vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Site hacked by Myanmar Muslim Cyber Force (https://vborg.vbsupport.ru/showthread.php?t=302092)

Phat Phreddy 09-11-2013 01:20 PM

Doing my head in.. Restored a full clean backup 3 times.. removed install.. Deleted admins.. Changed PWs..

Still it keeps coming back..

If the files are from a week ago, and hence clean.. what can there be to cleanup ??

What can forum logs show me ?? How can I look at how this is happening ??

pityocamptes 09-11-2013 06:51 PM

Would running your site through http://sitecheck.sucuri.net/scanner/ help? Might find the malware file. Also, have you checked your htaccess in root?

pjkcards 09-11-2013 07:00 PM

I hired someone in the paid forum to fix it. Took them quite awhile to fix it, and the styles are now messed up. Apparently it isn't an easy fix.

Phat Phreddy 09-12-2013 01:40 AM

Quote:

Originally Posted by pjkcards (Post 2444975)
I hired someone in the paid forum to fix it. Took them quite awhile to fix it, and the styles are now messed up. Apparently it isn't an easy fix.

I am assuming you mean fixing it when you didnt have a file system backup ??

teamemmenracing 09-12-2013 11:14 AM

I have a similar re-direct as of yesterday, only mine is to
http://www.cadiroig.cat/downalert.html

I have spent hours following instructions,, have re-installed files etc removed directories, I even deleted all files on the server and up loaded last months back up ...... which makes me wonder if it is the database that has been attacked.

I have found this unauthorised visit ......

20749 N/A 04:05, 10th Sep 2013 notice.php modify 91.144.37.46
20748 N/A 04:04, 10th Sep 2013 notice.php update 91.144.37.46
20747 N/A 04:04, 10th Sep 2013 notice.php add 91.144.37.46


........ but even replacing the notice.php with a newly downloaded version doesn't help.

Im kind of hoping that as hundreds of sites have been affected that someone might have found a common fix .....

anybody have any ideas ?

Phat Phreddy 09-12-2013 11:24 AM

You got the added admins ??

Also make sure you change admin PW, FTP and MySQL passwords ??

TheLastSuperman 09-12-2013 11:47 AM

Quote:

Originally Posted by teamemmenracing (Post 2445081)
I have a similar re-direct as of yesterday, only mine is to
http://www.cadiroig.cat/downalert.html

I have spent hours following instructions,, have re-installed files etc removed directories, I even deleted all files on the server and up loaded last months back up ...... which makes me wonder if it is the database that has been attacked.

I have found this unauthorised visit ......

20749 N/A 04:05, 10th Sep 2013 notice.php modify 91.144.37.46
20748 N/A 04:04, 10th Sep 2013 notice.php update 91.144.37.46
20747 N/A 04:04, 10th Sep 2013 notice.php add 91.144.37.46


........ but even replacing the notice.php with a newly downloaded version doesn't help.

Im kind of hoping that as hundreds of sites have been affected that someone might have found a common fix .....

anybody have any ideas ?

Ladies and Gentlemen, there is no "added fix" let me clear up some misconceptions here:
  • Most of the sites hacked recently still had their /install/ folder present on the site, its the exploit mentioned here - http://www.vbulletin.com/forum/forum...-1-vbulletin-5
  • A security bulletin email was also sent out, you should have received one and followed instructions promptly. *Always ensure you're receiving vBulletin emails and eBulletins/any and all mail from vBulletin.com needs to bypass your spam filters and others and be in your inbox and able to be read each and every time and you need to read these emails as apparently they are important!
  • If you restore a backup of the database prior to being hacked, you must restore a backup of the files from that time as well otherwise a file may have been modified still allowing access. Is it just vBulletin files to overwrite? Well you certainly need to overwrite the vBulletin files with 100% fresh files AND any others you find that were modified, if you find a suspect file such as lol.php or sexy.php or even owned.html basically anything that does not belong should be deleted, run suspect file versions from the admincp maintenance area to check vBulletin related files.
  • Follow the links that myself and Zachery have been posting in countless threads, the links to his blog, mine and other links we post are to blogs and articles that provide detailed instructions including various ways to test and ways to fix.

Here are the links again:
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site
http://www.vbulletin.com/forum/blogs...vbulletin-site

So to be perfectly clear, there is no "automatic" fix, no upload this and run it then your done and site secure... it is this simple:

1) Restore a complete backup (database and filesystem, the backups need to be from before the hacker made changes and had access) then once restored promptly delete the /install/ folder and at this time check your version, patch to the most recent patch # of your version OR upgrade to a more secure version i.e. 4.1.5 --> 4.2.1

- OR -

2) If no backup is available, using the links provided above you must manually clean your site. Check the database and filesystem for modified files and be very thorough to ensure nothing slips past you and remains in place for example if a shell script is left on the server or a spare admin account then you're still vulnerable and the site can be exploited/defaced again.

If you're unsure about something and need a clarification do not hesitate to post and ask, if you feel its a stupid question well then its not, no question is stupid unless your specifically being silly when you ask it and even then it ends up being a silly question instead lol. Ask questions now and receive helpful replies that may assist you in cleaning your site and returning to business as usual ;).

joeychgo 09-12-2013 01:23 PM

I strongly recommend forum owners sign up with Securi.

They have done a great job for me and I use them on all my forums.




.

lapiervb 09-12-2013 05:45 PM

Quote:

Originally Posted by joeychgo (Post 2445107)
I strongly recommend forum owners sign up with Securi.

They have done a great job for me and I use them on all my forums.




.

You need to stop pushing this as you are losing any credibilty the site may have had and it is against the rules here to have your affiliate link in a post.

teamemmenracing 09-12-2013 06:33 PM

................... well I have tried everything and its still there.
worst of all, when I try to copy files back to my computer, they are all password protected and I cant access them.

Finally I went to my host and deleted everything from the server ........ except the database, then loaded new files that I just downloaded from the vbulletin members area ......

and from nowhere this file appears .....

zdberrb4476bf0aed19d1e05964d0757f51.dat

it doesn't look legit, I managed to open it up and the only contents were a number .....

13790115241146

Im thinking I now have a server problem .....

any ideas ?


All times are GMT. The time now is 02:19 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01097 seconds
  • Memory Usage 1,755KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete