Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - hacked, again!
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

hacked, again!

 Post Reply Post Reply
Author
louiselouise View Drop Down
Newbie
Newbie
Avatar

Joined: 13 February 2003
Location: United Kingdom
Status: Offline
Points: 11
Post Options Post Options   Thanks (0) Thanks(0)   Quote louiselouise Quote  Post ReplyReply Direct Link To This Post Topic: hacked, again!
    Posted: 16 May 2003 at 7:54am

I was hacked again. Now I can't login into the database as the hacker must have changed the passwords. I tried to upload the access database but it's either a newer version than mine access 2000, or something has happened to it so that i can't open it. I had put up a mirrored version of the site while I figured out some database issues on the forum that was originally hacked. Meaning I had a forum on the clients server. IT was hacked, so I pointed it the href to a dulpicate forum on my own site, but didn't worry about the read write permissions as I couldn't imagine it was going to get hacked while I was working on the other one, then that was hacked. http://www.louisekennedydesign.com/forum/default.asp

On the original forum, I went in and tried to rename the database, and put it in a private folder, but I can't open the forum now.

very frustrated

 

 

Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 16 May 2003 at 7:56am
Well the best first measure you can take is to change the admin password, theres a link to it on the admin menu, make the password a random string of about 6 - 10 numbers and characters to ensure no one will guess it.
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 16 May 2003 at 7:58am
On another note, moving the database obviously can help a lot, but changing password is best measure
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 16 May 2003 at 8:10am

You really must place the database outside of your web site, otherwise you are leaving your database wide open to any hacker.

The documentation with the forum gives a step by step guide on how to do this.

Your only option is to find someone who has access and can change the password for you.

Another option is to upgrade to version 7, the migration tool will reset the username and password back to the default username and password, you will also have the added protection of having your passwords 160bit one way encrypted, but you should still place the database outside of your web site away from the prying eyes of a hacker.

Back to Top
louiselouise View Drop Down
Newbie
Newbie
Avatar

Joined: 13 February 2003
Location: United Kingdom
Status: Offline
Points: 11
Post Options Post Options   Thanks (0) Thanks(0)   Quote louiselouise Quote  Post ReplyReply Direct Link To This Post Posted: 16 May 2003 at 8:18am

thanks Borg, which version of  7? I pulled the forum down.

Is this hacker a person who targets webwiz a lot?

Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 16 May 2003 at 8:36am

All version 7's have the passwords encrypted, to be hacked you probally have a version 6.x of the forums.

Just download the latest version from the forum download page and the data migration tool and follow the instructions.

There are many lame hackers out there targetting inscurely setup free web applications (just have a look at a few hacking sites to see this), as it is very simple to download a free application and see what the default name and location of the database would be. From there it doesn't take anyone above 6 years old with a computer to simply find a site running the software where the person has left there database unsecured. This is why there is a step by step guide on setting up the forum with the database renamed and placed in a secure location on the web server.

Even encrypted passwords could still be hacked eventually so a simple rule is never leave a database where it is open to hackers.

Back to Top
louiselouise View Drop Down
Newbie
Newbie
Avatar

Joined: 13 February 2003
Location: United Kingdom
Status: Offline
Points: 11
Post Options Post Options   Thanks (0) Thanks(0)   Quote louiselouise Quote  Post ReplyReply Direct Link To This Post Posted: 16 May 2003 at 8:38am

got it, thank you. I'll download version 7. The question was which version of 7, as it looks like you've got a couple going.

the question of course is why would anyone spend time hacking a forum. but that will remain unanswered

Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 16 May 2003 at 8:58am

Download which ever version you need, if you have access 2000, download that version, if your web hosts gives you an SQL server database then download that version (SQL server is much more faster and more secure than access, but you only get an SQL server database with more expensive hosting accounts).

Why would anyone want to hack a forum, usually it's done by young school kids who think it's cool to deface a web site.

Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.