XenForo 2.0 Outgoing Email (hacked)?!?

Soul02

Active member
Registered
Joined
Aug 24, 2021
Messages
35
Points
8

Reputation:

Hey guys, so just got an email from my host: (webspace sending emails attacked) and so they stopped all emails as a security measure.

I usually get around 100/150 new members a day, just woke up and I got 6 throughout the night, LOL. Because the emails are disabled, so this is a matter of importance to me. Can someone help, please? I have checked through things and this guy somehow got into my site and is able to send emails.

The host said 100 attempts were made, and all from a German IP. Now my email is ([email protected]) all of this guy's emails were like this:

Sender: admin+02d2222b+marcellotheo99=[email protected], admin+8f13edb4+frankcastle0616=[email protected], admin+d7ef4223+vergeefjehetme=[email protected], admin+6cd686b9+gullisiggi=[email protected], admin+c57e37f2+linus.theodor=[email protected], admin+202fca5e+polehead9313247=[email protected], admin+cee27b6f+luinoh12=[email protected], admin+e65552c5+xboxhelpassistant225=[email protected], admin+72bcdc2b+tornados1000=[email protected], admin+628a25ee+davie.8760=[email protected]
Changing my real site name to (mysite.net) of course.

Any idea how I can find this guy and fix it? or make it more secure? thanks.

Edit: Found more, looks like he got into my JS folder:

Screenshot_1.png


That isn't me from the 7th, 8th, and 9th of June, definitely not. The files above which he added are here (download) there is no sensitive information don't worry.

So how can I fix this, please?

Edit 2: I think the files above in the JS folder are wrong, they are made because I use (AdBlock) and that creates the JS needed in there. Please confirm if I am right? thanks
 
Last edited:

Soul02

Active member
Registered
Joined
Aug 24, 2021
Messages
35
Points
8

Reputation:

Anyone? - this is kind of important so :(
 

MEGAHERZ

Collaborate
Collaborate
Registered
Joined
Mar 16, 2019
Messages
50
Points
38

Reputation:

Deleted

Soul02

Active member
Registered
Joined
Aug 24, 2021
Messages
35
Points
8

Reputation:

honestly if you have a little bit of money id buy a email host on namecheap https://www.namecheap.com/hosting/email/ its like 1$ a month or 11$ a year more protection information here https://www.namecheap.com/security/anti-spam-protection/ and they also have a friendly live support chat if you need help setting it up with Xenforo.
MEGAHERZYea seems my email host was crap and too insecure, I have since cleaned stuff up and changed email host, and now it's all sorted. Thanks :)
 
Top