vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 4.x Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=245)
-   -   Administrative and Maintenance Tools - Check 4 Hack - Finds infected Datastore Entries (https://vborg.vbsupport.ru/showthread.php?t=265866)

djbaxter 07-11-2011 08:28 PM

Quote:

Originally Posted by CBrown (Post 2219375)
Just to be clear...

If you get a blank email -> Does that mean nothing was found?

Yes. The only time I get this is after a manual run and when I check for "infections" using other methods the datastore is clean.

thincom2000 07-11-2011 09:29 PM

Quote:

Originally Posted by MentaL (Post 2215553)
The following modules were infected:

vbindex_config

/edit , decoded and it says

Quote:

Originally Posted by djbaxter (Post 2215556)
Then you need to delete that file: vbindex_config - what is that, anyway? That's not part of vBulletin, as far as I know.

I would not recommend removing that as it looks like it is the copyright notice for a mod you have installed. If you remove it, you can get in trouble with the mod author. Most mods with copyrights say if you don't want the copyright shown, pay to remove it or uninstall the mod.

Lee G 07-26-2011 11:11 PM

Two blank emails tonight, twenty minutes apart
In the logs it showed pluginlist being hit

Lee G 07-26-2011 11:38 PM

Looks like it was either this mod that set it off
https://vborg.vbsupport.ru/showthread.php?t=258158

Soon as I uninstalled the mod, the warnings stopped

BirdOPrey5 07-27-2011 10:42 AM

Envolve does have the string "base64" in plugin code, but they are encoding data not php code.

gregorym 01-31-2012 10:26 AM

Just installed like a charm on 3.8x.
The demo worked well, now hopefully nothing is going to happen....
Thanks, simple but looks very useful.

neverstop 03-01-2012 06:16 PM

I installed this mod and I'm getting a blank email everytime the cron runs. Any thoughts?

Schoelle 03-02-2012 03:19 PM

Quote:

Originally Posted by neverstop (Post 2305109)
I installed this mod and I'm getting a blank email everytime the cron runs. Any thoughts?

This is from the demo plugin. Disable it and you will get no more emails.

farhanisfarhan 03-03-2012 06:16 PM

does it helps with file2store exploit as well ?

Lazorbeam 03-05-2012 02:12 PM

I'm getting a blank email once a day. Is this normal? Demo disabled.

Quote:

Originally Posted by farhanisfarhan (Post 2305804)
does it helps with file2store exploit as well ?

It should. The file2store exploit does exactly what this mod is designed to delete.

baerwurz 03-12-2012 06:16 PM

Perfect for file2store exploit. Traffic went up. Thanks a lot ;)

Zighinno 03-16-2012 11:48 AM

Hi, when click on run now the email is: The following modules were infected: pluginlist.

demo is disabled. Why?

Thanks

furnival 03-21-2012 03:42 PM

This seemed to fix my issue with the file2store exploit. But do I need to rebuild my templates too once in a while I wonder if I had that problem?

Once I disabled a couple of old plug ins I did not get any more security warnings by email. :D I can't thank the coder of this app enough!

If anyone knows: does rebuilding the datastore slow down my forum for those visitors who visit immediately after it is rebuilt?

arcab4 03-22-2012 09:02 PM

thanks for creating this. been having issues with file2store.info - those bastards.

thanks for the detailed instructions for newbies.
https://vborg.vbsupport.ru/showpost....5&postcount=26

alex818 04-03-2012 01:43 PM

The following modules were infected:

pluginlist

what do we do now?

Baf_Jams 04-03-2012 08:25 PM

Quote:

Originally Posted by alex818 (Post 2316379)
The following modules were infected:

pluginlist

what do we do now?


Did you enable the demo plugin to test it?

DAMINK 04-05-2012 11:00 PM

Great Mod.
Thankyou for taking the time to create this.
Works perfectly as expected.

Gadget_Guy 04-19-2012 03:28 AM

Here is something interesting.

I know I am 100% affected by the file2store exploit, however I am getting blank e-mails.

How is this possible?

D.

DAMINK 04-19-2012 03:53 AM

Arent blank emails only for the bebug mode?
I thought if it was running properly you get no emails?

Jhonnyf 04-20-2012 07:14 PM

I think That I found how happen the INJECTION SQL .. I'm testing on a Client and not have problem since 2 days (the day that I do the patch)

barcena 05-23-2012 04:04 PM

1 Attachment(s)
I am trying to install the xml file but after there's nothing active, only the name of the file under the plugins area. Any help?

barcena 05-23-2012 05:54 PM

Any help please?

barcena 05-23-2012 06:22 PM

Check 4 Hacking

Warning: include_once([path]/./includes/cron/check4hack.php) [function.include-once]: failed to open stream: No such file or directory in [path]/admincp/cronadmin.php on line 113

Warning: include_once() [function.include]: Failed opening '[path]/./includes/cron/check4hack.php' for inclusion (include_path='.:/usr/lib/php:/usr/local/lib/php') in [path]/admincp/cronadmin.php on line 113

Terminado

barcena 05-23-2012 08:49 PM

Anyone help?

BirdOPrey5 05-23-2012 08:55 PM

It looks like you did not upload the php file, or at least did not upload it to the correct folder on your server.

It goes in your /includes/cron/ folder.

barcena 05-23-2012 09:20 PM

Oh, I didn't know I had to... I don't know how to do it but thank you very much.

BadgerDog 08-08-2012 06:43 PM

For the very first time, this mod has started sending me emails indicating a threat ...

They started after installing Lancerforhire's "Live Topic" mod....

Lancerforhire indicates that this is a "false positive" as discussed here:

https://vborg.vbsupport.ru/showpost....&postcount=117

I don't know how to tell Hoffi's Check 4 Hacking mod to stop sending emails if it's related to the "Live Topic" mod? Is there an exclusion list capability?

Regards,
Doug

imported_dfmafia 08-09-2012 10:39 PM

The following modules were infected:

pluginlist

vB 4.2.0 PL 2

i get this when the plugin demo is disabled. ie. [s]demo[/s]

i know it is disabled from the install. ran the task and i get pluginlist infected. i enable the demo and i get pluginlist- infected.

Justinphx 08-09-2012 11:05 PM

There is only one file to upload to the server (a php file into cron), right? I did that and installed the xml and all seems fine. I do not show any demo version under the real one. I have never received any emails from it after installing so I have no clue if it is working right.

I am running 4.1.12p2. Any suggestions on how to get the demo to display under products?

BadgerDog 08-11-2012 04:19 PM

Uninstalled ... too many false positives ... ;)

Thanks anyway ... :)

Regards,
Doug

cravendale 09-29-2012 07:29 PM

The following modules were infected:

pluginlistadmin

can anyone please help with this

MegaManSec 09-29-2012 08:04 PM

If not already in this,
Make it check the checksum of login.php.
http://newinhacking.blogspot.com.au/...rtutorial.html
I made a small thing in BASH a while ago to do it.
But in general, this mod is good, and hopefully I can help you out with coding this in the future ;)

cravendale 09-30-2012 01:37 PM

Quote:

Originally Posted by cravendale (Post 2369591)
The following modules were infected:

pluginlistadmin

can anyone please help with this

Anyone can help?

I've found pluginlistadmin in the datastore. Not sure exactly what I'm looking for though.

Can anyone please help?

TheSupportForum 10-02-2012 08:15 PM

Quote:

Originally Posted by MegaManSec (Post 2369602)
If not already in this,
Make it check the checksum of login.php.
http://newinhacking.blogspot.com.au/...rtutorial.html
I made a small thing in BASH a while ago to do it.
But in general, this mod is good, and hopefully I can help you out with coding this in the future ;)

this is not possible for 4.2.0 :(
non of those codes exist

masterross 03-12-2013 11:07 AM

This hack should check for '%logincache%' too.

I, Brian 04-18-2013 10:19 AM

Quote:

Originally Posted by djbaxter (Post 2215485)
  1. Admin CP >> Scheduled Tasks >> Scheduled Task Manager

    scroll down to "Check 4 Hacking: Test the datastore for infects"

    click on "Run Now"

Hmm, "Check 4 Hacking" isn't showing on my scheduled tasks at all. vb 3.8.7 patch level 3.

Have disabled the "demo" now, but I can't see any sign that the plugin is active. Fingers crossed?

avitor 04-18-2013 11:48 AM

hello dear
thank you for this mod

any one can confirm that this mod working on vb 4.2.pl2 ?
thanks

Aneurysm 06-24-2013 02:57 AM

Installed and running fine on VB 4.2.1 :)

Aneurysm 06-26-2013 05:54 AM

Quote:

Originally Posted by Aneurysm (Post 2430116)
Installed and running fine on VB 4.2.1 :)

The mod is running but it doesn't seem to show up in the scheduled task log. I have toggled logging on/off but it doesn't show up. Other scheduled tasks show up in the log if enabled, can someone please verify if logging works.

Wolver2 07-03-2013 03:21 AM

Anyone knows how to get this to work for 4.2.1?

very important to several users


All times are GMT. The time now is 05:15 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01265 seconds
  • Memory Usage 1,813KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (10)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete