Forum Admins look here!

Discussion in 'vBulletin' started by melol2, Sep 30, 2006.

  1. #1
    I just wanted to tell all forum admins this simple fact. Do NOT upload forum backup files to the internet! Or atleast rename them! Recently I did a test to see how many people were dumb enough to upload a PHPBB backup file to the internet with the original filename. I whipped up a simple google hack (not going to post here because if you are going to do things like this learn it youself) and found 50 ".sql" files that contained everything that someone SHOULDNT get a hold of. Usually, from the PHPBB admin panel, you do not have access to the passwords of the users. BUT some people dont know that if you make a full backup of the forum, it also has all user passwords in it. They are in the form of an MD5 hash wich is easilly crackable. Using this info I was able to find alot of admin passwords. But I reported the backup files to the administrators because I thought it would be harsh to delete their forum. Anyway this should be a lesson to all site owners. Do NOT post backup files that contain passwords on the internet.
     
    melol2, Sep 30, 2006 IP
  2. MrX

    MrX Well-Known Member

    Messages:
    1,563
    Likes Received:
    77
    Best Answers:
    0
    Trophy Points:
    140
    #2
    Good find!
     
    MrX, Sep 30, 2006 IP
  3. danielbruzual

    danielbruzual Active Member

    Messages:
    906
    Likes Received:
    57
    Best Answers:
    0
    Trophy Points:
    70
    #3
    Glad this isn't phpbb :).

    Anyway, I think that Mr. Hogan would use really complex passwords which wouldn't be easily cracked.
     
    danielbruzual, Sep 30, 2006 IP
  4. MrX

    MrX Well-Known Member

    Messages:
    1,563
    Likes Received:
    77
    Best Answers:
    0
    Trophy Points:
    140
    #4
    I believe vBulletin uses MD5 hashes as well (or SHA-1?).
     
    MrX, Sep 30, 2006 IP
  5. melol2

    melol2 Active Member

    Messages:
    511
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    80
    #5
    Right now MD5 is the most secure password type. But it can be brute forced
     
    melol2, Sep 30, 2006 IP
  6. sawz

    sawz Prominent Member

    Messages:
    8,225
    Likes Received:
    808
    Best Answers:
    0
    Trophy Points:
    360
    #6
    good point melol2, glad i don't use phpbb
     
    sawz, Oct 1, 2006 IP
  7. AnaB

    AnaB Peon

    Messages:
    1,336
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #7
    one of the 101 reasons why VB is better than phpbb ;)
     
    AnaB, Oct 1, 2006 IP
  8. Nida G

    Nida G Peon

    Messages:
    110
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #8
    good point .......I also dont use Phpbb
     
    Nida G, Oct 3, 2006 IP
  9. Will.Spencer

    Will.Spencer NetBuilder

    Messages:
    14,789
    Likes Received:
    1,040
    Best Answers:
    0
    Trophy Points:
    375
    #9
    It seems to me that vBulletin would be equally vulnerable.

    Why these files would be indexed by Google, that's another question.

    Keep your backups out of your production directories -- no matter what forum software you are running. :)
     
    Will.Spencer, Oct 3, 2006 IP
  10. ebooks-max

    ebooks-max Banned

    Messages:
    95
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #10
    Very good point thanks
     
    ebooks-max, Oct 3, 2006 IP
  11. I. Brian

    I. Brian Business consultant

    Messages:
    810
    Likes Received:
    59
    Best Answers:
    1
    Trophy Points:
    145
    #11
    If you could download a vbulletin database, it wouldn't be hard to manually edit the forum admin email address and then reset the password with the new email address. Had to do that before on a couple of my own forums. :)

    In other words, don't upload databases to your public_html folder!
     
    I. Brian, Oct 3, 2006 IP
  12. rockinaway

    rockinaway Guest

    Best Answers:
    0
    #12
    Am I right to say that also phpBB has an automatic back up MOD? SO admins may use this and the back ups just begin piling up in there site folders...
     
    rockinaway, Oct 6, 2006 IP
  13. Brian Kim

    Brian Kim Well-Known Member

    Messages:
    480
    Likes Received:
    33
    Best Answers:
    0
    Trophy Points:
    120
    #13
    great post
     
    Brian Kim, Oct 6, 2006 IP