View Full Version : My website contiunes to get hacked
daveaite
12-11-2009, 02:12 PM
I have been continually getting hacked over the past month. I've rolled back my server followed
https://vborg.vbsupport.ru/showthread.php?t=193930&highlight=securing+forum
by password protecting:
admincp/
modcp/
includes/
install/
renaming modcp/
admincp/
making myself an undeletable user
-reformatted my pc to prevent any viruses
They either change my index files around and brag about their hacking abilities ot they delete the entire contents of my public_html
----------------
What should I do? I have no clue how they are getting into my system. I've changed the cpanel password a ton of times. Maybe attachments entry?
About them?
Some arabic group
Tips? Help please.
Lynne
12-11-2009, 02:20 PM
Are you on a shared webserver? Have you talked to your host about this? Have you looked at your access_logs to see if anything is in there regarding the hacking?
daveaite
12-11-2009, 02:27 PM
I have talked to my web hosting. I feel like I've been bothering them too much lately by asking them to continually roll it back. It is on a shared hosting which makes me a bit worried, maybe it's time to switch...although I did buy 3 years of hosting.
They actually went ahead and changed the cpanel password for me, and it got defaced the next day.
This may be a coincidence but it started happening after I upgraded to vbulletin 4.0. I know its in beta, and I used to have this mod which now I think prevented this from happening: https://vborg.vbsupport.ru/showthread.php?t=196791&highlight=firewall
Lynne
12-11-2009, 02:40 PM
I doubt they are hacking through v4 but if you look at the access_logs, you could verify that. Shared hosting is not as secure as having your own server. But, I'm no server expert, so I really can't offer much advise here.
abdobasha2004
12-11-2009, 03:48 PM
What should I do? I have no clue how they are getting into my system
it is a possibly a root shell on one of your vbulletin or website files
1- download a backup of your site
2- scan this backup by a powerful anti - virus (for me avira antivirus can do it)
3- your anti virus will detect the shell and will notify you with its path.
4- if you are sure that the file is not important delete it, otherwise open it and remove the shell (most propably coded text) , or just rewrite the file from a clean vbulletin version
5- make sure that there is no other files
best wishes
daveaite
12-11-2009, 07:03 PM
Thanks for the quick feedback. I'll look into the virus scan method.
Matais
12-11-2009, 07:29 PM
you have checked out your end haven't you?
could have a keylogger, spyware etc.
also what version of vbulletin are you on?
Speysider
12-13-2009, 10:36 AM
also what version of vbulletin are you on?
See post #3, he says vBulletin 4 Beta.
Carnage
12-13-2009, 11:13 AM
on shared hosting ensure that config.php is NOT world readable.
In an ftp client you may see options for user, group and other permissions. Turn off all the permissions belonging to 'other'
CarlitoBrigante
12-14-2009, 07:22 PM
There is little doubt you have some backdoor installed in your system, or that you have some modification that works as a back door.
Make also sure, in case you have it installed, that vBSEO is upgraded to the latest package. 3.3.2 release needs to be re-upgraded as there was a security patch a while ago which did not cause a version number change.
Dunhamzzz
12-15-2009, 02:38 PM
Close forum, uninstall all mods, take database dump, Wipe server clean, re-upload a freshly downloaded vb, re-edit config.php, dump SQL, Go.
Attachments will be an issue, may have to sacrifice them unless you move them to the DB.
Anyway, you'll have a fresh vBulletin, with no addons or altered files. If it STILL gets hacked, blame your host or look at your other scripts.
Deimos
12-20-2009, 02:31 PM
I agree with Dunham, it's the only way to be safe
Also make sure any FTP/Control panel passwords are cryptic by using an md5 password generator.
Speysider
12-20-2009, 02:45 PM
Also, rename the admin and mod panel directories as that is what they do. Password Protect them and use strong passwords (let the other admins know).
Make sure you rename the path to admin and mod panels in the config file.
ExplosiveGFX
12-20-2009, 03:17 PM
Everyone has said great stuff, there are other things you can do AFTER being hacked, this article (https://vborg.vbsupport.ru/showthread.php?t=230239) covers a few of those..
daveaite
12-22-2009, 03:21 AM
Thanks I think there are a few new things Dunham has said. However that only works if you have a blank vbulletin to start off with. There are users on my current forum and I rather not lose their information. I've applied alot of the said about and done new stuff elsewhere on the web too. So far no attacks.
I think the biggest thing I did was that I blocked all IPs from the middle-east, asia and Russia. I can do without that traffic since the majority is probably not interested in my site nor english speaking. Of course this is a temporary solution.
Rideharder
12-22-2009, 03:49 AM
I went to the same problems.. here's what I did to fix my problem..
Secunia Personal Software Inspector (PSI)
http://secunia.com/vulnerability_scanning/personal/
and
Malwarebytes' Anti-Malware
http://www.malwarebytes.org/mbam.php
I realized the problem was on my computer..
Wish you the best!
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.