PDA

View Full Version : OK, so my site got hacked... I think? Advice?!


FleaBag
11-05-2008, 08:49 PM
I have a second vB board which I mostly use for testing stuff out... I logged onto it yesterday and found that in some shape or form I've been hacked (http://www.gamerforums.com/). The second time in my 12 years or so online... The last time was an old vB2 v3 Articles vulnerability... This test board however, had few hacks installed.

I've Googled for the names on the page but it doesn't yield many results, it seems my page is the only one online hacked in this way.

All vB URL's redirect to the page you can see in the above link, there is an embedded image - which is not actually a file on the server. I thought the FTP had been hacked but I logged in and all files are unchanged since my last upgrade. I then thought .htaccess had been changed in some way, but this is also unchanged...

ACP stuff works fine... So what's going on here? Where has my site gone?

I don't know if this is a vB issue (by issue I mean I left a door open somewhere, rather than an exploit) or server issue... The page does mention Safe Mode being off.

So if anyone could shed any light on what happened, how I stop it happening again and how I get rid of this trash it would be greatly appreciated!?

Oh and can anyone translate what the text on the page says?

The board is/was running 3.7.3 PL1. Thanks guys!

KW802
11-05-2008, 08:57 PM
Check your templates to see if any of them have been modified (replaced with the HTML you're seeing instead of the usual vB templates). I came across a site that was hacked where several templates were replaced; everything behind the scenes worked but the templates were replaced. Also be sure, after you've recovered to a point where you can go from, to check your phrases & translations to make sure nothing was added. The site I mentioned with the template changes also had a second language added and some phrases altered.

FleaBag
11-05-2008, 09:23 PM
Hi Kevin, thanks for the suggestions...

I must have been tripping last night, as I just tried to log into the ACP and I get the same defaced page on login.php?do=login. So no cookie can be set. :(

KW802
11-05-2008, 09:34 PM
Hi Kevin, thanks for the suggestions...

I must have been tripping last night, as I just tried to log into the ACP and I get the same defaced page on login.php?do=login. So no cookie can be set. :(If you're sure that none of the actual files on the server have been comprimised, then perhaps your admin password has been reset and you're seeing the 'invalid password' error page that has been defaced.

Try resetting your admin password (http://www.vbulletin.com/forum/showpost.php?p=1633161&postcount=3).

Winterworks
11-05-2008, 09:34 PM
Do you have two licenses or just one? It all depends on this.

FleaBag
11-05-2008, 09:44 PM
If you're sure that none of the actual files on the server have been comprimised, then perhaps your admin password has been reset and you're seeing the 'invalid password' error page that has been defaced.

Try resetting your admin password (http://www.vbulletin.com/forum/showpost.php?p=1633161&postcount=3).

Thanks once more. I'll give that a shot now.

EDIT: Kevin I just realised, I need to set up a new account to do this... Which I don't have the ability to do. :(

Do you have two licenses or just one? It all depends on this.

What all depends on this?

Winterworks
11-05-2008, 09:45 PM
Just answer the question and I can help you?

FleaBag
11-05-2008, 09:53 PM
Oh right, I thought you meant there was an issue that only affected licensed boards lol.

Yes it is my friend, and I'm sure I'd be shut down here pretty fast if I didn't. :)

Winterworks
11-05-2008, 09:56 PM
That's not my question :p It was how many licenses do you have?

FleaBag
11-05-2008, 09:59 PM
Oh, right... Sorry I misread the question. I have two at present.

Winterworks
11-05-2008, 10:01 PM
Okay, just making sure.

Check your templates, or even download a new template. He might have accessed that somehow, it happens.

FleaBag
11-05-2008, 10:09 PM
You the vBulletin police? :)

As mentioned I can't access the ACP.

KW802
11-05-2008, 10:11 PM
Check your templates to see if any of them have been modified. ...

Check your templates, or even download a new template. He might have accessed that somehow, it happens.After playing "20 Questions" you offer the same advice as the first response? :confused:


Fleabag: Are you comfortable working directly with the MySQL tables using a tool like myPHPAdmin or similar?

FleaBag
11-05-2008, 10:24 PM
Sure Kevin, I've done a bit of modifying in the past. I'd considered altering the password field directly but I don't know how to encrypt the value adequately.

But to answer the question, yes I can do that. :)

Thanks again by the way, you've come to my rescue in the past on a few occasions, and it's appreciated.

