View Full Version : Site hacked
Big Country
01-21-2014, 02:46 AM
TONS of SPAM, 1000's of blog entries, and the freaky thing is there is a "new administrator".
"aku" no IP addy, nothing, I have no idea HOW it got there.
anyways. deleted some users and I noticed that I was NOT able to delete one user, no matter how many times I tried, the user would still be there.
using Spam-O-Matic,, guess that has been defeated given the number of new users.
questions, HOW do I mass delete blogs?
I shut down the site and some of these spammers are STILL posting blogs while the site is down :mad:.
help WOULD be appreciated. thanks.
ozzy47
01-21-2014, 02:49 AM
Please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked (http://www.vbulletin.com/forum/blogs/zachery/3993888-fixing-your-site-after-you-have-been-hacked)
http://www.vbulletin.com/forum/blogs...vbulletin-site (http://www.vbulletin.com/forum/blogs/zachery/3993849-best-practices-for-securing-your-vbulletin-site)
Also please see these recent security announcements:
vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5 (http://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/3991423-potential-vbulletin-exploit-vbulletin-4-1-vbulletin-5)
vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions (http://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/3993204-vbulletin-5-connect-security-patches-released-all-versions)
Big Country
01-21-2014, 02:55 AM
Please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked (http://www.vbulletin.com/forum/blogs/zachery/3993888-fixing-your-site-after-you-have-been-hacked)
http://www.vbulletin.com/forum/blogs...vbulletin-site (http://www.vbulletin.com/forum/blogs/zachery/3993849-best-practices-for-securing-your-vbulletin-site)
Also please see these recent security announcements:
vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5 (http://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/3991423-potential-vbulletin-exploit-vbulletin-4-1-vbulletin-5)
vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions (http://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/3993204-vbulletin-5-connect-security-patches-released-all-versions)
thank you, still fishing for a way to kill all the blogs.
ozzy47
01-21-2014, 03:05 AM
I would start by securing the site first, then repair the damage.
ForceHSS
01-21-2014, 03:07 AM
Check in plugin manager hackers add there own sometimes so if removed then can make more accounts.
Big Country
01-21-2014, 03:19 AM
thanks guys, working on it, guess Ill be down for a few days while I tackle things.
:mad:
ozzy47
01-21-2014, 03:25 AM
Yeah unfortunately these things tend to happen sometimes, just make sure you follow everything thoroughly, or you will have more problems.
New Joe
01-21-2014, 05:42 AM
Do you have a back up of the data base before the hack?
maybe that could help if you did.
Big Country
01-21-2014, 06:33 PM
sadly I do not have recent back ups.
getting errors when prunning/deleting some users
Deleting User JesseLowe
Fatal error: Call to a member function query_read() on a non-object in /home1/*/***/public_html/includes/class_dm_blog_user.php on line 218
tbworld
01-21-2014, 10:33 PM
Most good hosting services retain a backup for their own purpose. There is usually a fee involved for retrieving your database/files from their backup system, unless it is included in your host service pack. Depending on the size of your board this might be an option for you.
ozzy47
01-21-2014, 10:44 PM
Problem is there is no telling if the issue was in the backup or not.
tbworld
01-21-2014, 11:13 PM
Problem is there is no telling if the issue was in the backup or not.
True, True - The infection date would have to be known. Usually, the service is not cheap either since they have to parse the backup image.:)
ozzy47
01-21-2014, 11:16 PM
I still would like to know what allowed them in, probably the install folder was still there sounds like.
tbworld
01-21-2014, 11:19 PM
Problem is there is no telling if the issue was in the backup or not.
True, True - The infection date would have to be known. If backups are not included in your service package, it can get quite pricey: as they usually have to parse the backup image. :)
Big Country
01-26-2014, 01:28 AM
well, to a degree, its good I have very few actual members, most joined when the forum started, so anyone with user ID past 10 needs to go, I need to find out a way to delete ALL blogs and ALL members, Ill just make the few original members back .
wondering if it might be easier to use a new database.
no backups, hostgator only archives 1 wwek orso I was told. the forum was left alone for a long time as we had many other things to deal with and just noticed this mess.
going to the blogs section is a mess
http://www.patraditionalbowhunters.com/blog.php
no user names attached to blogs, my permissions should not allow this.
seems we got hacked right around SEPT of last year, no one noticed as we were not active for a long time.
still getting errors tryong to delete some users using the "prune" function
Deleting User VerlaQQJB
Fatal error: Call to a member function query_read() on a non-object in /home1/***/public_html/includes/class_dm_blog_user.php on line 218
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.