Jump to content
DevFuse Forums

3.1.4 hacked... started from garage system


mieciu

Recommended Posts

I don't know if that has anything to do with security in a garage system, but attack on my forum, which has caused lot of problem, started from porn spambots adding lot's of vehicles with links.

I lost 40k users in few minutes. These were replaced with 170 bots. ibf_members tabel was restored without any problem, but i didn't have backup of 'uploads' folder. Whole IPGallery and avatars were pruned.

 

Just want you to know, but I'm not blaming anyone. I dont really know if it was security problem with ipb or garage system.

Link to comment
Share on other sites

  • Management

If you can PM me anymore information you have, I'll definitely take a closer look into this. Obviously you never can guarantee something is 100% secure, as someone is always trying to find vulnerabilities but I'm currently not aware of any exploits in IPB 3.1.4 or the Garage. Have you considered a server vulnerability or any other software you have installed on your site?

Link to comment
Share on other sites

  • Management

I could add a captcha for add vehicles but if these bots registered they probably can bypass captcha. If you can use the spam service from IPS, that should cut down a lot of the spam. Also make sure the group permission setting "Vehicles allowed per member?" is not set too high.

 

I've got a few ideas to cut down on spam that I'll implement next version. If you want to try them, open a support ticket and I can provide instructions or apply the changes for you. As for the hacking, I'll need to confirm it's the Garage before doing anything.

Link to comment
Share on other sites

  • 4 weeks later...

I'm presuming for the garage mod you have group permissions feature? If that's the case, you can always set registered members to be able to post there and also enter a challenge question only humans would understand in order to prevent bots from registering.

Edited by Breadfan
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...