Home Private Messages Search
CPG Dragonfly™ CMS Dedicated Server & Bandwidth Sponsored by DedicatedNOW
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security ⇒ Several members suddenly un-suspended?


Several members suddenly un-suspended?
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2, 3, 4  Next
Post new topic    Reply to topic    Printer Friendly Page     Forum Index ⇒  Security

View previous topic :: View next topic  
Author Message
MajorHeadache
Supporter
Supporter

Offline Offline
Joined: Mar 05, 2005
Posts: 263
Location: My Little Pony Arena
PostPosted: Fri Sep 16, 2005 1:36 am
Post subject: Several members suddenly un-suspended?

I am currently on DF 9.0.3.0 just about to upgrade. In the meantime, today 3 or banned members were suddenly unbanned. They appeared to be targeted because they are the most notorious banned users, not just random. There are no new admins.

Are there any known hacks to accomplish this, or would someone have to be logged in as admin to do it?

Are there any IP records of admins? I'm running IP Tracker, but it seems to register their regular username, not their Admin login name.

Any other thoughts on preventing or tracking this?


MajorHeadache's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Redhat Enterprise 4/Apache 2.2/MySQL 4.1.22/PHP 5/CPG 9.1.2.1
Back to top
View user's profile Visit poster's website
robertall
Heavy poster
Heavy poster

Offline Offline
Joined: Jul 07, 2005
Posts: 181
Location: spreadkmeleon.com
PostPosted: Sat Sep 17, 2005 4:39 pm
Post subject: Re: Several Members Suddenly Unbanned?

In old versions, there is a bigger chance of being hacked, i would recommend upgrading to 9.0.6.1, and then ban those members again.

_________________
www.teenout.com
www.spreadkmeleon.com
www.host-me-free.com <free image hosting>www.imagecamel.com

robertall's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
FreeBSD/1.3.33 (Unix)/4.1.13-log/4.4.0+5.0.4(Using 4.4.0)/9.0.5.0 for teenout.com
Back to top
View user's profile Visit poster's website AIM Address MSN Messenger
MajorHeadache
Supporter
Supporter

Offline Offline
Joined: Mar 05, 2005
Posts: 263
Location: My Little Pony Arena
PostPosted: Mon Oct 10, 2005 6:44 pm
Post subject: Re: Several Members Suddenly Unbanned?

OK, this is still happening, and I have some new info.

1. I upgraded to the current version, 9.0.6.1

2. I removed all admins except myself.

3. I have IP_Tracker installed and working and when I checked who was in my admin, there was only me, except in one instance my IP was listed as 0.0.0.0 but the host name was still mine.

It is consistently the same 3 users and it happens two or three times a week. I changed all of their emails to my email address so they can't retrieve their passwords or get the email that they are banned yet again. They are the 3 most notorious banned members, and the ones that are commonly known to be banned. How can this be happening?

_________________
My Little Pony Arena

MajorHeadache's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Redhat Enterprise 4/Apache 2.2/MySQL 4.1.22/PHP 5/CPG 9.1.2.1
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Tue Oct 11, 2005 10:57 am
Post subject: Re: Several Members Suddenly Unbanned?

Banning only applies to forums - suspension is required for the overall site.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
MajorHeadache
Supporter
Supporter

Offline Offline
Joined: Mar 05, 2005
Posts: 263
Location: My Little Pony Arena
PostPosted: Tue Oct 11, 2005 4:33 pm
Post subject: Re: Several Members Suddenly Unbanned?

Yes, you're right, I was using the wrong terminology. I have been "suspending" them, and they will consistently become unsuspended.

(However, even if I was banning them, I would expect their status to "stick".)

_________________
My Little Pony Arena

MajorHeadache's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Redhat Enterprise 4/Apache 2.2/MySQL 4.1.22/PHP 5/CPG 9.1.2.1
Back to top
View user's profile Visit poster's website
spacebar
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Sep 28, 2005
Posts: 413
Location: Providence
PostPosted: Tue Oct 11, 2005 5:19 pm
Post subject: Re: Several Members Suddenly Unbanned?

