MyBroadband admin security issue, code injection in footer

Yuu

Executive Member
Joined
Apr 3, 2006
Messages
5,259
Phewww, glad you guys are so knowledgeable about how to fix these things.

I thought i said or did something very bad (no, to my knowledge haven't) and uncle RPM disabled my posting :D.

I would send an email to ALL members to change their passwords irrespective of whether they were able to gain access to the database. I know that even if it was a smaller thing that happened, still take precautions.

Thanks HavocXphere - you rock bro :)
 

DrJohnZoidberg

Honorary Master
Joined
Jul 24, 2006
Messages
23,995
Phewww, glad you guys are so knowledgeable about how to fix these things.

I thought i said or did something very bad (no, to my knowledge haven't) and uncle RPM disabled my posting :D.

I would send an email to ALL members to change their passwords irrespective of whether they were able to gain access to the database. I know that even if it was a smaller thing that happened, still take precautions.

Thanks HavocXphere - you rock bro :)

First thing I did when I heard.
 

Kornhub

Blackburn Fan
Joined
Oct 15, 2008
Messages
34,514
Phewww, glad you guys are so knowledgeable about how to fix these things.

I thought i said or did something very bad (no, to my knowledge haven't) and uncle RPM disabled my posting :D.

I would send an email to ALL members to change their passwords irrespective of whether they were able to gain access to the database. I know that even if it was a smaller thing that happened, still take precautions.

Thanks HavocXphere - you rock bro :)

I thought I was banned or something :eek:
 

I.am.Sam

Honorary Master
Joined
Jun 14, 2011
Messages
92,118
is this the end of mybb ?

are they going to take over our lives ?

are there going to be cloned accounts like facebook ?
 

DJ...

Banned
Joined
Jan 24, 2007
Messages
70,287
Well tapatalk said I had the incorrect username or password two days ago even though nothing had changed. I put in my usual mybb details and it logged me in again.

I thought that was rather odd...
 

DrJohnZoidberg

Honorary Master
Joined
Jul 24, 2006
Messages
23,995
I was just worried about the database of PMs. Tons of private information going around there, like ISP account details.
 

Yuu

Executive Member
Joined
Apr 3, 2006
Messages
5,259
I thought I was banned or something :eek:

You better message me when there is competitions again or else..... :O

I was just worried about the database of PMs. Tons of private information going around there, like ISP account details.

So true, am sure his thought about sending everyone an email but we are here to push him to do it sooner rather than later :p.

One good thing is this will let RPM and the techs to strengthen the security :). Isn't this why there is a love/hate war with hackers ;-)
 

Dark Agent

Expert Member
Joined
Nov 30, 2008
Messages
2,312
All I found lately is that when you want to "edit" or "reply with quote" the display ( Chrome) would be very slow not updating the page as if it doing something else with cursor flashing yet if I open the edit or quote links in new page it would work most of the times immediately and I could post the reply or edited changes still before the other original page updated. I then rather closed that page as it seems lost but sometimes if left open after quite a while it would recover. Sometimes I will get a chrome window saying the server is not available when posting. Maybe not related but maybe gives you a clue what happening on our sides.

Also experiencing the same issue as @Seriously you cannot "Reply with Quote". This problem occurred about 3 - 5 days ago if not mistaken or even last week sometime on firefox. Also noticed that sometimes my browser keeps on freezing being on this website (not sure if it is the flash content).

Should we also monitor our email for anything suspicious.
So it was not only me having this issue
I pm rpm yesterday with that issues.

Well tapatalk said I had the incorrect username or password two days ago even though nothing had changed. I put in my usual mybb details and it logged me in again.

I thought that was rather odd...

I was randomly logout, despite the keep signin was ticked.
 
Last edited:

|tera|

Master of Messengers
Joined
Mar 31, 2006
Messages
25,906
I was also logged out of all my devices today, phone, pc's etc.

Was it a system wide security thing initiated by rpm or what gives?
 

rpm

Admin
Staff member
Joined
Jul 22, 2003
Messages
66,740
I was also logged out of all my devices today, phone, pc's etc. Was it a system wide security thing initiated by rpm or what gives?
Nothing from our side. We did most of the work on Thursday and Friday.
 

|tera|

Master of Messengers
Joined
Mar 31, 2006
Messages
25,906
Trying to quote you, but it won't rpm.

I just logged onto my pc at home, it's fine and logged in. I forgot that I don't "remember me" my pc at work, so it's a false alarm. I also remember that I had my Opera Mini open the whole night on my Blackberry, so it might have cleared the cookie for some odd reason, since I always close it and never leave it running.

Sorry for the false alarm.
 

Lucas Buck

Executive Member
Joined
Jun 20, 2005
Messages
5,628
I could not reply in any of the threads since yesterday because the reply box was missing. I changed my password and cleared all history in firefox which sorted out the problem.
 

Scott

Dealer
Joined
Sep 26, 2004
Messages
2,212
When I arrive on the homepage I am logged out, when I click through to a thread and the page loads I am logged in.
 

DJ...

Banned
Joined
Jan 24, 2007
Messages
70,287
When I arrive on the homepage I am logged out, when I click through to a thread and the page loads I am logged in.

There's no login required nor login indication on the main news page. Only the forums to the best of my knowledge...
 

Rocket-Boy

Honorary Master
Joined
Jul 31, 2007
Messages
10,199
Sounds like a similar situation to the one that occurred recently with the ubuntu forums.
They sent a bunch of pm's to other admins though and got further access like that, they also got hold of the db in that instance.
 

marine1

Honorary Master
Joined
Sep 4, 2006
Messages
49,491
Question: so there was an attack. Do you have an ip address of the attacker?
Can we then proceed to trace the attacker?
 
Top