Hackers

haha reminded me when some moron tryed to hack my forum xP
one of my staff members edited all his posts to "I am an idiot"
rofl xD
everyone kept on replying "yes u are" hehe
eventually he couldn't take the pressure and just left :lol:


Anyways I don't believe in the ability of others hacking you
as long as that u've got a long enough pass with letters and numbers... a different email then the one you created your forum with and u don't use your pass for any other site... you should be fine :great:
 
You should be unless you get Gumblar which auto hacks your forum! Watch out for this - incase you have not seen it in my other post:

http://www.phpbb.com/blog/2009/05/22/de ... nd-martuz/

Very malicious - be careful - make sure your anti virus is up to date as this got me last week. No idea where it came from as I only visit the usual sites.
 
karkooshy said:
as long as that u've got a long enough pass with letters and numbers... a different email then the one you created your forum with and u don't use your pass for any other site... you should be fine :great:
If you have any basic knowledge of hacking, you would know that passhacking is often quite slow, especially on softwares that salt passwords. Thus, only a dictionary attack would work to get the password. A much easier way is to find exploits in the code.
 
Kirisute Gomen said:
If you have any basic knowledge of hacking, you would know that passhacking is often quite slow, especially on softwares that salt passwords. Thus, only a dictionary attack would work to get the password. A much easier way is to find exploits in the code.
If you're doing a brute force on a site to get an account's password, being salted or not doesn't have any effect. That only works if you have the salted hash, which takes even rainbow tables awhile to get 😉

Most software has a timeout for accounts. If you guess wrong 5 times, you must wait a set period of time before trying again. That disables brute force attacks completely.
 
ℓєσ gнσѕт said:
Kirisute Gomen said:
If you have any basic knowledge of hacking, you would know that passhacking is often quite slow, especially on softwares that salt passwords. Thus, only a dictionary attack would work to get the password. A much easier way is to find exploits in the code.
If you're doing a brute force on a site to get an account's password, being salted or not doesn't have any effect. That only works if you have the salted hash, which takes even rainbow tables awhile to get 😉
I was referring to if you have the password from a forum software (ex. you have the DB from BH and you wanted to hack DMB) and you were trying to figure out the password using a program of some sort. I tried to see if a program could recover my password on a backup of my first SMF forum, and it took days to even get 1.0% through (SMF is salted MD5).
 
@Kirisute Gomen
That's the method where you have the salted hash 😛

It can still be cracked, but would take days even with using a custom rainbow table. Pointless on a grand scale but if you have a reason it may be worth it.

Honestly social hacking is the easiest way for some 😛
 
o.o Thought I'd join in the convo. 😉

There are a small group of hackers that are of a young age, mostly 13 to 16 that think it's cool to hack forums and to deface sites. To all the real hackers out there they are called skids, these skids arn't hackers but people who use pre-made tools and methods of hacking and deface stuff to say they are hackers.
The real hackers out there, who make, develop and find new methods of hacking, creating tools and find holes laugh at these skids because they know the fail they truly are.
Most people do it because it's against the law to do so and makes them feel big, other people do it because they are addicted. Once you learn to hack things you get this urge to go and hack things, I did it on my own sites and stuff, people do it on forums and sites that are just found to be vulnerable.
Some people also hack things for money if their on the light side of the coin and need a quick way to make some money, people pay about $50 - $100 for a basic forum running php3 with a 70 man member base.

There are just so many different reasons the only way to find out is to ask the hacker himself as each one has a different reason. 🙂

@ Leo and Kirisute Gomen.
It is actually much easier to find holes in the coding of the software, you can easily purchase a known error for a software on the black market to brute forcing a site. BFing isn't used that much in the hacking world due to really crappy forcers and the lack of patience to hacking it. Hacking a site via brute forcing will depend on the word list you use and the password itself. There are huge password lists out there that do contain every possible work combo known to man to a good 8 mill character length, a while back the police's word list that they spent like 10 years making was leeched so is possible to force any password but with no good program to do this it's kind of useless. the limit of the amount of tries you use is crap, if the program loads with a different IP every 4 times the 5 limit won't pick it up, it will just take longer, and there is no suck brute forcer out there >.>
 
heh, luckily if my forum gets hacked I can have it restored in a few hours.

but yeah, hackers do it for fun and test their skills.
 
skeithex said:
heh, luckily if my forum gets hacked I can have it restored in a few hours.

but yeah, hackers do it for fun and test their skills.


Orly? Please share with us your masterful knowledge of how to do this when you can't access anything?
 
Danielw879 said:
skeithex said:
heh, luckily if my forum gets hacked I can have it restored in a few hours.

but yeah, hackers do it for fun and test their skills.


Orly? Please share with us your masterful knowledge of how to do this when you can't access anything?
It depends how it was hacked. If your cPanel/FTP is online then you can re-upload your last backup,. assuming you have one.
 
Danielw879 said:
skeithex said:
heh, luckily if my forum gets hacked I can have it restored in a few hours.

but yeah, hackers do it for fun and test their skills.


Orly? Please share with us your masterful knowledge of how to do this when you can't access anything?
1. Email support team
2. Get password changed
3. Remove malicious code

I know, I'm a genius.
:cheer:
 
Assuming you backed up everything, just re-upload the files and the DB.
 
Someone tried to hack my forum. T_T caught them just in time. saved me alot of pain. but now I'm on high alert. I hate hackers!!!!!!!!!!!!!!!!!!!!
 
yes! he hacked into my testing account then was stupid and emailed me after I deleted it. asking what happened to your testing account. We haven't deleted his account yet. my staff banded him. i don't know what to do.

and everyone gets a bad vide from him.

🙁
 
lol, Did he act any more suspicious. "What happened to the test account, is it alright, did it have a heart attack or something?" lol
 
I deleted it as soon as i saw it was online and the guy changed the password. For days now he was asking to be mod. we don't trust him.
 
For days now he was asking to be mod.
If someone asks me to become a mod more than twice in a month then I'd ban them or restrict their PMs. There is no excuse for begging.
 
Back
Top Bottom