Simple Machines Community Forum

SMF Support => SMF 2.0.x Support => Topic started by: Xycose on May 15, 2009, 10:26:34 AM

Title: krisbarteo joined my forum, known hacker irc
Post by: Xycose on May 15, 2009, 10:26:34 AM
krisbarteo joined my forum, no posts, if i understand correctly this is a known hacker. i banned him right away, i dont think there was any avatars in the folder, but there was a blank.gif that i dont remember being there so i deleted that as well, after reading a bit more i wish i saved that file to check it.

forum is running fine, what should i check to see if he's done anything?
Title: Re: krisbarteo joined my forum, known hacker irc
Post by: Toefur on May 15, 2009, 06:19:55 PM
He joined mine as well, and now my site is hosed.  Having problems seeing it in IE8, Firefox, and chrome. Safari seems to work for some reason.

I noticed some code in the php files that I don't think was there before. Also checking the source on my home page shows a bunch of spam/links in the divider.

Would like to know how he did that so it can be prevented. I don't feel like trying to clean up everything so I'm about to just delete, re-install, and hope for the best.
Title: Re: krisbarteo joined my forum, known hacker irc
Post by: shadow82x on May 15, 2009, 06:23:58 PM
Guys,

Be sure to take a look at this topic - http://www.simplemachines.org/community/index.php?topic=309717.0

There will be a patch in the near future addressing these security issues. :)
Title: Re: krisbarteo joined my forum, known hacker irc
Post by: Toefur on May 15, 2009, 06:29:40 PM
BTW I guess I should have posted in the 1x forums. I came to 2.0 to see if this version was safe from the attack.  Reading the other threads on it now.  Thanks!
Title: Re: krisbarteo joined my forum, known hacker irc
Post by: greyknight17 on May 16, 2009, 04:15:56 PM
It's affecting both versions from what I understand. SMF will be releasing a patch for this as soon as possible.
Title: Re: krisbarteo joined my forum, known hacker irc
Post by: glennk on May 26, 2009, 03:04:07 PM
Bugger got me as well. Says he lives in monaco. What a nugget.
Title: Re: krisbarteo joined my forum, known hacker irc
Post by: Antechinus on May 26, 2009, 06:54:00 PM
Follow the instructions here if you want to check everything: http://www.simplemachines.org/community/index.php?topic=313201.0
Title: Re: krisbarteo joined my forum, known hacker irc
Post by: ɔɔɔɔɔɔuɥoɾ on October 11, 2009, 04:06:57 PM
Do is SMF2.0 RC1.2 safe from this "krisbarteo" or any other alias he may use?

Nevermind, the exploit was removed for SMF 2.0 RC1