corbra
|
Wilshizer LTD.PLEASE ENTER THE FOLLOWING>>>>
Enter your myff forum url here (or link to your specific problem) : http://wilshizerworks.myfreeforum.org
Please indicate keywords you have searched on:
Now ask your question in clear English without "txt" speak>>>>
A Tesuser, which is an admin, has been goten into, and has delted all accounts that are not founders, this is my freinds forum, but im still a founder, and i found this out in the ACP. This also happened yesterday, so we did a ip range ban, but they got back on.
Please help
Thanks
Corbra
|
admin (no pm's please)
|
They must have an admin account for which they know the password.
|
corbra
|
we changed the password, and only one person new it, and that was the person that made it
|
wilshizer
|
I am the admin of the forumhi i am the admin and i dont know how he did it but he removed my admin premmisions yesterday and now the accounts after i changed the passwords on the forum
|
admin (no pm's please)
|
As I say either he must know an admin password, or the control panel password.
Use the admin panel user search to look for admin accounts!
|
admin (no pm's please)
|
The daily log shows "blipblipblur" as the admin.
|
corbra
|
yh, we know he is an admin.
wilshizer delted the tesuser.
also, i know how to run a my free forum, i have my own.
also on PHPBB3
|
wilshizer
|
infowe just want to know if there is a way to recover the users that have been deleted
|
admin (no pm's please)
|
| corbra wrote: | yh, we know he is an admin.
wilshizer delted the tesuser.
also, i know how to run a my free forum, i have my own.
also on PHPBB3 |
Then you will know the only way in is via a password.
|
wilshizer
|
passwordsall the passwords have been changed
|
admin (no pm's please)
|
We can go round in circles like that forever.
The only way in is an admin/control panel password or I suppose the lost password routine if someone has access to your email, or someone with access to your PC if it stores passwords.
Deny it is any of the above and that you have not missed something and your forum will continue to have problems.
|
wilshizer
|
2 auestions1 is there a way to recover the user accounts that were deleted
2 is there a programme he could have used
|
admin (no pm's please)
|
You can pay $10 for a forum restore.
There is no way in apart from a password, repeated tries gets the account locked. So no program can be used.
|
wilshizer
|
hiok thanks for the help
wilshizer
|
admin (no pm's please)
|
But have you figured it out?
It is not good to just leave the issue hanging. Much better for all of us if the attack vector is explained. It may be a bit embarrassing to explain what happened but it does help everyone.
|
blipblipblur
|
well i hate to be the one who says it but there was a fallout between wilshizer and corbra at one point, its quite possible for there to have been a leek of information back then in the spite of anger.
seems to be one of the only explanations.
|
admin (no pm's please)
|
Well I can't comment on exactly what happened, but you have to consider the order of probabilities.
e.g.
1) Is it likely our forums are vulnerable, but only your forum out of the 30,000 odd on myff and the hundreds of thousands of other phpbb forums in the world is hit?
2) Someone you trusted is a rogue?
3) Someone guessed your password on forum or email account?
It is clearly obvious that if myff/phpbb had the vulnerability then forums would be being hit by the hundreds and thousands. If it happened we could not (and would not) deny it.
|
corbra
|
well this is the log
Test user2 90.192.88.122 Sat Nov 22, 2008 1:00 pm Deleted user
» test user
Test user2 90.192.88.122 Sat Nov 22, 2008 12:59 pm Deleted user
» skategurlx
Test user2 90.192.88.122 Sat Nov 22, 2008 12:58 pm Deleted user
» PyRoZz<3sGEARS
Test user2 90.192.88.122 Sat Nov 22, 2008 12:58 pm Deleted user
» jenzo
Test user2 90.192.88.122 Sat Nov 22, 2008 12:57 pm Deleted user
» berandombecrazy
Test user2 90.192.88.122 Sat Nov 22, 2008 12:56 pm Deleted user
» semplew
but Test User2 got delted
and i got my freind( dunno if he still is) to join a new forum i made and it came bck as the same ip address, his ip changes too much, we did a Ip range ban, and this is about 1 week after that, its change way differently then before.
|
|
|