MyBB Community Forums

Full Version: myBB 1.6.4 Backdoor Exploit
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
<snip>
Please do not post code to hack forums.
sorry for this post..i just came to know this now..theres a backdoor to hack forum..i want all users to patch the backdooring the forum site with metasploit, my forum was hacked yesterday..
Are you actually talking about HF or hacking any forum? Huh
no..my forum has been hacked by some hackers..they have modified my calender.php to their custom message as HACKED BY " .. they have accessed my database, mybb admin panel, they still have my database name,username and password, with the help of honeypot i got my admin panel back, the forum is offline now, i want to know how this hack has been done..this is the second time i lost my forum, what to do now, i have to delete those databases or what?? they know my DB details, i am using the patched version of mybb, so i thought theres no security issues in my forum,, but i dont know how these guys hacked my form... please sombody help me..
Reupload all mybb files, change absolutely all your forum-related passwords, and if you do not use it and you think it is a problem, delete calendar.php
what about databases Omar?? i have to delete those databases??i dont want to lose my posts..can we change the database password?? and updating it in config.php..is it possible??
^ first change passwords for everything ; then can you check contents of database tables and
ensure that database has no malicious codes (may be you can compare with a backup ... etc.)
You already have a thread for exactly the same thing. You can ignore my advice and everyone else's too if you want, but this will keep on happening until you do things properly.

http://community.mybb.com/thread-107803.html