MyBB Community Forums

Full Version: Hacked.
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3
There are various ways to even protect your MyBB installation beyond default protection, you should try some tutorials out there about that.
(2012-07-27, 06:30 AM)Omar G. Wrote: [ -> ]There are various ways to even protect your MyBB installation beyond default protection, you should try some tutorials out there about that.

Good point Omar. Tom K.'s is a good one.
I followed his tutorial, but it did not work.
In fact, my ACP is now screwed up.
(2012-07-27, 06:03 AM)RedCP Wrote: [ -> ]Thanks, and the exploit was through the plugins, in case I didn't give that info out.

Then MyBB has not failed you. A plugin has.
(2012-07-27, 06:36 PM)brad-t Wrote: [ -> ]
(2012-07-27, 06:03 AM)RedCP Wrote: [ -> ]Thanks, and the exploit was through the plugins, in case I didn't give that info out.

Then MyBB has not failed you. A plugin has.

Indeed, I was just frustrated since we were getting a high traffic rate and many users registering, and we were about to get a partnership with a very popular and big virtual world.

It was stressful being hacked by the person who hacked us (I'm not going to say names on the MyBB Community Forums).
IP.Board has less security then MYBB. It was most likely how you got hacked due to a 3rd party exploitable addon.
Backups are vital no matter how big or small you are.

I auto backup monthly and manually backup weekly. No matter which solution you choose you need to backup as often as possible. In fact I am looking into mirroring with daily auto syncs soon because my data is so so valuable
The reason why MyBB is the best software on the web is because as soon as they find any vulnerability they work on it and within a week they release a new update to prevent other forums from being hacked. There are only 3 ways to hack a MyBB Board, reasons as follow.

1. Using an old version.
2. Ratted or being Keylogged
3. Having unofficial or plugins with vulnerabilities.

And all these 3 reasons are the fault of the founder for not paying much attention or doing some research before downloading and/or uploading the plugins.
please share the plugin name and version with the support staff and perhaps contact the plugin author to inform them of the vulnerability. this way the plugin can be removed from the mods sites and if popular enough, the staff may post details about the exploit so others can defend against it.
(2012-07-31, 03:46 PM)pavemen Wrote: [ -> ]please share the plugin name and version with the support staff and perhaps contact the plugin author to inform them of the vulnerability. this way the plugin can be removed from the mods sites and if popular enough, the staff may post details about the exploit so others can defend against it.

It was that "Hello world!" plugin.
Pages: 1 2 3