Strange PM

davesnow

Crabby Old Geezer
I got this PM message from user doguscafe. I don't know what it means:


if (&l036;row[&l039;user_id&l039;] != cookies)
&l123;
&l036;sql = &l039;UPDATE &l039; . USERS_TABLE . &l039;
SET user_login_tries = user_login_tries + 1, user_last_login_try = &l039; . time() . &l039;
WHERE user_id = &l039; . &l036;row[&l039;user_id&l039;];
&l036;db->sql_query(&l036;sql);
}

`
 
I recognise that kind of code - it's a mixture of PHP and SQL, both coding languages.

Looking at it, the moderators may need to see that one (and possibly N3V as well) as it appears to be potentially dodgy code.

Shane
 
That's my concern as well. Hopefully either Zec or Cratey can sort it fairly soon (even though it's a weekend in Oz) in case a working version crops up.

Shane
 
Could this be someone specifically targeting this certain forum or would this affect all vBulletin forums?

This is possible if they aren't patched. There have been updates to the forum software, which apparently stopped this one if this was a hack.

I recommend should anyone receive anymore of these PMs, that they report them to the helpdesk immediately.

John
 
Agreed. It's an issue that N3V need to be aware of, in case it's something that's not very well known. It's kind of lucky that my forum is not powered by VBulletin so probably wouldn't be affected by that (although it would soon be caught anyway).

I'm hoping that N3V do post something here regarding this issue, as we have no idea who else may have been sent this, and through other checks, the user has not posted any posts, and does not state a location in their Planet Auran profile.

Shane
 
Dave's been contacted by Aliens :eek:, Quick everybody run for the hills and don't go near him unless you are wearing tin foil wrapped around your head ROFL. Your special now Dave.
Cheers Mick.:hehe:
 
I'm not at my computer right now so I can't forward this PM to anyone
How do we really know this is the real Dave Snow and not the Alien abducted Dave Snow Dave ?. LOL sorry i can't help it Dave.
Cheers Mick.:wave:
 
There appear to have been a couple of attacks elsewhere on vBulletin forums in the last couple of weeks through user accounts. I agree with Shane that code looks decidedly dodgy.
 
That definitely "doggy" code. Forward the PM to Zec Murphy and Cratey.

John

Forwarded to both.


How do we really know this is the real Dave Snow and not the Alien abducted Dave Snow Dave ?. LOL sorry i can't help it Dave.
Cheers Mick.
awave.gif

Aliens wouldn't want an old wore out guy like me! Haha

Cheers,

Dave
 
Back
Top