PDA

View Full Version : vBulletin exploite lost me entire site.


CoryNickerson
12-16-2007, 10:59 PM
This guys like 42 years old and he hes a PHP developer and "hacker" so I'm told. He runs a site about hacking on the side. He knew my friend which led him to me, and since he knows an exploit to vB 3.6.8 he took down the site, deleted all the files to the system, and changed index.php to say "site was pwned by psychomarine".

http://www.enigmagroup.org/forums/index.php/topic,2852.0.html

Theres thread on his forums where hes talking about it. Its just sad to see people behave like this. I'm not sure how to find out what the exploit is or how to fix it, but apparently he can take down any site using vBulletin because its insecure he said.

Any thing we can do about this?

Please help.

nexialys
12-16-2007, 11:25 PM
for direct support relative to your site, you have to go to http://vbulletin.com ...

Kirk Y
12-17-2007, 12:59 AM
What (if any) modifications did you have installed? And what version of vBulletin were you running?

shortbus1662
12-17-2007, 01:14 AM
surely you can sue the guy or press charges of some kind. I'm assuming he's a U.S. citizen living in the U.S....?

Marco van Herwaarden
12-17-2007, 03:07 AM
From your description, i strongly doubt that the hack was done on standard vBulletin. Files missing often means that there was access to the filesystem, something that you will not get with default vB.

If you have any indications that this was done using standard vBulletin, please open a support ticket providing as many details as possible.

Please read the following thread on how to improve security for your board:
http://www.vbulletin.com/forum/showthread.php?t=194701