JCYouth Christian Teen Forum Welcome to JCYouth!   
Join the World's   
Best Teen Forum   
|   
July 30, 2010, 02:13:52 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?
Shout Box

...loading shoutbox...












Login with username, password and session length
News: Welcome All New Members to JCYouth!
 
   Home   Arcade Store Help Search Calendar Login Register  
JC Youth - Christian Teen Forum > Main boards > News and Announcements > JCYouth Support & Feedback > Security problems?
Pages: [1]   Go Down
  Print  
Author Topic: Security problems?  (Read 2501 times)
0 Members and 1 Guest are viewing this topic.
Administrator

********

Hugs: 9
Offline Offline

Posts: 145
Username: Arkav

213.00clams

View Inventory
Send Money to Arkav

View Profile WWW
« on: April 26, 2008, 01:03:56 AM »

What happened here? sombody exploited your forum and shoutbox?
I keep seeing a red text image in the shoutbox that says "hacked by BHack Crew"
if you need help with fixing stuff or something else like finding those guys just let me know.
Logged

ElaineG / Arkav *FF General*
www.forcefighters.com
Beauty showing through the ugliness of the world.

*****

Hugs: 44
Offline Offline

Posts: 2740
Username: Amythestjewel09

886.40clams

View Inventory
Send Money to Soliele

Child at heart


View Profile WWW
« Reply #1 on: April 26, 2008, 04:56:19 PM »

I noticed that too. I'm really freaked out now...
Logged

I am the way
I am the light
I am the dark inside the night

I hear your hopes
I feel your dreams
And in the dark I hear your screams

Don't turn away
Just take my hand
And when you make your final stand

I'll be right there
I'll never leave
And all I ask of you
Believe
Administrator

********

Hugs: 9
Offline Offline

Posts: 145
Username: Arkav

213.00clams

View Inventory
Send Money to Arkav

View Profile WWW
« Reply #2 on: April 27, 2008, 01:57:17 AM »

you shouldn't be freaked out,
it's probably nothing that big,
there are some security issues with most things which are done in web languages like these and when someone finds those vulnerabilities and spread them, well there are group of people who enjoy damaging ("defacing") websites/forums randomly...

Consider that this version of SMF forums is quite old and it is easy to find exploits for it online. I've been posting about this issue time ago, but it looks like people here are not very likely to take my words into consideration on this matter, not sure why.

Well, again, these things are quite easy to fix. The shoutbox is still giving a redirection to that picture "hacked by..." and I hope your admins are able to handle this kind of problems. I would be glad to help in this but it's your choice.
Logged

ElaineG / Arkav *FF General*
www.forcefighters.com
I never thought I'd make it this long, but the Lord has delivered me!
Global Moderator

*******

Hugs: 87
Offline Offline

Posts: 3896
Username: mandapandajbb

34.00clams

View Inventory
Send Money to Amanda


View Profile WWW
« Reply #3 on: April 27, 2008, 05:41:12 AM »

You're awesome Arkav =)
That's all I have to say. lol *hugs*
Logged

"Fare Thee Well."
Have faith, ye weary and ye worn
Thy burden lay ye here
The tides are rushing 'round and 'round
No waters shall ye fear.
(excerpt from my poem "Fare Thee Well")


PM me if you need help!
Administrator

********

Hugs: 9
Offline Offline

Posts: 145
Username: Arkav

213.00clams

View Inventory
Send Money to Arkav

View Profile WWW
« Reply #4 on: April 27, 2008, 07:57:36 AM »

lol *hugs* manda Wink
Logged

ElaineG / Arkav *FF General*
www.forcefighters.com
Administrator

********

Hugs: 9
Offline Offline

Posts: 145
Username: Arkav

213.00clams

View Inventory
Send Money to Arkav

View Profile WWW
« Reply #5 on: April 27, 2008, 02:39:59 PM »

Fixed it for now,
it's a silly exploit but can be problematic if people use it for bad purposes.
So my suggestion is still to update to newest version of SMF and check for a newer version of shoutbox aswell
Logged

ElaineG / Arkav *FF General*
www.forcefighters.com
Return.

*****

Hugs: 179
Offline Offline

Posts: 1436
Username: Shub

382.00clams

View Inventory
Send Money to RAVENOUS


View Profile
« Reply #6 on: April 30, 2008, 05:10:29 PM »

but it looks like people here are not very likely to take my words into consideration on this matter, not sure why.

You have bad hair and you smell funny.

Peace Wink
Logged

"Nothing is certain until you are certain of nothing."
Administrator

********

Hugs: 9
Offline Offline

Posts: 145
Username: Arkav

213.00clams

View Inventory
Send Money to Arkav

View Profile WWW
« Reply #7 on: May 01, 2008, 02:12:43 AM »

but it looks like people here are not very likely to take my words into consideration on this matter, not sure why.

You have bad hair and you smell funny.

Peace Wink

Lol, drank something alchoolic this time, END?
The shoutbox is fixed by the way, at least until someone else doesn't feel like injecting it with more html Tongue
Logged

ElaineG / Arkav *FF General*
www.forcefighters.com
Return.

*****

Hugs: 179
Offline Offline

Posts: 1436
Username: Shub

382.00clams

View Inventory
Send Money to RAVENOUS


View Profile
« Reply #8 on: May 01, 2008, 06:20:34 AM »

but it looks like people here are not very likely to take my words into consideration on this matter, not sure why.

You have bad hair and you smell funny.

Peace Wink

Lol, drank something alchoolic this time, END?
The shoutbox is fixed by the way, at least until someone else doesn't feel like injecting it with more html Tongue

Yeah, I noticed you doing the same thing to the shoutbox really, same principle fundamentally when you get down to it. That's why I stopped messing with JCyouth ages ago. Couldn't keep a line drawn in the sand, because I kept smearing it when I'd cross over, even when it wasn't prompting "apolocolypse". Your continued usage of coding would indeed prompt any passerby looking for exploits, to exploit what has been brought to their attention as well. That's why they say where there's one vulture, there's soon to be many.

Thank you though for correcting the issue, you have our thanks.

Peace.
Logged

"Nothing is certain until you are certain of nothing."
Administrator

********

Hugs: 9
Offline Offline

Posts: 145
Username: Arkav

213.00clams

View Inventory
Send Money to Arkav

View Profile WWW
« Reply #9 on: May 01, 2008, 08:04:10 AM »

yeah, that's true that I used the same exploit to make my text coloured.

fortunately it seems that now only registered members can write on shoutbox. Also it would be quite easy to avoid the problem completely by updating forum+mods (shoutbox in this case) Tongue

Anyway, if you ever need some help with this kind of stuff let me know, I enjoy it. Wink
Logged

ElaineG / Arkav *FF General*
www.forcefighters.com
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC Valid XHTML 1.0! Valid CSS!