MyBB Community Forums

Full Version: Warning...Script Kiddy about
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3 4 5 6 7
Thanks Chris, I'm adding this plugin now (although with a much more rude die() message, hehehe).
Hmm...I had an install recently that I didn't have posted anywhere. So yes..he is finding sites with Google or another search engine looking for the Powered By line...

How can we prevent this since removing that line is against copyright?

Will you guys allow the removal of that text and changing it to an image?
I hope they allow it, cuz I've done it. To any observer, it looks like the normal text copyright, but as an image it prevents the name of your forum software from being picked up by search engines. I used an image map to retain the links to mybboard.com as they were in the text version. I don't see any problem with it, since the copyright is NOT removed, it's just in a different form.
Maybe this should be default Wink
Not a bad idea, but then the board is not friendly to non-graphical browsers and for the blind.
how you check ??? to see if anyone like this on my forum can someone tell how can i look for it

thanks
The Wicked Flea Wrote:MyBB 1.1.2 was protected from the attack as well. At least upon my board it was.

1.1.2 is vulnerable from this exploit. Please upgrade to 1.1.3
80.242.79.132

and more signups...this is annoying..I added '.system( to the username ban list but it appears not to have worked

I added just the word system to see if that does it.

Also how can I ban all .ru email signups? Such as *@*.ru works on most forums but will it work for mybb?

We need a better solution to prevent this guy from signing up so much.

This is scary what he is trying...

'.system($_POST[cmd]).'
Quote:and more signups...this is annoying..I added '.system( to the username ban list but it appears not to have worked
Use the plugin posted in the announcements forum and it will prevent it completely.
labrocca Wrote:We need a better solution to prevent this guy from signing up so much.
It's not just one guy. There's a Perl script floating around that automates the whole exploit process, so anyone who can run a Perl script can try to exploit a MyBBoard.
Pages: 1 2 3 4 5 6 7