Web Hosting Talk Australia


Go Back   Web Hosting Talk Australia : General Forums : Lounge Bar : vBulletin exploit or easy password?
Reply

Lounge Bar General Discussion Area

 
Thread Tools
Old 12-10-2008, 09:15 AM   #16
Bendweb
Registered User
 
Join Date: Feb 2008
Location: My house!
Posts: 151
Re: vBulletin exploit or easy password?

Quote:
Originally Posted by kin0013 View Post
Hey,

Isn't it a bit strange how it always seems to happen to him.
Yeah that's exactly what I thought. If it's a VB exploit then surely whoever's doing it would have much more to gain by getting into a moderator/admin account, then they could edit everyone's posts and make people say all sorts of things rather than just send PMs from MM's account. Just seems a bit strange that's all.

Does MM usually post from a static IP address? Just wondering if VBulletin has the ability to lock user accounts to IPs, I'm pretty sure you can with Invision and other boards I've used...
Bendweb is offline  
View Public Profile Find all posts by Bendweb Reply With Quote
Old 12-10-2008, 11:24 AM   #17
Shaun Ewing
Registered User
 
Shaun Ewing's Avatar
 
Join Date: May 2002
Location: Canberra, Australia
Posts: 239
Re: vBulletin exploit or easy password?

Quote:
Originally Posted by Jon View Post
It is clearly not MM
Indeed.

I also know for a fact that Michael has not been in Canberra, nor had easy Internet access since 6am on Friday morning.

Quote:
Originally Posted by Bendweb View Post
Does MM usually post from a static IP address?
Yes.

-Shaun
__________________
Shaun Ewing
AussieHQ Pty Ltd
http://www.aussiehq.com.au

Shaun Ewing is offline  
View Public Profile Visit Shaun Ewing's homepage! Find all posts by Shaun Ewing Reply With Quote
Old 12-10-2008, 11:29 AM   #18
Ozzie
Ozzie Web Hosting
 
Ozzie's Avatar
 
Join Date: Oct 2006
Location: Hunter Valley, NSW
Posts: 386
Re: vBulletin exploit or easy password?

Well whoever it is was logging in quite regularly last night.
__________________
"Communication is the key to success in all things that life endeavours"

Ozzie is offline  
View Public Profile Visit Ozzie's homepage! Find all posts by Ozzie Reply With Quote
Old 12-10-2008, 11:33 AM   #19
adhc
Australian Data Hosting
 
adhc's Avatar
 
Join Date: Feb 2007
Location: Melbourne
Posts: 748
Re: vBulletin exploit or easy password?

Why not change the password or does this exploit get around that too?
__________________
Cheers,

Mike

I may be house trained but I still don't do windows!


adhc is offline  
View Public Profile Find all posts by adhc Reply With Quote
Old 12-10-2008, 01:48 PM   #20
perlboy
Cooking? Traderecipes.net
 
perlboy's Avatar
 
Join Date: Jun 2002
Location: Brisbane, QLD, Australia
Posts: 1,093
Re: vBulletin exploit or easy password?

By the sounds of it though Michael may just have a rather weak password. Problem is, just where he uses that password might make it possible to do the usual password reset techniques anyways.

Mods, how about a password reset on his account and see if the problem returns. If it does, now you got a bigger problem.

Stu
__________________
Personal: GooFi - Google Maps WiFi!

perlboy is offline  
View Public Profile Visit perlboy's homepage! Find all posts by perlboy Reply With Quote
Old 12-10-2008, 01:51 PM   #21
Bendweb
Registered User
 
Join Date: Feb 2008
Location: My house!
Posts: 151
Re: vBulletin exploit or easy password?

If it's a password problem... let's just hope he doesn't use that same password anywhere more mission critical!
Bendweb is offline  
View Public Profile Find all posts by Bendweb Reply With Quote
Old 12-10-2008, 02:49 PM   #22
Gary
Administrator
Moderator
 
Join Date: May 2002
Location: Tasmania
Posts: 601
Re: vBulletin exploit or easy password?

Quote:
Originally Posted by Bendweb View Post
If it's a password problem...
It's not.

G
__________________
The Dr. Phil of Web Hosting

http://www.garymeadows.com

Gary is offline  
View Public Profile Visit Gary's homepage! Find all posts by Gary Reply With Quote
Old 12-10-2008, 03:02 PM   #23
hightekhosting
Hightek Hosting - Manager
 
hightekhosting's Avatar
 
Join Date: Jun 2007
Location: Wagga Wagga, NSW, Australia
Posts: 1,072
Re: vBulletin exploit or easy password?

Quote:
Originally Posted by Gary View Post
It's not.

G
Right then. So what's the issue and what exactly is being done to stop/prevent it, out of interest?
__________________
Hightek Hosting
Affordable cPanel & Plesk Website Hosting - 24/7 Sales & Support
Ph: 1300 85 34 30- Engin VoIP Users Free Call: (02) 5908 2370 Fax: (02) 6971 1189
Web: http://www.hightekhosting.com.au Email: sales@hightekhosting.com.au

hightekhosting is offline  
View Public Profile Visit hightekhosting's homepage! Find all posts by hightekhosting Reply With Quote
Old 12-10-2008, 03:13 PM   #24
Gary
Administrator
Moderator
 
Join Date: May 2002
Location: Tasmania
Posts: 601
Re: vBulletin exploit or easy password?

