thanks for this.
Both are caused by php's max_execution_time being reached. It's common to see this on posts and search table because they are typically largest tables increasing the chance that is where it will occur.
I know nothing about that thing.

I currently have no backups. I plan to install a regime. :)

Return to “[3.3.x] Support Forum”