vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Hacked through provider - files added. (https://vborg.vbsupport.ru/showthread.php?t=316709)

Dave 01-20-2015 03:50 PM

You should look into the access.log file of Apache and FTP log file, maybe that will give you some more information.
Do you use shared hosting by the way or do you have your own VPS/dedicated server?

kh99 01-20-2015 03:51 PM

Not that I'm an expert on the subject, but the only thing I can think of other than your host server having been hacked is that they could have added a plugin. Seems unlikely though.

You said you scanned for non vbulletin software, how did you do that?

squidsk 01-20-2015 03:52 PM

Have you deleted the install directory?

pityocamptes 01-20-2015 04:29 PM

Quote:

Originally Posted by Dave (Post 2533535)
You should look into the access.log file of Apache and FTP log file, maybe that will give you some more information.
Do you use shared hosting by the way or do you have your own VPS/dedicated server?

Shared hosting. Last time I went in, when this first happened, all my logs were deleted...

--------------- Added [DATE]1421778601[/DATE] at [TIME]1421778601[/TIME] ---------------

Quote:

Originally Posted by squidsk (Post 2533537)
Have you deleted the install directory?

Yes.

ForceHSS 01-20-2015 04:30 PM

Could be a hidden file that hackers put in place sometimes and very hard to find

pityocamptes 01-20-2015 04:34 PM

Quote:

Originally Posted by kh99 (Post 2533536)
Not that I'm an expert on the subject, but the only thing I can think of other than your host server having been hacked is that they could have added a plugin. Seems unlikely though.

You said you scanned for non vbulletin software, how did you do that?

In the admincp, looking for suspicious files... unless that is not a good indicator of looking for non vb files...

When it first happened, I went into FTP and looked at all the files. Especially looking for modification dates, in the last day or so. Deleted all the files that were added on the day of the initial hack, and also uploaded clean files like the index file. Would this be a good indicator for looking at suspect files - by looking at the DAY they were uploaded or altered?

I hate to be paranoid, but could this be something on my home computer that malware software is not finding? I have firewalls, etc. so I don't know how they are getting new PW information.

It looks like these +++++++s are an Egyptian hacker group...

kh99 01-20-2015 04:41 PM

Quote:

Originally Posted by pityocamptes (Post 2533551)
In the admincp, looking for suspicious files... unless that is not a good indicator of looking for non vb files...

I think that's OK, although I'm not sure offhand if it will find hidden files. But if you have any web directories outside the vbulletin directory then you'd have to check there too, and you want to make sure you're seeing hidden files (I don't know if your ftp shows you by default or not).

pityocamptes 01-20-2015 04:44 PM

Quote:

Originally Posted by kh99 (Post 2533552)
I think that's OK, although I'm not sure offhand if it will find hidden files. But if you have any web directories outside the vbulletin directory then you'd have to check there too, and you want to make sure you're seeing hidden files (I don't know if your ftp shows you by default or not).

Ok, this iw what I am wondering. So it is possible to physically hide a file from physical view, sort of like Windows does? Because I would think if they buried code in a vbulletin required file, the date stamp should have changed for its modification, which I would have seen in FTP, correct?

Since the database has not been screwed with, I assume they did not get access to that, but would be easily available considering the access info would be in a file....

nhawk 01-20-2015 06:01 PM

I know this won't be helpful but...

$5 will get you $10 that your host is GoDaddy.

I've found that a good majority of hacked sites are hosted on GoDaddy.

pityocamptes 01-20-2015 06:19 PM

Quote:

Originally Posted by nhawk (Post 2533566)
I know this won't be helpful but...

$5 will get you $10 that your host is GoDaddy.

I've found that a good majority of hacked sites are hosted on GoDaddy.

You would be correct. I have a few months left on hosting and will be leaving to another provider. Unless of course this goes $hit south, in which case I will be punching out sooner than later...

So, are you indicating that the issue is on their end, or my end? Like I said, I have no idea how my original account was hacked, too much info they would have had to have had. Now this time around could be explained by something still on the server that I did not clean up, or perhaps, they are having issues??? Thoughts?


All times are GMT. The time now is 09:43 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01219 seconds
  • Memory Usage 1,739KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (6)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete