Print Page | Close Window

What is going on?

Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=15654
Printed Date: 13 April 2026 at 10:16am
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: What is going on?
Posted By: GemmaJF
Subject: What is going on?
Date Posted: 29 June 2005 at 7:40am
Hi there,
 
We had a post on our forum this morning from 'Tithackers'
 
The notification emails went out with a 'Tithackers' background Gif image and clicking on the posting again revealed the image not the usual forum layout.
 
What the hell is going on? Our access database is stored outside our root directory.
 
It appears that the culprit joined the forum and simply made a post, how do I protect against this happening again??
 



Replies:
Posted By: dj air
Date Posted: 29 June 2005 at 9:22am
firstly , make sure you are runing the latest version.

an also do you have a url that we can see also.




Posted By: GemmaJF
Date Posted: 29 June 2005 at 9:28am
Hi dj air,
 
I deleted the original posting and it he rejoined and did the same thing, all I have is the following cut a paste of the posting. I can't see how they could have got to the database it appears to be a defacement of the post. What you see on screen is their gif image, but a copy and paste reveals this:

http://www.herpetofauna.co.uk/newsletter_subscribe.asp - http://www.herpetofauna.co.uk/newsletter_subscribe.asp -
  

 

 

UK Reptiles and Amphibians

 

  http://www.herpetofauna.co.uk/forum/default.asp - - UK Reptiles and Amphibians

javascript openWinpop_up_topic_admin.asp?TID=1089,admin,toolbar=0,location=0,status=0,menubar=0,scrollbars=1,resizable=1,width=590,height=425">

 

Topic: Look



Posted By: dj air
Date Posted: 29 June 2005 at 9:35am
are you using V7.01 if so thats the problem, there was a hack done on V7.9, and then v7.91 came out that repaired the hole.

you best bet is to upgrade to V7.91


Posted By: GemmaJF
Date Posted: 29 June 2005 at 9:41am
OK I'll download it now, many thanks Wink


Posted By: WebWiz-Bruce
Date Posted: 29 June 2005 at 11:41am
It's not really a hack and he is not getting into your database.

The problem is that the person is using CSS to change the background image of the page by posting some CSS in their post.

Just delete the post and install version 7.91 to prevent the person from posting a simular post.

Version 7.91 has a new fileter to remove this type of CSS from posts and prevent it from running.


-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: GemmaJF
Date Posted: 29 June 2005 at 12:36pm
Thanks Borg, I didn't know about css but I guessed he wasn't in the database as I still had admin control and he was doing it using the post reply box each time by rejoining.
 
Now have 7.91 installed, many thanks guys Big smile



Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net