vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Myfilestore.com Virus (https://vborg.vbsupport.ru/showthread.php?t=323931)

mscottralston 11-30-2016 09:34 AM

Per the advice in this thread, I'm going to be deleting all plugins, fixing 4.2.0 and upgrading to 4.2.3 this morning; I am under the impression that a very likely culprit here is Yet Another Awards System, a plugin which, when I googled it, came back heavily associated with "SQL Injection."

It's a bit of a shame, though -- apparently we've used YAAS for many years to give badges and whatnot to members of the community. This is a shot in the dark, but does anyone know if those vulnerabilities have been patched by 4.2.3? Is there a good way to similarly overwrite the plugin's files without losing our data on who has what award and so forth?

Paul M 11-30-2016 10:24 AM

Quote:

Originally Posted by mscottralston (Post 2578929)
This is a shot in the dark, but does anyone know if those vulnerabilities have been patched by 4.2.3?

Official patches will not not do anything for vulnerabilities in addons. as they are their own code.

Only the product developer could fix them.

mscottralston 11-30-2016 03:46 PM

Hi folks,

My upgrade from 4.2.0 to 4.2.3 seems to have stalled out at the very first step:

Upgrading to 4.2.3
Status: Processing 4.2.1 Alpha 1, Step 1 of 6

The "upgrade progress" window is completely blank. It's been this way for about twenty minutes. I know that the whole process may take an hour, or hours, but the lack of any visible progress has me a little spooked. Should I be concerned that it's run out of memory or something? (It advised me before I started that there was a way I could do this from the command line if necessary, but not knowing whether or not it would be necessary, I elected to let the script try to process through the browser control panel as normal). Is there a way to cancel out, then retry from the command line?

Thanks!

Dave 11-30-2016 06:15 PM

Check the error logs of your web-server or PHP in order to figure out what is causing it to stop.
Cause could vary; out of memory, webhost blocking you automatically because of too many connections to the server, SQL error, etc.

RichieBoy67 12-01-2016 08:16 AM

Quote:

Originally Posted by mscottralston (Post 2578940)
Hi folks,

My upgrade from 4.2.0 to 4.2.3 seems to have stalled out at the very first step:

Upgrading to 4.2.3
Status: Processing 4.2.1 Alpha 1, Step 1 of 6

The "upgrade progress" window is completely blank. It's been this way for about twenty minutes. I know that the whole process may take an hour, or hours, but the lack of any visible progress has me a little spooked. Should I be concerned that it's run out of memory or something? (It advised me before I started that there was a way I could do this from the command line if necessary, but not knowing whether or not it would be necessary, I elected to let the script try to process through the browser control panel as normal). Is there a way to cancel out, then retry from the command line?

Thanks!

You can just restart the upgrade and it will continue where it left off. yoursite.com/install/upgrade.php

Budget101 12-11-2016 02:57 PM

1 Attachment(s)
Quote:

Originally Posted by oguzdinc (Post 2578748)
Hello i have problem with my www.Madenciyim.com

Visitors coming from google search is redirecting to www.myfilestore.com. When they go back to google and come back again going to my website.

What can i do.

I deleted VBSEO plug in. I upgraded my vbulletin on friday but it is still happening.


Here, I'll save you a whole messload of trouble- login to your server.

Go to your MySql Database (the one for your vBulletin install).

Click on search. Type %base64%
click on SELECT ALL

hit "Go".

You will find a large number of base64 codes hidden, most likely within [img] tags from filestore. Remove those. If you have plugins that are using base64- you'd better run a decode and see precisely what they're using it for.

Attachment 155535

If you look through your files and see picture_inline.php that file is Shell Script installed and is infecting your server/site. ( Picture_inlinemod.php IS legit)

Harley PoMmom 04-24-2018 11:38 AM

Getting those redirects from a google search to the forum where I help admin, is there an absolute fix for this issue? We have vbulletin 4.2.5.

TheLastSuperman 04-24-2018 12:58 PM

Quote:

Originally Posted by Harley PoMmom (Post 2594381)
Getting those redirects from a google search to the forum where I help admin, is there an absolute fix for this issue? We have vbulletin 4.2.5.

You can reference these for possible fixes:
https://www.vbulletin.com/forum/foru...lestore72-info

https://clients.urljet.com/knowledge...e123-Hack.html

https://clients.urljet.com/knowledge...version-2.html

With filestore they can insert it many different ways, be sure to check for template edits and also rogue plugins (OR malicious code added at the bottom of a plugin). I've even seen some take the site into debug mode and add the infection to the Master Style before let's hope they didn't do that to you i.e. possibly some script-kiddie using a tutorial and hasn't a clue about things of this nature other than how to read top-to-bottom and clickity-click-click (lol).


All times are GMT. The time now is 03:16 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01008 seconds
  • Memory Usage 1,740KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (4)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (8)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete