vForums Support > vForums :: Support :: > URGENT HELP PLEASE

URGENT HELP PLEASE - Posted By heather (heather) on 12th Nov 08 at 11:14am
Forum URL:
Experienced By:
Browser:
Operating System:

Problem:

Hi there I have circle of friends on here and, one of my admins account has been hacked into over night and the said person has sent messages to my members causing trouble, she would of gained acces to my admins personal messages etc and I need to know how she did this and how to ban them etc. please help!!! Heather xx

Re: URGENT HELP PLEASE - Posted By Ross (admin) on 12th Nov 08 at 11:24am
Hi Heather,

Do you still have access to your account on there then?

Do these PMs still exist? If not can you tell me some things what their subject and/or content was. Even if they've been deleted I'll be able to lookup the IP address of who sent them.

Re: URGENT HELP PLEASE - Posted By heather (heather) on 12th Nov 08 at 11:45am
The said person was called Sophi and her user name was shinycandi, she went into hels account somehow and PM'd all members with an email from another forum that her and I were in conflict over, she is a nasty piece of work, but I cant understand how she got access to Hels account{Confused} Also Celine (username cm1e) has been deleted and I have blocked there IP addresses, but I need to know what kind of damage can the pair of the do as obviously they now have personal info of us!!! Surely this is a police matter now?

Re: URGENT HELP PLEASE - Posted By Ross (admin) on 12th Nov 08 at 12:17pm
 
The said person was called Sophi and her user name was shinycandi, she went into hels account somehow and PM'd all members with an email from another forum that her and I were in conflict over, she is a nasty piece of work, but I cant understand how she got access to Hels account{Confused} Also Celine (username cm1e) has been deleted and I have blocked there IP addresses, but I need to know what kind of damage can the pair of the do as obviously they now have personal info of us!!! Surely this is a police matter now?


So does hels still have access to her account? I've been looking at numerous IP numbers which isn't helped by the fact that hels seems to have a dynamic IP address (it changes every time she connects to the Internet).

Looking at the private messages sent from hels account, none seem to match the description of being trouble making. Do we have any other details such as the subject of the message or who it was sent to?

I've also looked up the IP addresses associated with both cm1e and shinycandy (note, the last IP shinycandy logged in with was (pm me if you didn't copy it already) - different to the one you have banned). Neither of their IPs are associated with any PMs sent from hels account.

As for the final question regarding how. There are only two ways that someone can get access to someone elses account.
1, Guess the password (known as cracking)
2, Use the same computer. Particularly if a public computer is used and you don't log out then someone can come along behind you and have full access to your account.

Re: URGENT HELP PLEASE - Posted By Sven (sven) on 12th Nov 08 at 12:20pm
Psst, Ross, a tip. Censor the IP address {Wink} Kindda rude posting it for the whole world to see. Just a point I'm going to point out as it IS in your privacy policy.

(I really don't care, but others will. Just some heads up)

Re: URGENT HELP PLEASE - Posted By heather (heather) on 12th Nov 08 at 12:21pm
Even if you don't percieve these messages as causing trouble WE do hun and the fct the this person has been able to hack into Hels account and read her private info and then send a PM to most members making it look as if it were hels is just awful. And the subject is me, it is me she is attacking and I need to know how to prevent this!!! And can everyone have a dynamic IP address. And how do we stop this happening in the future Ross>

Re: URGENT HELP PLEASE - Posted By Ross (admin) on 12th Nov 08 at 12:27pm
 
Even if you don't percieve these messages as causing trouble WE do hun and the fct the this person has been able to hack into Hels account and read her private info and then send a PM to most members making it look as if it were hels is just awful. And the subject is me, it is me she is attacking and I need to know how to prevent this!!! And can everyone have a dynamic IP address. And how do we stop this happening in the future Ross>


What I'm saying is that I'm having trouble telling which messages are the troublesome ones, sent by someone other than hels. She has sent a lot of messages and I'm trying to tell which one(s) you are referring to. By subject, I mean the title of the message. Or even the link to it if it still exists?

