vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Community Lounge (https://vborg.vbsupport.ru/forumdisplay.php?f=13)
-   -   My Site Got Hacked Today (https://vborg.vbsupport.ru/showthread.php?t=285763)

Harpo 03-12-2013 09:18 AM

Hi OP. sorry about your website. I hope you do well in life.

loua_oz 04-02-2013 01:03 PM

My site got hacked yesterday.

The Hosting provider (webhostinghub.com) said it's a vB issue.

The symptom was that nobody could log in, not even Admin (myself) but the site was readable.

Why on Earth vB can not provide a function such as "restartable copy of site" that can download a snapshot of the site to a local PC?

Now I am going through the hoops and people running their sites by free software , not vB, could be laughing at me and our entire community.

Why is hacking so easy with vB? No tools on my site, all by the book.

Brandon Sheley 04-02-2013 03:13 PM

Quote:

Originally Posted by loua_oz (Post 2413850)
My site got hacked yesterday.

The Hosting provider (webhostinghub.com) said it's a vB issue.

The symptom was that nobody could log in, not even Admin (myself) but the site was readable.

Why on Earth vB can not provide a function such as "restartable copy of site" that can download a snapshot of the site to a local PC?

Now I am going through the hoops and people running their sites by free software , not vB, could be laughing at me and our entire community.

Why is hacking so easy with vB? No tools on my site, all by the book.

You should really start your own thread if you're asking for support.

Any website can get hacked, even free ones. :up:

loua_oz 04-03-2013 01:01 AM

I am not asking for support.
Restored (still in process) from backups but with nothing changed nor improved, the hackers can walk in at any time again.

Simon Lloyd 04-03-2013 04:25 AM

Quote:

Originally Posted by loua_oz (Post 2413850)
...............the site was readable.

Why on Earth vB can not provide a function such as "restartable copy of site" that can download a snapshot of the site to a local PC?......

They do, if your site was readable then all you had to do was upload tools.php, repair your access and you're back in!

If you have all the latest patches, no extra add-ons...etc and it's a bog standard forum then it's either a very insecure admin password thats been discovered or they've accessed your server by poor ftp password, insecure folder permissions or if your on a shared server via some other vulnerability on the server maybe via another user.

loua_oz 04-03-2013 07:20 AM

Thanks, I did not know that (that tools.php) can be used to do a snapshot. Never actually seen what it looks like, never started it, just removed from the site.

It is a shared server. The pasword, although not easy, could have been cracked by some automated procedure.
Changed them all today, for site, for ftp for hosting control panel.

The site is up and running now, fully restored. What they did this morning was to insert some malware. Several members who know my private email address reported that their computers are warning them about malware (the hackers placed it in index.php, even word "Russia" was readable among other things)

Simon Lloyd 04-03-2013 07:36 PM

tools.php doesn't do a snapshot, if you're locked out for whatever reason, database issues...etc then you upload tools.php and you can gain access, you wouldn't have had to do a restore from back up. It appears your backup has the malicious code already injected.

Download your entire directory and scan it on your pc at the very least.

DragonByte Tech 04-04-2013 12:38 AM

Bear in mind it's possible the server itself was compromised - if another site on the server was hacked symlink means all sites on the server are now vulnerable.

loua_oz 04-04-2013 03:28 AM

backup does not have the infected file - it was newly created index.php which is 5Kb, the original one is 1.99Kb. Not knowing what else could be infected, restored the whole lot.
While the site had the contaminated file, Google bots found it and inserted my site into "known malware distributors", warning people not to enter.
Now I am getting it removed from there.

Lionel 04-04-2013 03:50 AM

I had a customer with a similar problem. The malware came in via Word Press


All times are GMT. The time now is 01:41 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01060 seconds
  • Memory Usage 1,739KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete