image
image

Go Back   macosx.com > Community > Bob's Place

Reply
 
Thread Tools
  #1  
Old June 17th, 2008, 06:27 AM
Rhisiart's Avatar
Dal i Fynd! (Keep Going)
 
Join Date: Apr 2005
Location: West Britain
Posts: 1,629
Thanks: 13
Thanked 6 Times in 6 Posts
Rhisiart will become famous soon enough
Coincidence?

I manage a running club forum using vBulletin. Over the last few months, numerous spammers have set up user accounts, only for me to delete them once I know they are there.

After a while I gave up and closed down user registration. Now to join, prospective members have to email me with some evidence that they are local and that are genuine sports people.

So far so good. However this morning - out of the ordinary I may add - I logged into the forum admin control panel using Windows XP on the VMware virtual machine and within twenty minutes some hackwallah from Turkey had broken in and had created a new user account.

I suspect he did it to prove it could be done. I just find it hard to believe that he would have achieved this had I logged in using MacOS. Or am I wrong?
__________________
Intel Mac Mini 1.83 1GB 10.5.4
PowerMac G4 833Hz 768MB 10.3.9

Education is when you read the fine print - experience is what you get when you don't.
Pete Seeger
Reply With Quote
  #2  
Old June 17th, 2008, 09:03 PM
symphonix's Avatar
Scratch & Sniff Committee
 
Join Date: Jul 2001
Location: The Australian Jungles
Posts: 4,022
Thanks: 2
Thanked 2 Times in 2 Posts
symphonix is on a distinguished road
It is hard to know without knowing at what point you've been compromised.

If it was a vulnerability in VBulletin, or if your VBulletin password was insecure and was brute-force hacked, or had been picked up through being used at another site, then no, using a Mac would not have made a difference.

If the access was gleaned using spyware, a keylogger, or remote access to a file share on your computer, perhaps grabbing your cookie files or any documents containing the word "password" then it might have made a real difference. Perhaps the access had been achieved much earlier, perhaps you accessed your account from another compromised computer, or perhaps the database backend to the forum was vulnerable enough to allow the hacker to read the username/password table.

The real question is, where did this guy get in? Without carefully checking each link in the chain, you can't really be sure. Would I discount a Windows virus/spyware program infecting your Windows VM: hell, no. It would be pretty high on my list of suspects.
__________________
- iMac G5 1.8GHZ 17" | SuperDrive | 160GB | 512MB | Airport Extreme | Bluetooth Keyboard & Mouse | Wacom Intuos II
- Pentax *ist DL - JVC MiniDV Camcorder - Airport Express - iPod Nano 1gb white
Reply With Quote
  #3  
Old June 18th, 2008, 11:03 AM
Rhisiart's Avatar
Dal i Fynd! (Keep Going)
 
Join Date: Apr 2005
Location: West Britain
Posts: 1,629
Thanks: 13
Thanked 6 Times in 6 Posts
Rhisiart will become famous soon enough
Yes, I need to investigate it a little more. It just seemed a coincidence that this person got in whilst I was using Windows.

Interestingly the hacker's username is the same one identified in another forum hosted in our village. That person was traced back to Turkey, but after that it was a dead end.

Your reply is very helpful. I shall delve into the forum control panel and see if I can see anything that might help.
__________________
Intel Mac Mini 1.83 1GB 10.5.4
PowerMac G4 833Hz 768MB 10.3.9

Education is when you read the fine print - experience is what you get when you don't.
Pete Seeger
Reply With Quote
  #4  
Old June 19th, 2008, 01:53 PM
Registered User
 
Join Date: Apr 2004
Posts: 202
Thanks: 0
Thanked 0 Times in 0 Posts
rubaiyat is on a distinguished road
btw Is Wallahwallah Hindii for a homosexual?
Reply With Quote
  #5  
Old June 20th, 2008, 03:36 AM
Rhisiart's Avatar
Dal i Fynd! (Keep Going)
 
Join Date: Apr 2005
Location: West Britain
Posts: 1,629
Thanks: 13
Thanked 6 Times in 6 Posts
Rhisiart will become famous soon enough
I don't know. That's outside my scope of practice.

I do sometimes refer to the good wife as the dobi wallah (at the risk of having certain parts of my body removed against my will).
__________________
Intel Mac Mini 1.83 1GB 10.5.4
PowerMac G4 833Hz 768MB 10.3.9

Education is when you read the fine print - experience is what you get when you don't.
Pete Seeger
Reply With Quote
  #6  
Old June 20th, 2008, 11:26 AM
fryke's Avatar
Super Moderator
 
Join Date: Sep 2000
Location: macosx.com
Posts: 13,158
Thanks: 2
Thanked 12 Times in 12 Posts
fryke has a spectacular aura aboutfryke has a spectacular aura about
In my experience, such hacks are done by (ab)using existing exploits for the forum software. It's a drag.
__________________
MacBook Air 13" 1.6 GHz, 2 GB RAM, 80 GB HD. Mac OS X 10.5.5
MacBook 13" 1.83 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
Hackintosh Core2Duo 2.4 GHz, 2 GB RAM, 160 GB HD. Mac OS X 10.5.5
iPhone 3G 16 GB (v2.1), AppleTV 1G 40 GB (v2.1)

Mac user since 1987, Apple Product Professional 2007, 2008.
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off
Forum Jump


All times are GMT -5. The time now is 09:51 AM.


Mac Support® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Copyright 2000-2008 DigitalCrowd, Inc.