3
Hi redheadedrod, thx for the quick reply, firstly I don't think it is a xoops issue, I have several hobby sites for flight sim enthusiasts & other sites constructed for friends all of which use xoops as the core, none of these have ever been 'attacked'.
I have checked some of the passwords used by my clients in an md5 hack tool which unfortunately reveals their passwords correctly, that said the 'attacker' must also have the clients username to be able to log in, this is where I am stumpped.
There are several code snippets that use the core data, I am currently working through these to see if there is any information 'leaks'.
Modules used...
System 2
User Profile 1.57
Smart FAQ 1.08
News 1.64
XForum 5.46
Protector 3.4
Today I will upgrade to the latest version of xoops.
UPDATE:
Installed upto 2.5.4, unfortunately got a white screen after updating everthing, reverting back to 2.4.4 and updating to 2.4.5
Thanks for your interest.