somebody hacked my forum?

Fowler said:
I have seen MyBB forums also. I am 99.9% sure we know who is behind it. It was a member here who was banned for this kind of behaviour. It is also the same user who set up a fake login page of this site to try and steal users logins a few weeks back. I am pretty sure all these attacks are linked to him gaining access to a site recording users login details and trying them on other sites. Once he gets in, he can then upload what he wants.
Is it possible to out this crook? I think it's only fair we know who this is so we can ban/block them from our sites. If not, could you PM me your thoughts?
 
Oliver.. Goes by many alias's, mostly immature names though.

He's barely a hacker.. and constantly makes me laugh.
 
Nathan said:
Oliver.. Goes by many alias's, mostly immature names though.

He's barely a hacker.. and constantly makes me laugh.
I don't know an Oliver :S the only person I remember doing any hacking really was 'P U R P' or 'xPurp412' I think he went by at one stage.
 
Oliver was before your time Jamie, he crops up now and then. A nasty piece of work that has caused lots of trouble at FP. I don't think it was him this time though, although I will let fowler decide whether he wants to give names or not as I was given the name by someone else..
 
Tindris said:
Oliver was before your time Jamie, he crops up now and then. A nasty piece of work that has caused lots of trouble at FP. I don't think it was him this time though, although I will let fowler decide whether he wants to give names or not as I was given the name by someone else..
Ah, I see. Well whoever it is is just childish, and it's really unfair taking it out on new people to the forum as it's going to put them off entirely.
 
fa5_r said:
iPhonefreak,
Did you say you reported his IP to proxpn? Is there a way to trace back to his original IP? I dont think proXPN terms of use permit malicious activity.
I told them to tell me everything they have on him but they didn't. .<br /><br />-- Fri Apr 05, 2013 7:28 am --<br /><br />
Fowler said:
I have seen MyBB forums also. I am 99.9% sure we know who is behind it. It was a member here who was banned for this kind of behaviour. It is also the same user who set up a fake login page of this site to try and steal users logins a few weeks back. I am pretty sure all these attacks are linked to him gaining access to a site recording users login details and trying them on other sites. Once he gets in, he can then upload what he wants.

Could you PM me who it is? I think I should know. 🙂
 
Nathan said:
Oliver.. Goes by many alias's, mostly immature names though.

He's barely a hacker.. and constantly makes me laugh.
It is not Oliver but it a kind of an American equivalent.

That said, at this time I don't really want to give too many details away about who it is at the moment. 1) I am not sure if Fergal will have an issue with me releasing the name and any information we have regarding the user and 2) I don't really want to give away how we came to find out who was behind it. The person we believe it is is not a staff member (or ever was a staff member as far as I am aware) just incase anyone accuses us of protecting a staff member. Neither are they still a member here.

What I will say is the following:
  • Check your sites for malicious files and file modifications. Check the files last modified date and use that to help see what files have been modified or uploaded recently. If you see files that shouldn't be there or files recently modified that you haven't edited then you may have been compromised.
  • Once you are pretty sure you site is in a clean state, change your account password, cPanel password and password protect your admin directory.
  • Common sense... It isn't very common. Be careful where you enter login details, what links you click and what files your download. Also be careful what sites you sign up to. Never reuse the same password between sites. Don't have guessable passwords either.
  • Make sure everything is up to date. Forum software, plugins, themes and every things on your computer. Don't forget to update your browser, Anti-virus software and so on.
  • Be security conscious. Everything you do, security should be your top priority.
 
Fowler said:
Nathan said:
Oliver.. Goes by many alias's, mostly immature names though.

He's barely a hacker.. and constantly makes me laugh.
It is not Oliver but it a kind of an American equivalent.

Tayne? I'm not sure if he's American, but he was 'working' with Oliver. Both are still not hackers and make me laugh.
 
Nathan said:
Fowler said:
Nathan said:
Oliver.. Goes by many alias's, mostly immature names though.

