Trw hacked

Brian Boston

I got myself banned.
Hey Brian, i forgot my shit again lol.
could you PM me when you see this?
There was no shit to be forgotten last night. Everything was gone.

Right now my host rolled my back to a backup and its backed to being hacked. So pretty much I gotta figure out out how to unhack it because my original theory isn't going to work to fix it. FML
 

Brian Boston

I got myself banned.
Pinpointed that its SQL injection. Can't find out where the code is that is making the page go to the hacked message though...
 

Brian Boston

I got myself banned.
Well I ended up deleting all the tables out of the database cept the ones with user data+forum posts and shit. Now the hacker messages are gone but I can't get vbulletin to install again without SQL errors. Shit is mangled mangs.

edit: made some progress...
 

TomK

Super Moderator
Staff member
This I why I stickied the thread. I love TRW, but this hacking is fucking insanely gay.
 

Brian Boston

I got myself banned.
It's cause they're using PHP and not scuring it right. PHP is easy as hell to hack and inject code into
Its because vBulletin sucks and the same exact thing can happen here too (SRs forums run on the same system but I use vb4 and SR is using vb3). Its some SQL injection through vBulletin they obviously isn't patched and the group of people slamming TRW obviously have the URL on their hit list.

Im going to be looking into options other than fixing the current site like moving away from vbulletin to a different system or moving in with someone else...

edit:i ran the upgrade script which fixed it before but no dice.

editedit: my bad brock on making a new thread i forgot this was here.
 
Top