Re: URGENT HELP PLEASE - Posted By Ross (admin) on 12th Nov 08 at 12:28pm
 
Psst, Ross, a tip. Censor the IP address {Wink} Kindda rude posting it for the whole world to see. Just a point I'm going to point out as it IS in your privacy policy.

(I really don't care, but others will. Just some heads up)


I intended to censor it the whole time, just once Heather had seen it {Wink}

Re: URGENT HELP PLEASE - Posted By heather (heather) on 12th Nov 08 at 12:28pm
I have had to ban Celine who was an admin today, would sophi of been able to access celines password and somehow gain access to hels account that way?

Re: URGENT HELP PLEASE - Posted By heather (heather) on 12th Nov 08 at 12:32pm
subtitle for the message was "oh good god"

Re: URGENT HELP PLEASE - Posted By Ross (admin) on 12th Nov 08 at 12:41pm
OK, I've found the message, would you like it removed from being able to be seen by anyone other than you and hels? The IP it was posted by has been used many times in the past by the user with the username "loz". However it is an AOL IP address so there has to be a level of uncertainty, AOL often uses dynamic IPs which means that it could be a coincidence that the same IP has been used by both loz and the "cracker".

Re: URGENT HELP PLEASE - Posted By heather (heather) on 12th Nov 08 at 1:02pm
i am confused as Loz deleted herself weeks and weeks ago.

Re: URGENT HELP PLEASE - Posted By Ross (admin) on 12th Nov 08 at 1:11pm
 
i am confused as Loz deleted herself weeks and weeks ago.


Like I say, it could just be a weird coincidence. But there are 14 records in the security log of actions performed by loz from that IP address. Other than that and these 3 PMs, the IP address does not appear in any other records.

Re: URGENT HELP PLEASE - Posted By Ross (admin) on 12th Nov 08 at 1:27pm
I've been widening the search across the entire vForums network. You mentioned a conflict over another forum, was this one on the vForums network (if so can you PM me the URL). I ask as the IP seems to have been used for regular access to 2 other forums.

Re: URGENT HELP PLEASE - Posted By heather (heather) on 12th Nov 08 at 1:33pm
sorry when I say another forum I mean website and it is www.babycentre.co.uk ( ihave reported her to the community manager on there)

When were the latest activity from Loz's IP address on my forum? And can you tell me when this mail was sent from Hels account? Can we tell who else was online at that time? Also I have spoken to Hels and there is no way anyone would know her password etc so that leaves us to how this has happened!!!

When a member deletes herself why dont the admins or at least me get notification etc

Re: URGENT HELP PLEASE - Posted By heather (heather) on 12th Nov 08 at 1:34pm
I need to also know how long this person was online last night as Hels private info was used and also we have a secret santa thing going on and everyones personal details were on the forum, and it is possible this bitch has access to it, and if that is the case I will be contacting the police!!!!

Re: URGENT HELP PLEASE - Posted By heather (heather) on 12th Nov 08 at 1:35pm
what other forums, can you tell me or PM them Ross?

Re: URGENT HELP PLEASE - Posted By Ross (admin) on 12th Nov 08 at 1:41pm
 
sorry when I say another forum I mean website and it is www.babycentre.co.uk ( ihave reported her to the community manager on there)

When were the latest activity from Loz's IP address on my forum? And can you tell me when this mail was sent from Hels account? Can we tell who else was online at that time? Also I have spoken to Hels and there is no way anyone would know her password etc so that leaves us to how this has happened!!!


I'm downloading the entire access log from the last month. That'll probably take at least another 20 minutes. Once that is downloaded I'll try and track down exactly what that IP has done on your forum and when.

Quote:
When a member deletes herself why dont the admins or at least me get notification etc


When any action like that takes place a record is stored in the security log (in your admin panel).