Could it be the computer you are working on? Can you be sure you do not have any malware on your machine?

_________________


spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
Back to top
View user's profile Visit poster's website ICQ Number AIM Address MSN Messenger Yahoo Messenger
MajorHeadache
Supporter
Supporter

Offline Offline
Joined: Mar 05, 2005
Posts: 263
Location: My Little Pony Arena
PostPosted: Tue Oct 11, 2005 5:25 pm
Post subject: Re: Several Members Suddenly Unbanned?

Besides runnign Norton AV, I just scanned it with spysweeper and ad-aware, and am running spyware blaster. Nothing is coming up.

_________________
My Little Pony Arena

MajorHeadache's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Redhat Enterprise 4/Apache 2.2/MySQL 4.1.22/PHP 5/CPG 9.1.2.1
Back to top
View user's profile Visit poster's website
Beldak
Nice poster
Nice poster

Offline Offline
Joined: Jun 15, 2005
Posts: 78
Location: Edwards AFB, CA
PostPosted: Tue Oct 11, 2005 5:48 pm
Post subject: Re: Several Members Suddenly Unbanned?

I had the same thing happen to me but I can confirm it was nothing malicious and instead a possible bug.

I had 13 users suspended, and I went and unsuspended one user who returned to wanting to use the board. When I unsuspended him, it unsuspended several other folks with him and had to re-suspend them.

Wish I had more details, but something in the unsuspend code is not selecting the right users with the mysql grab. I can't figure out the code, but thinking that the admin/modules/users_susdel.inc is likely candidate.


Beldak's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.32 / Apache 1.3.37 / MySQL 5.0.16 / PHP 5.2.2 / Dragonfly CVS
Back to top
View user's profile Visit poster's website
MajorHeadache
Supporter
Supporter

Offline Offline
Joined: Mar 05, 2005
Posts: 263
Location: My Little Pony Arena
PostPosted: Tue Oct 11, 2005 6:07 pm
Post subject: Re: Several Members Suddenly Unbanned?

Well, I haven't been able to pin this to any action on my part but I'll keep an eye on it. Strange that it's only these three and never any others. I know it's not when I'm unsuspending someone else because I haven't done that at all.

_________________
My Little Pony Arena

MajorHeadache's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Redhat Enterprise 4/Apache 2.2/MySQL 4.1.22/PHP 5/CPG 9.1.2.1
Back to top
View user's profile Visit poster's website
MrPotatoes
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Apr 23, 2005
Posts: 403
Location: Florida
PostPosted: Tue Oct 11, 2005 7:39 pm
Post subject: Re: Several Members Suddenly Unbanned?

go into the SQL tables and change thier names to something else. then ban thier IPs in your htacess file in the root directory and they won't even be able to goto the site at all.

but i have to ask. what are they doing? is it just being really annoying all the time or something?

_________________
i'm just that sweet

MrPotatoes's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Windows XP | P4HT 3.4| 1.5GB RAM | 256 Vid Card PCIX | Apache2.0.52 | MySQL 1.4.8 | PHP 4.3.10 | 9.03
Back to top
View user's profile Visit poster's website
MajorHeadache
Supporter
Supporter

Offline Offline
Joined: Mar 05, 2005
Posts: 263
Location: My Little Pony Arena
PostPosted: Tue Oct 11, 2005 10:24 pm
Post subject: Re: Several Members Suddenly Unbanned?

I thought about these things...

If I change their names, then they could theoretically sign up again with their original names. They all have dynamic IPs too.

They were each suspended for different reasons, being rude, or scamming other members. As far as I know, none of them has used the window while their account is unsuspended to do anything, but two of them hold major grudges, and one is a wannabe hacker.

My thing is, A. How is this happening? B. Why these three? C. Is there a security flaw, or what?

I'd really like to get to the bottom of this.

