While surfing through my forum yesterday, a popup appeared alerting me that is has been six months since Vb software has been installed and that I should change my password. It has been about that long so I did it. Woke up this morning to this:
Announcement
Collapse
No announcement yet.
Is this how they hacked my VBulletin?
Collapse
X
-
I am afraid you were duped, vBulletin do not use any pop ups for this purpose,the system for password control is in your ACP,what happens on expiry is that you cannot login to your account till you go through the password renewal process.
NEVER ever respond to any popup till you check it out.
-
-
I think it is coincidence - because the stuff they uploaded can't be done over vB which is a forum software and not ftp. Usually these 'hacks' are done via exploit in source code (which yes, could be vBulletin, and you are running an older version), or unofficial plugins or third party software (like wordpress, etc). Or wrong directory configurations, etc. The host has to trace back and narrow it down.
Comment
-
Originally posted by Floris View PostI am not a developer, but to my knowledge it is per session.
-----------------------
Anyway, assuming you now have control of the forum and server this thread http://www.vbulletin.com/forum/showthread.php?t=194701 will help you protect against hacking.
In particular change the Admin and mod control panel folder names and password protect folders like Install and config on your server .
Always use long passwords for your logins on the server and forum.
Comment
widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
Comment