• IP addresses are NOT logged in this forum so there's no point asking. Please note that this forum is full of homophobes, racists, lunatics, schizophrenics & absolute nut jobs with a smattering of geniuses, Chinese chauvinists, Moderate Muslims and last but not least a couple of "know-it-alls" constantly sprouting their dubious wisdom. If you believe that content generated by unsavory characters might cause you offense PLEASE LEAVE NOW! Sammyboy Admin and Staff are not responsible for your hurt feelings should you choose to read any of the content here.

    The OTHER forum is HERE so please stop asking.

Recent cases of hacking all used the same exploit...

TopSage

Alfrescian
Loyal
Joined
Feb 13, 2011
Messages
798
Points
0
both done through SQL Injection which is quite simple.

These web masters of the hacked site fail to upgrade their software to
close a long standing bug.

The hacks are done via a 2 step process:

1. SQL Injection Scanners such as SQLIer – SQLIer takes a vulnerable URL and attempts to determine all the necessary information to exploit the SQL Injection vulnerability by itself, requiring no user interaction at all.

2. Once the SQL vulnerability is found it is a matter of injecting malicious code into the system.
 
That's what happens when sites are built using open source software. If you don't stay on top of the revision upgrades and patches, the site becomes vulnerable very quickly as information regarding the security hole spreads like wildfire.

I made the same mistake at the beginning and started a couple of forums using SMF in order to save money. They were hacked within months and it taught me a valuable lesson.

Even vbulletin add ons and plug ins can contain vulnerable code.
 
Back
Top