_________________
My Little Pony Arena

MajorHeadache's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Redhat Enterprise 4/Apache 2.2/MySQL 4.1.22/PHP 5/CPG 9.1.2.1
Back to top
View user's profile Visit poster's website
MrPotatoes
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Apr 23, 2005
Posts: 403
Location: Florida
PostPosted: Wed Oct 12, 2005 12:02 am
Post subject: Re: Several Members Suddenly Unbanned?

if you do a whois on those members call thier ISP and tell them about the things that they are doing. make sure to get the managers' name and have proof on hand of what they have done. other than that i'm not a security expert on DF (der)

_________________
i'm just that sweet

MrPotatoes's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Windows XP | P4HT 3.4| 1.5GB RAM | 256 Vid Card PCIX | Apache2.0.52 | MySQL 1.4.8 | PHP 4.3.10 | 9.03
Back to top
View user's profile Visit poster's website
MajorHeadache
Supporter
Supporter

Offline Offline
Joined: Mar 05, 2005
Posts: 263
Location: My Little Pony Arena
PostPosted: Fri Oct 21, 2005 3:57 am
Post subject: Re: Several Members Suddenly Unbanned?

This is still happening. We recently suspended one of the member's friends and they were unsuspended a short time later. We have over 35 other suspended members who never become unsuspended, only those related to these 3. I even changed one members username and they still got unsuspended.

If I was going to look at IP_Tracker for evidence, what should I look for?

The fact that this thread has been ignored by any site admins makes me wonder... Do you imagine I'm somehow doing it wrong? Do you think it it's an inside job? Is suspending members not important? Or is it just a matter of this not being as important as the many other things you're all dealing with? Whatever the reason, I'll understand, but I'd really like SOME kind of response on what I feel is a serious issue when it comes to adminning a site.

_________________
My Little Pony Arena

MajorHeadache's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Redhat Enterprise 4/Apache 2.2/MySQL 4.1.22/PHP 5/CPG 9.1.2.1
Back to top
View user's profile Visit poster's website
spacebar
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Sep 28, 2005
Posts: 413
Location: Providence
PostPosted: Fri Oct 21, 2005 2:56 pm
Post subject: Re: Several Members Suddenly Unbanned?

You're going to have to start debugging by the process of elimination.

I would first thing is to take away the member option from any other admins on your site. You become the only admin capable of suspending / unsuspending a user.

Then... wait.

Or if you don't want to do that, I would suggest breaking the piece of code that unsuspends a user.

In \admin\modules\users.php go to line 89.

PHP:
echo '<tr><td colspan="4"><input type="hidden" name="susdel" value="restoreUser" /><input type="submit" value="'._RESTORE.'" /></td></tr>';

change it to something like:

PHP:
echo '<tr><td colspan="4"><input type="hidden" name="susdel" value="BUSTED" /><input type="submit" value="'._RESTORE.'" /></td></tr>';

With a little time the folling code could be put after line 81 in \admin\modules\users.php.

PHP:

$userinadmin
=& $CLASS['member']->members[is_user()];
$header = "From the User Admin";
$mailto = "YOURNAME@YOURSITE.com";
$subject = "Person in User Admin";
$message = $userinadmin['username'] . " is in the user admin area of the admin.php users script.";
mail ($mailto,$subject,$message,$header);

I tested the above code and it works and used apart from the other options mentioned might help you catch the insider doing the unsuspending if there is such a person. Be sure to change $mailto = "YOURNAME@YOURSITE.com";
to your proper email address.

_________________


spacebar's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Unix / 2.0.46 (Red Hat) / 0.9.7a / 4.1.9-standard / 4.3.2 / 9.0.6.1
Back to top
View user's profile Visit poster's website ICQ Number AIM Address MSN Messenger Yahoo Messenger
MajorHeadache
Supporter
Supporter

Offline Offline
Joined: Mar 05, 2005
Posts: 263
Location: My Little Pony Arena
PostPosted: Fri Oct 21, 2005 5:41 pm
Post subject: Re: Several Members Suddenly Unbanned?

I did try the first thing, and it still happened. I will definitely implement the hack.

_________________
My Little Pony Arena

MajorHeadache's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Redhat Enterprise 4/Apache 2.2/MySQL 4.1.22/PHP 5/CPG 9.1.2.1
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic    Reply to topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 4
All times are GMT
Go to page 1, 2, 3, 4  Next



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

читај повеќе...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy