@William,
William wrote:Would you please tell me what you mean by "hacked again"? What does that mean if you are meaning it was a detriment to the other forum. If I was, I never knew it or noticed it.
Through the VB forum software it was hacked in a way that allowed the hacker to install a script on our server that then connected to a remote server for instructions (it usually will then be used to attack other servers/computers/sites).
The reason it is a detriment to other sites the forum is hosted with (the forum was on the same servers as able2know and some of our mission critical sites) is because it allowed them past our security, they were
in, and dialing
out.
This happened twice with the philforum. I posted about it once on philforum the first time, when I patched the software and removed the exploits (we also moved servers at the same time, together with a2k), but then it happened again and instead of trying to pinpoint what VB code or plugin caused it we decided to kill the hacked software within 24 hours (it actually took us 48 or more to pull off). That many hours is something I already consider completely unacceptable to be hacked but luckily no damage seems to have been done (except that the hack inserted hidden viagra ads that only showed up for google, which you may remember philforum members talking about, as it was also doing that when I got it).
You may remember the album thumbnails being weird, that may have been affected by the hack as they were running a script they uploaded into the album thumbnail directory (/home/phforum/public_html/images/albumthumbnails/0/45d64c50996cd5db3376fe06d521bf26_651.php).
Anyway, we noticed because the server started making a remote connection that was unauthorized, that is a huge red flag for us and one of the few times in my career I've had my servers breached. And like every other time it was due to crappy out-of-box software. This year philforum's vBulletin software was breached in two such instances, sending us scrambling both times. The first time we moved all the sites from The Planet's Houston and Dallas data centers to a Chicago datacenter and worldwide CDN while patching the software (similarly, we had planned to upgrade servers much later but did that instantly because it was a cleaner break with the hack than patching the hacked server and hardening it again). The second time it was "off with his head" time for VB and it had to go ASAP. I chose the option where I only didn't have to sleep for 3 days, anything else was too many more than I could afford.