
Originally Posted by
NP Carling26
Well, yes, we got hacked. We have put everything back to normal though. We restored to a day old backup, and upgraded from vBulletin 4.1.3 PL1 to 4.1.4 PL2. We believe we were hacked via an exploit that allows for SQL injection, which is what the patch was for, so that is why we were updated. However, one other possibility was that an admin was keylogged, and although we haven't confirmed this yet, it is advised that if any of you used any tool by Relevent, especially including the SB tool Kit, that you uninstall it and run a full system virus scan immediately. The administrator of another website one way or another used a method to hack us, change our index page, steal all the files off of our server, and steal our database. This is why upon reentry to NGU all users and staff will be required to change their passwords. For security purposes, admins passwords, even those who aren't on, have already been changed. The database was put up for sale and supposedly sold, but again, it is useless due to the fact that all user's passwords will be changed. However, PM's may become vulnerable, for it is recommended that if you sent any vulnerable information via PM or VM, that you change any details that could be at risk.
I sincerely apoligize for this guys, and for the downtime, but we wanted to make sure everything was secure again. And rest assured, those parties responsible for this will pay, and although most of you know the website related to it, I DO NOT under any circumstances go to that website and cause shit. We are gonna deal with this in a professional, mature, and legal manner. The only thing any of you guys could do is stir up more shit.
Also, give a big thanks to magglass1 for being on top of the issue, and to Enzo for helping to sort out some of the issues caused by the upgrade.
Thank You for your time and continuing to be loyal, even through all this. -Carling, Enzo, Magglass, and all the other staff at NGU.