Announcement

Collapse
No announcement yet.

forum hacked

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • forum hacked

    paypal address has been hacked/changed so new paid subscriptions has been paid to wrong paypal email address.
    im checking the transaction log and when type shows failure i can see the details but if type shows charge i cant see the details.

    i wanna check what hacked paypal address was use.
    is there a way to check this?

    thanks

  • #2
    The paypal email can be seen in your:

    Admin CP -> Paid Subscriptions -> Payment API Manager -> Edit

    The hacker must have entered their email into there if they changed where the payments were sent.

    Comment


    • #3
      yeah but problem is he changed the address and then he changed it back to my paypal. so some payment when to his paypal email address.

      so my question is
      how can i know which payments when to his paypal email address?
      transaction log doesnt show the email .

      Comment


      • #4
        You will need to contact PayPal about that. vB does not log this info.
        Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
        Change CKEditor Colors to Match Style (for 4.1.4 and above)

        Steve Machol Photography


        Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


        Comment


        • #5
          Originally posted by Steve Machol View Post
          You will need to contact PayPal about that. vB does not log this info.
          Just a guess but...

          How would Paypal know where that money went? All they can say is if it went to his account, or not. Right? If it's a transaction that took place on the forum...into a account...shouldn't vB be able to say what account it went into?

          Comment


          • #6
            also if i go to Admin CP -> Paid Subscriptions -> Payment API Manager -> Edit it shows my paypal address but if i go to site/forum/payments.php it shows the hacker paypal addressi have check and subscription.php has been edited



            Last edited by MessiAz; Sat 16th Aug '08, 4:37am.

            Comment


            • #7
              Is anybody concerned about how this site got hacked?

              How is this possible? Is this someone you know?

              Comment


              • #8
                It's probably been changed in the PHP code so instead of using the DB stored value it uses his hard coded value. Try "grep"'ing the vBulletin .php files for his email address.

                Or better yet run the suspect files scanner.

                Since it would seem he had access to the .php files to make the change I would suggest A) you contact your host and tell them that someone was able to gain unauthorized access to the server and B) change ALL your passwords for everything from MySQL to FTP to forum user passwords for any admin/moderator accounts.
                http://data.collectiveirc.net/status/user/Jobe.png

                Comment


                • #9
                  Originally posted by q22inc View Post
                  Just a guess but...

                  How would Paypal know where that money went? All they can say is if it went to his account, or not.
                  PayPal has full records on ALL the payments made through their system.
                  Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
                  Change CKEditor Colors to Match Style (for 4.1.4 and above)

                  Steve Machol Photography


                  Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


                  Comment

                  widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                  Working...
                  X