View Full Version : HELP!! Hacker keeps hacking site
Jeff G
12-13-2009, 11:37 AM
Don't know how he is doing this & would like help if possible.
Hacker is from Hanoi, Vietnam got me twice so far, used different IP's
He creates a screen name & then he is able to log onto my admincp? How? All permissions are set for new users & the have no admincp access, but he does & give himself admin privileges! & then tosses code for streaming ads into my main forum page.
I have change name of admincp directory to a completely obscure name, is there anything else I can do besides that & ban his IP & email addresses?
Any help would be greatly appreciated.
I have checked all files via FTP & none have been changed, so he is doing this straight thru Vbulletin!!
snakes1100
12-13-2009, 01:09 PM
Well, if you aren't running the latest version of vb then it's not vb's fault, i would suggest you upgrade it and any installed hacks on your site.
Then you need to upgrade your server's backend programs, sql, apache, php etc...
Next on the list would be to remove any other custom scripts mainly php based that you have added to your site, even if they arent vb related.
You should also check your server logs and see if there is any indication that he is doing a db injection.
Install some security while your at it, suhosin/apf etc.
Lynne
12-13-2009, 02:16 PM
Along with making sure vBulletin is up-to-date, make sure all your modifications are up-to-date and don't run any modifications that have been graveyarded (they could have a security flaw in them).
iHatton
12-14-2009, 05:41 PM
Read this, https://vborg.vbsupport.ru/showthread.php?t=220914
motowebmaster
12-15-2009, 01:01 AM
If the respective server has been compromised, it would be easy to "cover your tracks". An FTP program is not going to give you conclusive info.
Share you site's URL with some folks you trust, without that info it's anyone's guess as to what the issue is.
Medtech
12-15-2009, 01:43 AM
There are many ways to secure your forum, renaming the admincp is the first and easiest, i like to have a dummy admincp folder with an index.html file in it with a redirect to a really nasty site or the 404 page.;)
Carnage
12-15-2009, 09:40 AM
put a .htaccess file into the admin cp directory and setup password protected access.
See this: http://davidwalsh.name/password-protect-directory-using-htaccess
Black Tiger
12-16-2009, 02:17 PM
And be sure to use a good host. Not some kid or man who started a hosting company without any experience.
If the hacker keeps coming back, even when you change the admincp directoryname, they can read your config file. Some hosts have not provided decent protection on their servers, and if you know the location of the config file (which is always in /forums/includes with vBulletin) you can read it out via ssh or via a self made php file.
All the hacker needs is an account on the same server.
daveaite
01-03-2010, 12:52 AM
There are many ways to secure your forum, renaming the admincp is the first and easiest, i like to have a dummy admincp folder with an index.html file in it with a redirect to a really nasty site or the 404 page.;)
Haha, this is good stuff
Princeton
01-04-2010, 12:39 PM
if this continues, I suggest hiring someone with a good reputation to check your site
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.