PDA

View Full Version : Really Phishing Problems in vb 4.1


temsamane
03-10-2012, 08:07 PM
Every time i see files added to my vb forum

files like:

lolz.php
B4nk0f4mer1ca.zip
brb11_9300.php

When i delete these files, it takes 5, 6 hours and they returns.

i searched, scanned, investigated every single file in Vbulletin folders, but i cant find some suspicious phishing file. I asked the host, but they advice me to look again all scripts with a developer.

Is there some one who can help me? because i dont know what to do now! And google is giving me a warning every day.

ps: i have only a vb forum on my server.

slammz
03-11-2012, 06:22 PM
Well, there possibly might be an exploit in your vBulletin. They are probably uploading shells and download your files and dumping your database. What version are you on?

temsamane
03-11-2012, 10:38 PM
Well, there possibly might be an exploit in your vBulletin. They are probably uploading shells and download your files and dumping your database. What version are you on?

i have the last version of vb4 slammz

setishock
03-12-2012, 02:18 AM
I see you have a few mods installed. Not saying all mods are bad but some can punch holes in your security. Need to check on those.
Check server logs to see how they are getting in and where they go once they do get in.
Check your htaccess file to make sure the back end of the software is protected.
Check to be sure you have html posting turned off for all usergroups.
Even if on a dedicated server or vpn, you have to have the same security set in place as if you were on the wildest shared hosting you could imagine.