Support Forums

Full Version: MyBB Flaw or ?
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Hello Support Forum users.Well me and my friend started this project about a marketplace called AnarchyZone.Well all went good in the past 2-3 weeks when he suddenly started to do crap stuff.It's coz i removed his admin and i appointed another member.Then he knew the database pass and i think that was why he was putting himself admin.Well then yesterday i was trolling him and asking him why he did and how he did this he said he made a usergroup same as Registered but using macedonian "e" which is the same as english "е", and that he copied Admin privilegies.Yesterday i cought him tryin to make another Super Administrator usergroup with same thing as the last.I deleted the group and banned him.Vorfin tried to help me with the problem also Smed and they both said that it's the Mybb database password.I changed the user password with the database and i challenged him yesterday to do it and he did it again.
At first he was lying me about somekind of 0day exploit about Mybb and i said try it on hackforums ( i knew he was lying ) then he said it's patched or some crap.

Please can anyone help me with this problem?
Suggest what can i do please.

My website he: http://www.anarchyzone.ws/
Are you using PHPmyadmin?
Yes im using PHP my admin.
This isn't really related, but are you NoriHF on HF?
Lol probably alot of people here are from HF im noticing because of Omnis new award.
Yes im from HF, but i need to solve this problem AS SOON AS POSSIBLE.
If your running the latest version of MyBB it's very unlikely he is legitimately hacking you.

You should first change your hosting passwords as this is where I suspect the problem is coming from.

Then you should check all your privileged usergroups for additional members, he may have created other accounts before he left.

Finally, follow this tutorial to maximize the security of your forum: http://community.mybboard.net/thread-44977.html
In particular rename the admin directory and .htaccess password protect it.

It may also be an idea to replace all your files with fresh copies in case he had access to the files at any stage and placed some malicious code in there.
The problem was he changed the email from nori-hf@xxxx.com to norl-hf@xxxx.com