• Howdy! Welcome to our community of more than 130.000 members devoted to web hosting. This is a great place to get special offers from web hosts and post your own requests or ads. To start posting sign up here. Cheers! /Peo, FreeWebSpace.net
managed wordpress hosting

XMB Forum has been hacked!!!!

Does anybody believe this statement?
"all admin accounts are secretly logged with IP and time and any other details we can receive from the browser at the current time"

I mean, come on... how stupid do you think we are :)
 
> I mean, come on... how stupid do you think we are :)

It's not at all hard for me to imagine that they put a little extra code in the php files so that whenever an admin does something (logs in, visits board, whatever...), their actions are logged in a file/database somewhere. Infact, I do the same thing in some of my scripts.

BTW, They probably don't mean on EVERY xmb forum out there, but their support forum.
 
When I want there I got this...

This message board is closed because:
If this hacking continues, and somebody changes my password ONE MORE TIME, and uses my account ONE MORE TIME to screw up the settings, I WILL take down this support site PERMANENTLY until we can gather who is doing this, and let the feds deal with it. Damnit guys, this support forum IS FOR YOU to get help, not abuse. We know who you are, since you foolishly decided to use my account to do your evil work, all admin accounts are secretly logged with IP and time and any other details we can receive from the browser at the current time. You will be receiving an email as soon as I have time to match you up with a regular user account... Oh yeah, doesnt matter if you change your emial in your account either, we have backups... Or if you dont have an account here, im sure the feds can find one. Thanks for your time, and consider all of you warned.
 
Originally posted by roly
When I want there I got this...

This message board is closed because:
If this hacking continues, and somebody changes my password ONE MORE TIME, and uses my account ONE MORE TIME to screw up the settings, I WILL take down this support site PERMANENTLY until we can gather who is doing this, and let the feds deal with it. Damnit guys, this support forum IS FOR YOU to get help, not abuse. We know who you are, since you foolishly decided to use my account to do your evil work, all admin accounts are secretly logged with IP and time and any other details we can receive from the browser at the current time. You will be receiving an email as soon as I have time to match you up with a regular user account... Oh yeah, doesnt matter if you change your emial in your account either, we have backups... Or if you dont have an account here, im sure the feds can find one. Thanks for your time, and consider all of you warned.

Exactly. That's what you're supposed to get. I guess they haven't gotten the boards back up and running again.
 
Originally posted by conkermaniac


Exactly. That's what you're supposed to get. I guess they haven't gotten the boards back up and running again.
I don’t even think it’ll be up for the time being. It’s not that easy to find the culprit.
 
I haven't used the forum but it is possible that admin actions are logged by IP (and that the forum has this feature in general), but that doesn't mean they know who it is, nor that they can catch them easily.
 
XMB wasnt the only board that had this bug, some others did as well, they have all fixed the bug with the fix we provided

The hacking done was done with a special way of registering with a certain username and certain characters after it. Then the lost password function was used and the password for the administrators account got changed.

AlieXai is correct, we do log all actions in the administration control panel, we log users ip's, actions, times, useragent and any other information we can gather. Its all stored in a file on the server so it cannot be wipped without having file access to the system.

The boards were down for so long because we were looking at ways to fix the bug and to change over the language system style.

We have tracked down this person, one of the staff also received U2U's (like PM's) from him explaining how he executed the bug. The ISP of the user has been informed and from what i hear, they are dealing with you

Thank you for your support :D

- Chris Boulton
http://www.xmbforum.com
 
Last edited:
Can i dl the fixew? I was going to install XMB Forum on my site but i thought that that may be a bad idea.
 
XMB 1.5 Gold will be out soon which will contain the fix, seeing its a very hard exploit to think up, we dont think it will be executed again...

If you really want it fixed now, you can email me by clicking here

Please included your forum name so i know who it is :)

Originally posted by roly
Can i dl the fixew? I was going to install XMB Forum on my site but i thought that that may be a bad idea.
 
Originally posted by surfichris
XMB wasnt the only board that had this bug, some others did as well, they have all fixed the bug with the fix we provided

What do you mean by this?
 
Back
Top