vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   vbulletin hacked (https://vborg.vbsupport.ru/showthread.php?t=187974)

dtv100 08-16-2008 05:40 PM

one of my forums was hacked not long ago and this hacks we both have.
dont know if this help us .

ibProArcade for vBulletin 2.6.7
Inactive User Reminder Emails 1.1.3
Miserable Users 3.7.002 .
vBSEO 3.2.0
vBSEO :: Sitemap Generator 2.2

PAKIDIL 08-16-2008 06:06 PM

Please check if you have set chmd to 777 or any of ur directory in the public_html.if you have then its easily can be hack like defacement by uploading somefile in php.after chaning the chmd check there must be some file with strange name delete it .

--------------- Added [DATE]1218913961[/DATE] at [TIME]1218913961[/TIME] ---------------

Quote:

Originally Posted by dtv100 (Post 1600174)
one of my forums was hacked not long ago and this hacks we both have.
dont know if this help us .

ibProArcade for vBulletin 2.6.7
Inactive User Reminder Emails 1.1.3
Miserable Users 3.7.002 .
vBSEO 3.2.0
vBSEO :: Sitemap Generator 2.2

ibProArcade for vBulletin 2.6.7 required chmd 777 on arcade soo its risky i guess

Bilderback 08-16-2008 08:45 PM

I did find the mysmiliesvb folder with 0777 permissions. The readme in the mod says it is required.
The user albums were moved into the file system and although the main folder is 0755,
every sub folder vbulletin creates is set to 0777
I found a 1x1 pixel image in the avatars folder but I cannot seem to locate it within file manager.

LT Mote 08-16-2008 11:45 PM

side note dude, my website & db was hacked a while back, maybe like year & 1/2 ago, I got in touch with my hosting company who checked the logs, and it ended up being FlashChat w/ vB intergration that they used to get in.... So if you are using systems outside vB that are intergrated into... Be advised of those as well, FlashChat is what got my site hacked.

PAKIDIL 08-17-2008 07:43 AM

All directories must be CHMOD 755 or higher security (meaning lower than 755, ex 750, 644, etc)

You cannot set CHMOD 777 on any files or directories because this makes the files world WRITABLE which is insecure

soo if any mod requires to set 0777 i recommend not to use it .have u lost any database of your site ?

fattony69 08-18-2008 03:06 PM

Happened again, this time different person.

Lynne 08-18-2008 03:08 PM

Have you followed all the steps outlined in this article?
How To Make My Forums More Secure

Digital Jedi 08-18-2008 03:15 PM

Quote:

Originally Posted by PAKIDIL (Post 1600557)
All directories must be CHMOD 755 or higher security (meaning lower than 755, ex 750, 644, etc)

You cannot set CHMOD 777 on any files or directories because this makes the files world WRITABLE which is insecure

soo if any mod requires to set 0777 i recommend not to use it .have u lost any database of your site ?

PAKIDIL, I recommend you read this before you continue to tell people not to install modifications with 777'd folders: Why chmod 777 is NOT a security risk

fattony69 08-18-2008 09:21 PM

Such a pain. Thankfully they only changed the index. I changed passwords and such. As for the list provided, I did most.

Bilderback 08-19-2008 01:08 AM

Thanks for all your suggestions- we're still looking for the exploit.
The latest hacker placed text within the inlinemodform just above the threadlist table.
http://thebestforumever.com/front-desk/
Has also been doing index page defacing.
I suppose we'll simply have to back track and begin disabling plugins until it can be located.


All times are GMT. The time now is 01:59 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01061 seconds
  • Memory Usage 1,739KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete