07-22-2021, 01:06 PM
(07-22-2021, 01:02 PM)Littlemaster Wrote: About the dbkiss.php, it seems a database control script, I hope it was not uploaded by any admins to control the sql server through web. I think mybb has some hash to encode the passwords, isn't the passwords are encrypted safely? If the hacker hacked database data, then I think the issue will be with the vps passwords shared through threads as plain text. Between deleting threads seems no enough, in case the hacker hacked the data the hacker could have taken all details all ready or may have a back up. I think vps owners should have a way to replace the passwords of their VPS panels, otherwise they could not change and hacker will have all working passwords.
I guess if it's about VPS password then Post4VPS is not wrong here since admin always ask us to change our password upon receiving the VPS. There may be possible issue where hacker create account with sudo permission but, well, I'm safe here since I always reset the server when receiving the VPS.