vBulletin Modifications

hacked

Welcome to vBHackers.com! - vBHackers Updates:

Go Back   vBulletin Modifications > General vBulletin Section > General vBulletin Support

Reply
 
LinkBack Thread Tools
Old 04-06-2004, 03:34 AM   #1
Charter Member
Join Date: Mar 2004
twoseven is on a distinguished road

Default hacked

alright on sunday my forum database was hacked and destroyed along with the backup that was. now i did manage to get a partial backup but i need some script(mysql or php) to go through the db and delete all the unused user id's and to clean some things out. the db is a wreck that i am using right now but speed was of the essence. any thoughts on help thanks again...
ts




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 04-06-2004, 03:35 AM   #2
Charter Member
Join Date: Mar 2004
twoseven is on a distinguished road

Default

i should say the users are deleted but their id #'s still are in tact not sure what the best course of action is




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-06-2004, 01:15 PM   #3
Join Date: Mar 2004
Real Name: Duh
Location: Cincinnati, Ohio
Ryan Ashbrook is on a distinguished road

Default

First I must advise that you do backups and put them on your computer rather then online.

Second, The only way to clean the user id's is to manually do it. I'm sure someone can right a script to do so but it would need tobe written to fit the number of users you have. I'm not exactly sure on this, I'm not fluent in MySQL.

And third I recommend looking in any sort of log you have and reporting any unusual IP addresses to the IP's host.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-06-2004, 02:10 PM   #4
Charter Member
Join Date: Apr 2004
acid burn is on a distinguished road

Default

you could do some thing like

[sql]
DELETE FROM user WHERE username=""
[/sql]

if they where deleting user names to delete all the rows with no user name.
make a back up of you back up and try out some stuff on that first though




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-07-2004, 02:05 AM   #5
Charter Member
Join Date: Mar 2004
twoseven is on a distinguished road

Default

i already reported the ips to the authorities
the backups are done via a cron'ed script and sent to another host but something must have failed so the backup was incomplete. all i know is what i should have done to ensure that this didnt happen and only can learn from it oh and acid thanks for the suggestion i will look into that query thanks again.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-07-2004, 05:18 AM   #6
Charter Member
Paul's Avatar
Join Date: Mar 2004
Real Name: Paul Dobbins
Location: Beaverton, OR, USA
Paul is an unknown quantity at this point

Default

Unfortunally nothing will happen to those people as theirs no hard evidence




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-07-2004, 07:34 PM   #7
Join Date: Mar 2004
Real Name: Duh
Location: Cincinnati, Ohio
Ryan Ashbrook is on a distinguished road

Default

Quote:
Originally Posted by Paul
Unfortunally nothing will happen to those people as theirs no hard evidence
Not nessicarily, if he has logs and stuff then that's evident enough.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-07-2004, 07:38 PM   #8
Charter Member
Paul's Avatar
Join Date: Mar 2004
Real Name: Paul Dobbins
Location: Beaverton, OR, USA
Paul is an unknown quantity at this point

Default

No its not. Having connection logs of some random ip's connecting is not proof enough that they hacked the server.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 04-08-2004, 02:31 AM   #9
Charter Member
Join Date: Mar 2004
twoseven is on a distinguished road

Default

oh btw one place was traced to ont. the other to a wireless service provider in North Carolina




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -3. The time now is 06:45 PM.

Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc. (Patent Pending)