The forum of the forums
Welcome to the Official Support Forum of Forumotion!

To take full advantage of everything offered by our forum, please log in if you are already a member, or join our community if you've not yet.



Create a free forum like this one.

Help Needed on Forum Security

View previous topic View next topic Go down

Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 9:29 pm

Myself and DanceJonDance have been administrating the forum: www.turboduelacademy.com for over a year and had issues in the past with accounts being used by a malicious individual to delete topics and cause us trouble resulting in having to back up the forum.

We were left alone for about 6 months and now its gotten worse. The individual who told us "I will hack you in christmas" appears to be back and is able to use any admin account as he/she wishes to get to the founder account and mess with the forum. Both myself and DanceJonDance have successfully reset the password on the founder account and banned the IP's he used to do this the first time. Since this guy is using some sort of proxy the ban method does nothing and the next day the founder account gets changed again and once again he starts messing with things. This happened for 2 days.

We deranked all admins leaving only myself and The TDA Staff. (The founder account) as admins since my admin account had never been touched by this individual.

I woke up this morning and it seems my account was taken and the entire Administration Group was deleted and we cannot even get the password for the founder account as he appears to now have changed the email. The founder account no longer seems to be an administrator either. I also received this email in my inbox:

The administrator : The TDA Staff. (Ip Address: 81.25.140.6) has chosen to delete the forum turboduelacademy.forumotion.com.

If he validates the deletion, the forum won't be available anymore.

The founder of the forum can restore it by going to this address :

http://www.forumotion.com/en/utils/



Cordially, the support of forumotion
http://help.forumotion.com/


The IP address listed in the email is one of a number of IP's coming from "Iraq" that have been causing us issues for 6 months now. We no longer have any power and need help on what to do :/

Much appreciated,
Det.

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 9:32 pm

Do you still have access to the utilities?

~ Tilum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 9:41 pm

I believe we still have access to utilities, since we could change the account password last night, but once we do so the next time this individual decides to visit he just changes the password again.

The weird thing is was when i checked the security in the admin panel when i still had access it showed something along the lines of:

10:02 The TDA Staff. etc etc
10:02 The TDA Staff. (founder) (IP address) has backed up the forum
10:01 BERKAY (IP address) administrator logged in

He gets onto an admin account and somehow without signing in through the founder account, gets onto that as well. When myself or DanceJonDance use the founder account the security shows a log of it signing in.

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 9:46 pm

This sounds pretty serious. Do you have a username or alias for the hacker, sounds something similar to Oliver. I assume Berkay is a normal admin?

~ TIlum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 9:53 pm

Berkay is a normal admin.

And yes we use a program called hamachi and on there he refers to himself as Kira.

We are not the only forum targeted by this individual either, he has successfully deleted other Yugioh based forums as a warning.

EDIT:
i didnt realise DanceJonDance already created a topic for this so sorry for the spam

http://help.forumotion.com/other-problems-f46/security-issues-t82631.htm#533780


Last edited by The Detonator on December 9th 2010, 9:55 pm; edited 1 time in total

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 9:55 pm

He uses Hamachi to hack?

~ Tilum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 9:56 pm

No hamachi is just a communication chat program we use to communicate with forum members. It also allows connection for internet gamers who cant host IP games

I believe this topic outlines it a bit more, i didn't realize he had posted.
http://help.forumotion.com/other-problems-f46/security-issues-t82631.htm#533780

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 10:00 pm

Hamachi is like LogMeIn.

Does that not mean that the hacker could get into your machine and control the founder account that way?

~ Tilum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 10:03 pm

I don't know much if anything about hacking through a program like hamachi. But none of the admins on our forum have him in a hamachi network. And yeah it is LogMeIn xD

So if he can use hamachi as a hacking tool and isn't in a network of an Admin member then that's not cool :/

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 10:06 pm

So there is a chance he's logging remotely into your computer and logging into the founder account and from there changing stuff?

~ Tilum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 10:08 pm

I honestly have no idea how that would work or if that is what is happening.

FYI:
We haven't signed up and registered account on LogMeIn, we have just downloaded Hamachi (the program)

Btw thanks for your replies on this.

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 10:14 pm

No problem, yeah, i'm just brainstorming on this.

I was thinking then that should appear in the security logs. That makes it very difficult for me to think what it is. The only way i can think that that would work if it is host side - which is extremely, extremely unlikely if not impossible. Are you sure all founder logins are monitored in the security log?

~ Tilum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 10:19 pm

Yeah,
Everytime DanceJonDance used the founder account it showed a log in with his IP.

DanceJonDance gave me a changed password for the account last night, so I have only used it the one time. I changed the email address to my own because he thought the problem was on his end. I also changed the password. So i had basically taken the founder account from him in an effort to stop this. (Every log in i made was logged).

Then like i said i woke up this morning and it was taken again.

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 10:24 pm

Very strange. Do your entries to the admin panel appear in the log too? Is it just you two as admins.

~ Tilum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 10:28 pm

All our admins entries appear each time we log in.

We have 4 active admins, last night we decided to demote all admins except myself and the founder account to see if the problem would stop which it didn't.


The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 10:43 pm

Can i suggest you demote all admins but the founder, then make the founder have a really strong password.

~ Tilum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 10:44 pm

And just see what happens?

We kinda need the admin accounts so this cant be a permanent thing.

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 10:46 pm

Yes, but we need to find out what is happening.

~ Tilum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 10:50 pm

Ok no worries. I'll get that organized and keep you updated on anything that happens. Is there any way i can contact you other than posting here?

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by Tilum on December 9th 2010, 10:53 pm

Sure, i will PM you my email address. I will check them periodically tomorrow.

~ Tilum

Tilum
Active Poster

Male Posts : 1759
Reputation : 62
Location : England.

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 9th 2010, 10:57 pm

Thanks a lot and once again much appreciated.

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

Re: Help Needed on Forum Security

Post by The Detonator on December 10th 2010, 3:28 pm

Well i guess ill give an update on this.

Apparently a fake log in widget was used on our site to steal passwords. Im currently now IP banned from the site and he has somehow got the password to the utilities so its just a big annoyance.

If anyone can help look into this it would be much appreciated.

The Detonator
New Member

Posts : 14
Reputation : 0
Language : English

Back to top Go down

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum