PDA

View Full Version : VBulletin 4.2.2 hacked; is it safe ?


t2cervens
10-19-2013, 03:59 PM
hi

This morning (19 oct), one mod warned me that my website was hacked and defaced; in fact
the content of the website was deleted (only a few files left and empty directories)

this website had just a couple of static html files with some photos and a forum ( VB 4.2.2) all plugins disabled, no blogs no CMS etc.. ( I disabled everything during the latest update from 4.2.1 to 4.2.2); nothing else on the website,no apps too or scripts, and of course install directory was deleted..

at this time, the main directory (home) of the site contained 2 files: index php and changelogs.php (or something like that) I was unable to download this last one ( blocked by avast as trojan) and I remotely deleted it; I put the website offline too

Q: is vbulletin safe, is there a security problem ?

actually I'm trying to restore a backup ( 6 weeks old)

any suggestion/idea please now?

thanks

Terry

fanyap
10-19-2013, 04:03 PM
If the physical files were deleted from the server, I think someone gained access to your server/FTP and deleted the files.

You should schedule automatic backups every 24 or 48 hours so that you're content loss is minimal if this happens again.

Digital Jedi
10-19-2013, 04:46 PM
A couple of resources you may want to look over:

Fixing Your Site After You Have Been Hacked (http://www.vbulletin.com/forum/blogs/zachery/3993888-fixing-your-site-after-you-have-been-hacked)
Recovering a Hacked vBulletin Site (http://www.vbulletin.com/forum/blogs/michael-miller/3934768-recovering-a-hacked-vbulletin-site)

WEBDosser
10-19-2013, 05:03 PM
did they delete the database? if not just upload the files again.

t2cervens
10-19-2013, 05:12 PM
update

restoring the website I found another php file obviously uploaded in vb directory by hacker..again avast detected infection when I downloaded it: PHP:Agent-IS [Trj] ...

--------------- Added 1382206444 at 1382206444 ---------------

did they delete the database? if not just upload the files again.

no I don't think so according to the db size

I did not check now 'cuz I was changing user db name and passw...

--------------- Added 1382209227 at 1382209227 ---------------

A couple of resources you may want to look over:

Fixing Your Site After You Have Been Hacked (http://www.vbulletin.com/forum/blogs/zachery/3993888-fixing-your-site-after-you-have-been-hacked)
Recovering a Hacked vBulletin Site (http://www.vbulletin.com/forum/blogs/michael-miller/3934768-recovering-a-hacked-vbulletin-site)

thanks!