MyBB Community Forums

Full Version: K Design hacked..
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3
http://www.kdezign.org/

Who owns this site? Hopefully they have back-ups...
Why not contact them?
I sent a PM to him earlier this evening. I had notice this too. I wonder what plugins he was running.
Hopefully they wont die out because of this, having your forums hacked must be depressing.
@Labrocca: This excludes you. Toungue
They should of released all the skins from premium. MyBB is piss easy to hack via the database.
http://www.kdezign.org

MyBB staff please check...could this be a MyBB bug?
Generally when there is an exploit of such magnitude found in software the 'hacker' would target bigger sites.
This seems to me like the administrator/owner did not keep passwords safe enough from public. Either MySQL passwords or the password to the administrator account itself.


I'm not saying that there is nothing wrong with MyBB right now, all I'm saying is that there is not enough to say that MyBB is unsafe. Currently we have no known issues.

Best of luck to the lucky owner of that site.
What about installed plugins? Do you recommend to keep mybb as clean as possible?

[offtopic]what are recommended permissions for config.php and settings.php? 644 is ok or 444?
Holy damn, that sucks :| Good luck ak47.
(2009-02-03, 02:11 PM)Mareshal Wrote: [ -> ]MyBB staff please check...could this be a MyBB bug?

What do you expect anyone to 'check'?? Huh We have no idea how they gained entry. It could be what rh1n0 said and be insecure passwords, ergo, nothing we can do to stop it. If it was a MyBB problem we'd need info on it, but again, as rh1n0 said, if there was a known MyBB exploit, I reckon these forums would be top of their list.

(2009-02-03, 01:19 PM)Combo Wrote: [ -> ]They should of released all the skins from premium. MyBB is piss easy to hack via the database.

I'm not sure what you mean here about releasing the themes... and if someone has database access, they can do anything... it's how they get to the database that's the problem. If they get to it through a MyBB exploit it's bad for us, if they get to it through insecure passwords, it's just bad luck for the admin.

(2009-02-03, 02:32 PM)Mareshal Wrote: [ -> ]What about installed plugins? Do you recommend to keep mybb as clean as possible?

[offtopic]what are recommended permissions for config.php and settings.php? 644 is ok or 444?

settings.php has to be 666 so it can be written to but config.php can be 444.
Pages: 1 2 3