I appreciate that you're interested, but it's not something that I'm discussing at this time. Once we nail the monkey (and we're close) , then maybe I'll comment.

G
__________________
The Dr. Phil of Web Hosting

http://www.garymeadows.com

Gary is offline  
View Public Profile Visit Gary's homepage! Find all posts by Gary Reply With Quote
Old 13-10-2008, 02:29 AM   #25
hightekhosting
Hightek Hosting - Manager
 
hightekhosting's Avatar
 
Join Date: Jun 2007
Location: Wagga Wagga, NSW, Australia
Posts: 1,072
Re: vBulletin exploit or easy password?

Quote:
Originally Posted by Gary View Post
I appreciate that you're interested, but it's not something that I'm discussing at this time. Once we nail the monkey (and we're close) , then maybe I'll comment.

G
Okie doke
__________________
Hightek Hosting
Affordable cPanel & Plesk Website Hosting - 24/7 Sales & Support
Ph: 1300 85 34 30- Engin VoIP Users Free Call: (02) 5908 2370 Fax: (02) 6971 1189
Web: http://www.hightekhosting.com.au Email: sales@hightekhosting.com.au

hightekhosting is offline  
View Public Profile Visit hightekhosting's homepage! Find all posts by hightekhosting Reply With Quote
Old 13-10-2008, 09:06 AM   #26
Adam Leayr
Registered Provider
 
Adam Leayr's Avatar
 
Join Date: Oct 2006
Location: Canberra
Posts: 24
Re: vBulletin exploit or easy password?

Hi guys,

Just to confirm what Gary and Jon have already stated, these PMs were not sent by Michael, as Michael is interstate for business purposes, and doesn't have access to the internet.

After all hacks on his account, the password has been changed to a more complex one, however, the issue as posted by Jon, seems to be a VB weakness, and the quicker its sorted the better for us
__________________
AussieHQ Pty Ltd
www.aussiehq.com.au
Ph: 1300 889 461
Email: sales@aussiehq.com.au

Adam Leayr is offline  
View Public Profile Visit Adam Leayr's homepage! Find all posts by Adam Leayr Reply With Quote
Old 13-10-2008, 09:48 AM   #27
Ozzie
Ozzie Web Hosting
 
Ozzie's Avatar
 
Join Date: Oct 2006
Location: Hunter Valley, NSW
Posts: 386
Re: vBulletin exploit or easy password?

Well the question still remains as to why it's only MM's account being hacked - what's the point of hacking just one members account if you have knowledge of a weakness in the VB code then you'd aim for the bigger fish and lock them out and take over the board, just doesn't add up, there's more to this!
__________________
"Communication is the key to success in all things that life endeavours"

Ozzie is offline  
View Public Profile Visit Ozzie's homepage! Find all posts by Ozzie Reply With Quote
Old 13-10-2008, 10:58 AM   #28
nljc88
Nathan C
 
Join Date: Mar 2007
Location: Gold Coast
Posts: 304
Re: vBulletin exploit or easy password?

Maybe as previously stated its a previous customer or employee, and they only want to get back at Michael?
__________________
Nathan C

nljc88 is offline  
View Public Profile Visit nljc88's homepage! Find all posts by nljc88 Reply With Quote
Old 13-10-2008, 11:59 AM   #29
Spirit Connect
Uptime Addict
Moderator
 
Spirit Connect's Avatar
 
Join Date: Feb 2003
Location: Brisbane, Australia
Posts: 5,854
Re: vBulletin exploit or easy password?

Hosting company owners will soon need to have personal security guards with the way things are these days.
__________________
Web Hosting

Spirit Connect is offline  
View Public Profile Visit Spirit Connect's homepage! Find all posts by Spirit Connect Reply With Quote
Old 14-10-2008, 10:25 AM   #30
Michael McGoogan
Registered User
 
Michael McGoogan's Avatar
 
Join Date: Jul 2004
Location: Canberra, Australia
Posts: 502
Re: vBulletin exploit or easy password?

Hi Guys,

A couple of points:
* As stated, it wasn't me sending the messages
* It has nothing to do with the password on the account and never has been. It is an exploit in the forum software.
* It is not just my account.
* Gary and Jon have assured me that the issue will be fixed soon.

Sigh.
__________________
AussieHQ Pty Ltd
www.aussiehq.com.au
Ph: 1300 889 461
E-mail: sales@aussiehq.com.au

Michael McGoogan is offline  
View Public Profile Find all posts by Michael McGoogan Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:

Similar Threads
Thread Thread Starter Forum Replies Last Post
Brute force password checker AndrewK Technical Support 2 05-09-2007 09:39 PM
vBulletin 3.6.4 causing extremely high server load hightekhosting Technical Support 8 26-08-2007 05:37 PM
Help with password protected directories please Ozzie Technical Support 7 01-12-2006 01:15 AM
auda password recover not working domdom Domain Names 6 28-08-2006 01:14 PM
vbulletin Skins ibroccoli Programming and Web Development 2 23-05-2006 08:47 PM