XF 1.5 Third time who i 'am hacked ...

Sc0rps

Active member
Hello all ,

today is the third time who i got hacked .... my forum got hacked every time who i restaure it ...! all my add on is payed ... ma license is 100% authentique and have 7 month more to renew it ...

i really dont know what to do ... i restaured it one week ago and now , i got hackd again ...

here is my forum : https://virtual-gaming.fr/

i afraid to finish to regret that i came to xenforo ..

if someone can help me , thanks alot
 

Sc0rps

Active member
people asked me about X add on , that here have fail ..
 
Last edited by a moderator:

Sc0rps

Active member
someone have advice how i can secure my forum for all deface ? ... all my add on and all is authentique ... nothing is nulled ..
 

tenants

Well-known member
Uninstall all addons and third parties, and identify the issue

I have seen security issues in addons in the past, I have pointed them out and they have gotten fixed. You need to track down the issue, it does not matter if they are not nulled, authentic addons can/will have security issues, particularly when written by inexperienced devs that are just learning the ropes

xenforo take no responsibility for addons, xenforo do not develop or maintain other peoples addons, you purchase / use these at your own risk
 

Brogan

XenForo moderator
Staff member
As I said in the ticket, the vast majority of cases we have dealt with have been due to password re-use or insecure servers/other software (e.g. WP) installed on the server.

A competent sysadmin should be able to investigate and discover how they gained access.
 

Sc0rps

Active member
thanks for the advice bro , but anyone have access and all add on came from xenforo.com ..
 

Sc0rps

Active member
and can i get help here from someone who is competent ? ... it can be very nice if someone can check for me about faill ..
 

Sc0rps

Active member
it was only my best friend (who is like my brother) . but now i changed all but am sure that i will be hacked again ... :(

here is my forum : www.virtual-gaming.fr

someone can check and see if here a secure problem ...

thanks alot
 

Optic

Well-known member
You really need to check logs to find the source of entry and see if your account or your "best friend's" account was compromised.

In XF check admin logs and moderator logs (any suspicious template edits/activity?)
/admin.php?logs/admin
/admin.php?logs/moderator

If that looks OK you also need to check server level logs (if there is SSH/root access - who last logged in? Was it a different IP than what they normally have? When did they log in, what did they change, etc.) Maybe there is a backdoor on your server. If you don't know how to do this you need to escalate to your host / a sysadmin to investigate closely.
 

Sc0rps

Active member
But the problem is when i got defaced ... i can't access to my panel to check cause all had been hacked ...
so idk how we should check of this ..

i think i have a virus on ftp or on the mysql injected ... :(

anyone can help me to fix this ? ..
 
Last edited:

Optic

Well-known member
Sorry, I'm not a sysadmin.. you are paying your host for support yes? They would be the best ones to ask.
 

whynot

Well-known member
But the problem is when i got defaced ... i can't access to my panel to check cause all had been hacked ...
It means that your hosting account is accessed by someone not only your forum.
How can they do it?
Tayhay gave you the clue: br....
 
Top