MyBB Community Forums

Full Version: Recovering from turkish hack
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Hola,

Recently I was hacked like my others by a Turkish group exploiting older versions of MyBB. So like any other admin I explored the MySQL database looking to see how I was being redirected, and upgraded my forum to 1.5.

After finding the redirect code within the boardclosed_reason area, I removed it and set boardclosed to 'no'. However my board still remains closed and the redirect inplace. I'm not qutie sure how this can be possible when I've removed it. Also none of my forum descriptions have been altered.

Following some of the posts on this forum I disabled javascript in my browser to look at the source, which promptly revealed that the redirect code is still in place right below the board is closed message.

What can I do to recover from this?

I would also appreciate if anyone could tell me how to access my ACP with my admin account deleted aswell, and therefore I have no other entry points while the closed message is implace.

Many thanks.
The settings are stored in the file inc/settings.php. It gets updated everytime you make changes in your Admin-CP. You have to edit the settings in the file.
Aha Big Grin. No idea why the information is repeated in the DB then, but oh well.

Thanks very much for that pointer Michael, everything is back to normal now Smile
When you edit the settings from the Admin CP, the file is supposed to be updated. Maybe your inc/settings.php isn't writable by the server?