EDIT: OK as an update I managed to use tools.php to reset the style settings and it seems it was indeed altered at the template level. That's fixed at least, but I guess I wiped out any trace of how it was done. There are a lot of weird registrations too...

EDIT 2: I've managed to log in using my old/current admin password. I was greeted by a screen telling me my password is 219 days old and needs to be updated. The screen seemed to refresh when it first loaded.

EDIT 3: Upgraded to latest version... Trying to make sure everything is locked down now. Thanks for the input guys. I just need to work out what happened now.

KW802
11-06-2008, 01:14 AM
Sorry for the delay... I was on the road home from work. If you're still interested in the SQL item, I'll follow up via PM.

The site I got hit with was done via an older version of a certain gallery software application that did not properly check file extensions and a malicious PHP script ended up on the server. It sounds like you got hit with either the same script or something similar.

- Check all of your modified templates. Some of the big ones, like forumhome were easy enough to tell that it got hit but I found out a day later that some others were hit as well. No fast way of doing this other than going into Style Manager, expanding the views, and checking all of the templates that were modified (the ones listed in red).

- Check your languages; when I got hit there was a second language installed that had to be deleted.

- Weird, but also check your "vBulletin is turned off" message. Not only did our templates get changed, but they turned off the site and replaced the 'turned off' message with a copy of the same HTML junk. The result was that even after restoring the templates and restoring access to the admin account, the site was still showing the HTML.

- If you're running a particular gallery app', upgrade it to the latest version. The issue was that files were able to be uploaded with a faked file extension resulting in a PHP file getting uploaded to the server. The vendor's support site also has a script to find suspect files that may have been uploaded.

- If you're not running a particular gallery app', check for other methods where a user may have uploaded a file to your server using some other add-on.

The big thing is really what non-Jelsoft add-ons you might be running to see if any of them may have been the culprit.

terracore
11-07-2008, 02:42 AM
What was the gallery app that caused the problem. I might have the same problem.

FleaBag
02-10-2009, 08:11 PM
Hey KW802, sorry for so long checking back. I forgot about this thread. Until now, when I got hacked all over again x 2. Seriously, why me?

Thanks for the advice last time around, I do have a gallery app on one of the sites but not both. Not sure which one you mean but I don't think it is the problem.

I have few modified templates, but I found nothing suspicious within.

I can't remember now, but I think there may have been a modified language last time. I'll have to check it out again now.

I have a few mods installed, most of which are considered secure I guess, but I will have to review that again.

I think the only thing I didn't have up to date this time around was the latest PL1 of the blog. I hope that isn't the culprit. Silly me.

For anyone who wants to see the damage check the links in my sig. But again seriously, why me? I have nothing to do with this war they speak of. Give me a break.

Now to try and fix this all over again. And at least it's in english this time - now I know who to hate.

Dismounted
02-11-2009, 08:28 AM
I have a few mods installed, most of which are considered secure I guess, but I will have to review that again.
Is there anything that makes you so sure?

FleaBag
02-11-2009, 06:39 PM
I guess because I've had them for years and never heard of any real problems. They only ones installed on both boards (and the only ones on board number 2 full stop) are GAB, Stop the Registration Bots, vBadvanced CMPS, vBSEO, vBSEO Sitemap Generator, vBStopForumSpam and vBulletin Blog.

I'm back in control again now, it seems I was exploited in exactly the same way as last time. I have a feeling they have compromised my WHM, so it's password changes all round.

Anyone know of any good apps to detect keyloggers? I don't wanna download malware by accident. :(

Any idea how I can view logs from WHM or from my server? I've never done logs before.

Dismounted
02-12-2009, 05:16 AM
Anyone know of any good apps to detect keyloggers? I don't wanna download malware by accident. :(
Make sure you have an effective virus scanner and scan your whole system (which do you have currently?).

FleaBag
02-12-2009, 11:30 AM
I run Comodo for security, it hasn't picked anything up. Recently formatted to install Windows 7 so there shouldn't be anything lingering I think.

Realised this is definately a vB issue as my Wordpress sites weren't touched. Still not sure how it's happened though, and I guess it's just going to happen again as I can't find the problem.

FleaBag
02-25-2009, 09:45 AM
Still have no idea how they got in. I don't understand why I seem to be the only vB to get hit? I couldn't find any others hit in the same way last time either.