You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 170 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - _UPCHANGE ??? what is this (how worried do I need to be??) [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
tenntrips
Nuke Cadet
Nuke Cadet


Joined: Oct 15, 2004
Posts: 4


PostPosted: Fri Oct 15, 2004 8:08 pm Reply with quoteBack to top

I've received a private message from myself (interesting enough) with the following

Subject _UPCHANGE

Message body
lacy - 24.233.154.97 _HCHANGEP

Is this a hack attempt??

I found the commands on the following page
http://aips2.nrao.edu/docs/reference/System/node91.html#SECTION001285000000000000000
and they appear to have the ability to globally change my files ! ! !

Is this something that is protected against ? ?

Being relatively new, I don't know what this can mean or what it can do.....


Last edited by tenntrips on Fri Oct 22, 2004 8:17 pm; edited 1 time in total
Find all posts by tenntripsView user's profileSend private message
tenntrips
Nuke Cadet
Nuke Cadet


Joined: Oct 15, 2004
Posts: 4


PostPosted: Fri Oct 22, 2004 7:53 pm Reply with quoteBack to top

Is anybody out there?? I'm now receiving MORE of these, and would really like to know what is going on ! ! !
Find all posts by tenntripsView user's profileSend private message
Getyousomeofthis
Sergeant
Sergeant


Joined: Jan 18, 2004
Posts: 128

Location: Tulsa Oklahoma

PostPosted: Fri Oct 22, 2004 8:08 pm Reply with quoteBack to top

There are some vulnerabilities using Private messages . Are you updated with the latest patches?? You should make sure your BBTONuke is upto date version 2.1.0 is the lates build for the forums

_________________
Click Here To Join Our CS:Source Game Server!
[img]http://www.dtsbase.com/files/logo.gif[/img]
Find all posts by GetyousomeofthisView user's profileSend private messageVisit poster's website
tenntrips
Nuke Cadet
Nuke Cadet


Joined: Oct 15, 2004
Posts: 4


PostPosted: Fri Oct 22, 2004 8:20 pm Reply with quoteBack to top

I just looked and I'm on 2.0.5 I won't get a chance to upgrade until next week !!

What will they be able to do with this??

I just disabled Private Messages (don't use them anyway).
Hopefully that will help untill I can get the upgrade done..
Find all posts by tenntripsView user's profileSend private message
Getyousomeofthis
Sergeant
Sergeant


Joined: Jan 18, 2004
Posts: 128

Location: Tulsa Oklahoma

PostPosted: Fri Oct 22, 2004 8:33 pm Reply with quoteBack to top

have you been able to get their IP?? whos Ip was that posted above??

i would suggest tracking their IP and ban it for now untill you get time to upgrade

Hopefully disableing the Module will work .. maybe even change the Private Messages modules folder name so they cant acess it directly incase that is what is going on also

Peace and good luck ..

_________________
Click Here To Join Our CS:Source Game Server!
[img]http://www.dtsbase.com/files/logo.gif[/img]
Find all posts by GetyousomeofthisView user's profileSend private messageVisit poster's website
tenntrips
Nuke Cadet
Nuke Cadet


Joined: Oct 15, 2004
Posts: 4


PostPosted: Mon Oct 25, 2004 8:23 pm Reply with quoteBack to top

Well, deactivating the Private Messages didn't help Sad

Was STILL getting new messages (couldn't see them, but still got them)

Since I don't use that anyway, I just completely removed the module for now.

When deleting I DID FIND that there was a HIDDEN .htaccess file in the Language directory of Private Messages (which I didn't get to look at).

I figured it was better to delete is as quickly as possible just in case one of the little buggers was on line......
Find all posts by tenntripsView user's profileSend private message
Getyousomeofthis
Sergeant
Sergeant


Joined: Jan 18, 2004
Posts: 128

Location: Tulsa Oklahoma

PostPosted: Thu Oct 28, 2004 2:49 am Reply with quoteBack to top

.htaccess files are good security files .. you can set rules in those files to deny users from accessing the files and folders directly .. Deleting those may not be a wise thing to do

peace

_________________
Click Here To Join Our CS:Source Game Server!
[img]http://www.dtsbase.com/files/logo.gif[/img]
Find all posts by GetyousomeofthisView user's profileSend private messageVisit poster's website
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.282 Seconds - 227 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::