Jump to content

pushpullbar hacked!


Fernando Lino
 Share

Recommended Posts

  • Administrators

This is really unfourtunate. They use the same forum software as CGA, so I will be currious to find out from the guys that run the site what weakness was exploited. It is a modified forum and not the latest version, so I'm hoping we are not vulnerable given that we are up to date and no forums hacks.

Link to comment
Share on other sites

I know hard it is to convey sarcasm over the net... right?

 

Yes, that was meant as sarcasm - I've seen this before, don't know if it's a "real" political group or just some kids in Ohio but so far I don't think they've hit anything that the people they say they oppose would care about, they're just annoying the rest of us.

Link to comment
Share on other sites

This is really unfourtunate. They use the same forum software as CGA, so I will be currious to find out from the guys that run the site what weakness was exploited. It is a modified forum and not the latest version, so I'm hoping we are not vulnerable given that we are up to date and no forums hacks.

 

Hi Jeff,

 

I am the founder of PushPullBar and yes it uses vBulletin (although I was only using Release Candidate 4 and never bothered about upgrading to the most current). The hackers got through not via the bulletin board, but they went in the backdoor, all the way and deleted everything including all the backup files. It is the hosting company's lack of security that was the problem. Did a google and found out that this hosting company is absolutely crap and verging on fraud.

 

I heard Architosh got hit 2 years ago too. BACK UP BACK UP BACK UP is all I can say, backup to your own computer.

Link to comment
Share on other sites

  • Administrators
Hi Jeff,

 

I am the founder of PushPullBar and yes it uses vBulletin (although I was only using Release Candidate 4 and never bothered about upgrading to the most current). The hackers got through not via the bulletin board, but they went in the backdoor, all the way and deleted everything including all the backup files. It is the hosting company's lack of security that was the problem. Did a google and found out that this hosting company is absolutely crap and verging on fraud.

 

I heard Architosh got hit 2 years ago too. BACK UP BACK UP BACK UP is all I can say, backup to your own computer.

 

Really sorry to hear about that Kevin. Does this mean you have lost everything? All your data? When you say backdoor, what did you mean. Email me at jmottle@cgarchitect.com if this is sensitive from a security standpoint. I want to be sure we are not also vulnerable. That's really too bad about your host as well. For what it's worth I reccomend my host to everyone. I have a dedicated server with them, and their support is beyond good, it's simple the best support I've ever seen from any company and I am extremely picky. www.alentus.com

 

Here is their client list: http://www.alentus.com/about/customers.asp

 

I remember when Architosh got hit. Our business development manager also works for them as well. Hope you are able to get back up and running.

Link to comment
Share on other sites

well, there is next to none security (from what i read from other's reviews after the event) for the account i have with the hosting company, so not just the /forum folders got deleted, but the entire directory structure outside the vbulletin stuff.

 

looking at a complete rebuilding from scratch. so i will buy vbulletin again and get the latest (from the sound of things, the latest version patches a security weakpoint of previous releases, so make sure you have the latest). i am just scared of messing around with this stuff, i am not a techincal person, hence i was scared of updating to the latest.

Link to comment
Share on other sites

  • Administrators

If you need a hand, let me know. While I am not a PHP guru, I've installed and upgraded the VB forums enough to know my way around it. I don't know anything about the addons you had done though.

 

As an aside, Alentus does daily backups for you in their plans.

Link to comment
Share on other sites

not just the /forum folders got deleted, but the entire directory structure outside the vbulletin stuff.

 

I'm really sorry to hear this, as well. That was/is a great site. The SU community is terrific, very generous lot. There was quite a collection of SU stuff on your site. If it was lost, I'm sure much of it can be re-posted by your members (which, I think, includes me). But the most valuable aspect was the backlog of answers to questions, just like CGA.

 

CYA, Jeff.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

×
×
  • Create New...