According to my host, your forum is NOT secure, and is easily Cracked!

Started by tpgames, June 06, 2017, 03:11:17 PM

Previous topic - Next topic

Colin

Sure, but you can assume that they are on the same server (for his situation) so that isn't the issue. The issue he was pointing out was some hacker brute forcing the password remotely and in that case for non 127.0.0.1 connections you can have some form of TFA.
"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin

tpgames

I do understand that they are trying to make the cloud safer and more crack proof then what we have now. I just am not seeing it as a reality due to the ingenious sophistication that modern day crackers have. Crackers just get better with the technology. Maybe someday the cloud will be so secure that crackers have a very tough time of negatively impacting other computers. Maybe someday, trojans and viruses won't be so easily transmitted between computers. I just don't see that as I see crackers as humans with brains that keep getting better and better. Thats all.

Arantor

You see threats that don't exist because you think that breaking into computers is like it is on TV. It really isn't.

When a certain antivirus vendor got their forum broken into, it wasn't because of anything sophisticated but simply the admin used a weak password that was already leaked elsewhere from another site that had been broken into. This was then used to log into the forum, make changes to the theme because admins can do that, to get a malicious piece of code onto the server, from where the server was compromised.

No DB password was touched.

tpgames

I'm glad that they think "no db pw" were cracked. All I know is that despite 50 character long passwords using all characters available to me, I was cracked and pages were changed. Nothing I can do about it. He did get onto my website and did change 2 files and did this AFTER SMF was deleted! Oh well, this is closed now. We can't do anything beating a dead horse. This happens. I'll have to take my other forum, and somehow run a fix as it didn't upgrade properly despite using the packet manager and seeing no "errors" to warn me of a potential conflict if I upgrade. :P Yep, I am having the issue that others have had. However, I'm assuming that the issue is with a mod. I can't remember which forum had the mod that I uninstalled, and think it might have been this one. I want to copy the look and feel of the theme and convert default to give me something similar anyway in preparation for 2.1 getting out of beta. Currently, I can't even log in to the forum. :P  I very nearly didn't update too. Oh well.  ::)
Update: I have to change the theme's coding to be compliant with new rules, then I should be fine. lol

Arantor

If they'd changed files, it's nothing whatsoever to do with the database!

It could be that your host hasn't secured permissions properly and another user on the same server messed up or broke in deliberately.

Stop chasing ghosts and jumping at shadows and get someone who can actually assess your situation.

tpgames

I got it working and tested it, but just got back here and was going to update my answer again. But here is my update:  I just replaced the files back to the 2.0.13 version. I'm going to change themes to SMF default so that I won't have issues upgrading in the future. I did look at the code and realized that the issue was the files that were replaced was incompatible with how metin blue was coded. I was wondering if this was it in the first place.  No worries. Thanks!

tpgames

Quote from: Arantor on June 09, 2017, 01:50:31 AM
If they'd changed files, it's nothing whatsoever to do with the database!

It could be that your host hasn't secured permissions properly and another user on the same server messed up or broke in deliberately.

Stop chasing ghosts and jumping at shadows and get someone who can actually assess your situation.

I've contacted IC3 ( FBI's agency for Cybersecurity). T35 did what they are going to do. Its done. T35 did suggest I go with dedicated server. I can't afford that yet so I'll just let it be and start the forum a new. The other forum works fine (different domain name). Its okay. Its not like I collect $Euro£ or anything. Its just a hobby site. Thanks though! I do appreciate your help!

Kindred

SO... you really have no clue.
You have watched too many movies and have no actual knowledge of reality.

What exactly do you think "the cloud" is?

as for you having issues with 2.0.14 --  that, right there, is suggestive of part of your issue.
2.0.14 will have those issues that you described if your host is running php 5.3 (or earlier)
since php 5.3 is not supported by even php any more, including security patches, there's a good chance that your HOST has an issue in that they are running an insecure server.

This has nothing to do with passwords.
This has nothing to do with SMF.
This has nothing to do with Cpanel or mySQL.


You need to STOP....   stop assuming that you have any clue at all and LISTEN to the people who know what they are talking about - because, so far, your explanations have just proven that what you THINK is your "knowledge" is just plain wrong.
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Advertisement: