PDA

View Full Version : We have been hacked as well


Jester1423
09-12-2013, 12:32 PM
Ok guys I need serious help. We were hacked and I was able to delete the Admin accounts the hackers added. Looking at the CP log all they changed was the Notice.php But I have no idea were to go to clean up the mess they made. Any help would be great.

www.jeepasylum.com

--------------- Added 1378993172 at 1378993172 ---------------

I figured it out and feel slightly stupid now. Any suggestions on how they might have been able to add admin accounts and how I can prevent this in the future.

joeychgo
09-12-2013, 01:18 PM
I always recommend forum owners hire Securi (http://affl.sucuri.net). I use them for all my sites. they monitor the sites for intrusions, and track down and repair successful malware / virus attacks on my sites. They have been fantastic for me and they monitor all my sites.



.

teamemmenracing
09-12-2013, 01:23 PM
Ok guys I need serious help. We were hacked and I was able to delete the Admin accounts the hackers added. Looking at the CP log all they changed was the Notice.php But I have no idea were to go to clean up the mess they made. Any help would be great.

www.jeepasylum.com

--------------- Added 1378993172 at 1378993172 ---------------

I figured it out and feel slightly stupid now. Any suggestions on how they might have been able to add admin accounts and how I can prevent this in the future.



You figured it out .....??????
Please tell .... I don't mind feeling stupid at all, Ive been banging my head against the wall all day .....
I had the exact ame hack

cellarius
09-12-2013, 01:30 PM
I always recommend forum owners hire Securi (http://http://affl.sucuri.net). I use them for all my sites. they monitor the sites for intrusions, and track down and repair successful malware / virus attacks on my sites. They have been fantastic for me and they monitor all my sites.
Not a bad tipp. But you might want to
a) fix the link, which is broken (typo)
b) remove the affiliate id. AFAIR that's against forum rules here.

Spangle
09-12-2013, 02:09 PM
Ok guys I need serious help. We were hacked and I was able to delete the Admin accounts the hackers added. Looking at the CP log all they changed was the Notice.php But I have no idea were to go to clean up the mess they made. Any help would be great.

www.jeepasylum.com

--------------- Added 1378993172 at 1378993172 ---------------

I figured it out and feel slightly stupid now. Any suggestions on how they might have been able to add admin accounts and how I can prevent this in the future.

First thing you need to do is delete your install folder if you haven't already.

Then you need to run ACP>Maintenance>Diagnostics>Suspect file versions
That will check your VB install for any suspect files, read all the files carefully, chances are they will have created file with .php extensions, check these are what the system is expecting, if it isn't the check will say something like "expected contents not found".

Then you actually need to check to see what is actually in your public_html file, deleted the suspect files, and look out for any you don't recognise, in my installation I found mail.php, password.php, password.txt.

If you are unsure as to what should be there check your downloads for files that go into the root directory.

Then do a check on all accounts that have admin permissions, if they have an IP address, block that address via IPDeny in your C Panel

Jester1423
09-12-2013, 03:11 PM
These are the only ones I dont recognize

admin_rbs.php
admin_rbs_banner_list.php
admin_rbs_delete.php

xenite
09-12-2013, 11:33 PM
Ok guys I need serious help. We were hacked and I was able to delete the Admin accounts the hackers added. Looking at the CP log all they changed was the Notice.php But I have no idea were to go to clean up the mess they made. Any help would be great.

www.jeepasylum.com

--------------- Added 1378993172 at 1378993172 ---------------

I figured it out and feel slightly stupid now. Any suggestions on how they might have been able to add admin accounts and how I can prevent this in the future.


STEP 1: Login to ADMINCP
STEP 2: In the left-hand margin, scroll down to NOTICES
STEP 3: Click on NOTICES
STEP 4: DELETE the notice with the hacker message
STEP 5: Find the new admin account(s) they created.
STEP 6: Note the IP address(es) used to create the admin account(s)
STEP 7: DELETE the admin account(s) they created.
STEP 8: BAN the IP address(es) they used.

rhody401
09-13-2013, 02:10 PM
These are the only ones I dont recognize

admin_rbs.php
admin_rbs_banner_list.php
admin_rbs_delete.php


Those are part of the Rotating Banner System mod. (RBS)

Jester1423
09-14-2013, 01:24 AM
Well found 4 more accts tonight and the modified some plugins but all it shows in the log is the plug in id. How do i tell which plugins were modified? The paypal address was also changed as well.

--------------- Added 1379125536 at 1379125536 ---------------

I did delete the install folder off the server just now because I had forgot to.

socialteenz
09-14-2013, 04:53 AM
Well found 4 more accts tonight and the modified some plugins but all it shows in the log is the plug in id. How do i tell which plugins were modified? The paypal address was also changed as well.

--------------- Added 14 Sep 2013 at 02:25 ---------------

I did delete the install folder off the server just now because I had forgot to.

You need to delete the plug in's & update the passwords as well.

Jester1423
09-26-2013, 11:38 AM
Ok after scouring the entire site i think im 100% cleaned up.

Now on to my next question. It appears that after deleting the Install folder form the server now my modcp is gone along with the banning.php so i cannot ban any users. I looked in the install folder and neither of these files where in there. any help?

kh99
09-26-2013, 12:00 PM
There is an option to rename the modcp folder, but if you haven't done that and it's really missing, then you should just be able to upload the modcp folder from your vb distribution.

Jester1423
09-26-2013, 12:58 PM
Yeah i still get this

Not Found

The requested URL /modcp/banning.php was not found on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.


I haven't been able to find the modcp location

ForceHSS
09-26-2013, 02:40 PM
Check ftp in the config file see what is the name of the modcp as it looks like it has been renamed. If it has been deleted then you will need to upload it again