He's barely a hacker.. and constantly makes me laugh.
It is not Oliver but it a kind of an American equivalent.

Tayne? I'm not sure if he's American, but he was 'working' with Oliver. Both are still not hackers and make me laugh.
Not him either. Unfortunately he is also from UK along with Oliver and Evan P
 
SpacewardAsh said:
Sucks that all of this hacking has started to circle again, somebody needs a life...

Anyhow, for those wanting to disable their template editors in phpBB3 from within the ACP, take a look at this: https://www.phpbb.com/kb/article/disabl ... te-editor/ and see if it helps 🙂

Ash, thanks for the link. Will this work on free hosting as well?<br /><br />-- 06 Apr 2013, 18:35 --<br /><br />
Fowler said:
I have seen MyBB forums also. I am 99.9% sure we know who is behind it. It was a member here who was banned for this kind of behaviour. It is also the same user who set up a fake login page of this site to try and steal users logins a few weeks back. I am pretty sure all these attacks are linked to him gaining access to a site recording users login details and trying them on other sites. Once he gets in, he can then upload what he wants.

Same moron (pardon the language) who hacked Chatting Time at one point as well, if memory serves me right. I remember getting hacked once when I had that forum and seeing that GeneralOJB page that's become so infamous.
 
Smitty Fan said:
SpacewardAsh said:
Sucks that all of this hacking has started to circle again, somebody needs a life...

Anyhow, for those wanting to disable their template editors in phpBB3 from within the ACP, take a look at this: https://www.phpbb.com/kb/article/disabl ... te-editor/ and see if it helps 🙂

Ash, thanks for the link. Will this work on free hosting as well?

-- 06 Apr 2013, 18:35 --

Fowler said:
I have seen MyBB forums also. I am 99.9% sure we know who is behind it. It was a member here who was banned for this kind of behaviour. It is also the same user who set up a fake login page of this site to try and steal users logins a few weeks back. I am pretty sure all these attacks are linked to him gaining access to a site recording users login details and trying them on other sites. Once he gets in, he can then upload what he wants.

Same moron (pardon the language) who hacked Chatting Time at one point as well, if memory serves me right. I remember getting hacked once when I had that forum and seeing that GeneralOJB page that's become so infamous.

The edit won't work on free forum hosting, not that template editing is usually enabled on free forum hosts anyway 😉

As for the case of the Chatting Time hacking, it was a brute force attack on Kevs account, and they edited the forums and placed a redirect, which is the best they could most likely do on a free forum hosted account depending on what features are enabled.

GeneralOJB last I knew was Oliver, and the "GeneralOJB" name appears to have been silent for quite some time now judging by Google, but who knows eh?
 
SpacewardAsh said:
Smitty Fan said:
SpacewardAsh said:
Sucks that all of this hacking has started to circle again, somebody needs a life...

Anyhow, for those wanting to disable their template editors in phpBB3 from within the ACP, take a look at this: https://www.phpbb.com/kb/article/disabl ... te-editor/ and see if it helps 🙂

GeneralOJB last I knew was Oliver, and the "GeneralOJB" name appears to have been silent for quite some time now judging by Google, but who knows eh?

Yeah, you never know with these guys. They go by different alises and crap like that all the time, which makes it hard to track them down and turn them in or whatever, because they go by so many ID's, and especially with all the free proxy options and crap. As for the GeneralOJB name, I think you're right there, because it's been a long time since I've seen that one come up, so who knows who's behind the attacks these days?
 
Im sick of this Bs*** we need to find this hacker and put a stop to It. I say we hunt this no life down And GET REVENGE.
 
"Getting Revenge" doesn't sound like a good idea to me. Doing that would make you no better than the hacker. It's childish stuff really.
 
I have a really great idea for catching him. He also has hacked my old forum and it took a while to restart. If you are pretty skilled in coding, please PM so you can hear what my idea is. I can't say it out loud because he may be reading this topic.
 
Back
Top Bottom