PDA

View Full Version : vbulletin 4.1.4 defaced using DBOL SQL


ebp123
01-16-2012, 09:40 PM
Im running vbulletin 4.1.4 ....My forum www.growboxforum.com was recently defaced using a program called DBOL...This has happened to me twice from not keeping the security patches updated on my forum....LESSON LEARNED!!

All my files are still intact from what I can tell, so i'm confident its just a matter of removing some files to restore the forum. The defacement was trying to get me to sign up and pay for a security website called privacyharbor.com.

I'm sure this has happened to other people besides me. I do not have a recent backup! If anyone knows how to fix this issue I would be extremely grateful.

Thanks

HMBeaty
01-16-2012, 09:52 PM
Well, your AdminCP to still work. (http://www.growboxforum.com/admincp/) Have you checked your templates to see if any of them need reverted?

--------------- Added 1326754514 at 1326754514 ---------------

Your forums still work too (http://www.growboxforum.com/search.php?do=getdaily&contenttype=vBForum_Post)

ebp123
01-16-2012, 10:15 PM
To be honest, i built the forum up myself and it did not take very much knowledge to do so. Im still rather clueless. Not sure what to check in the admincp. I do know how to navigate it so if you could elaborate i would be very grateful for your time and help

HMBeaty
01-16-2012, 10:32 PM
Well, for 1, check your FORUMHOME template. See if that's been tampered with and needs reverting.

Also, check your .htaccess file and see if that's been tampered with. Same thing goes if you have an index.html file on your server.

Have you already reuploaded all default vB files?

ebp123
01-16-2012, 11:46 PM
Ok thanks for that info. I have not done anything with the default vb files. I understand I would have to go to my webserver and replace a folder?

HMBeaty
01-17-2012, 01:01 AM
Here, see this post by Wayne Luke

https://www.vbulletin.com/forum/showthread.php/393317-Site-Hacked?p=2246345&viewfull=1#post2246345