vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Hacked forum, restored files, not working, help! (https://vborg.vbsupport.ru/showthread.php?t=312968)

romebaby 07-15-2014 02:25 AM

Hacked forum, restored files, not working, help!
 
Hi all, I administer a site that's running 4.2.1 and we got hacked last week. Hacker deleted all DB files and changed a ton of stuff to where we had to pay Godaddy for a full restore. Everything is back in place from a week prior to the hack, including DB. When you go to the main URL it automatically goes to xxx.com/forums/install/install.php and says file is missing. The install folder is not in the forums directory. What do I do here?

Also I was planning on updating to 4.2.2 once I got the site back up.

K4GAP 07-15-2014 06:52 AM

I would suggest you download 4.2.2 and do a fresh install. That way you will have your install folder back.

Disco_Stu 07-15-2014 10:07 AM

Quote:

Originally Posted by romebaby (Post 2506842)
Hacker deleted all DB files and changed a ton of stuff to where we had to pay Godaddy for a full restore.

Do you ever make a backup of your entire site? I don't mean just the DB but everything? It doesn't sound like it if you have to pay Godaddy to do a restore.

I suggest creating a full backup of the entire site once a week and a full backup of your DB every day. There's a nice mod on this site that will do the DB backup for you as a scheduled job.


https://vborg.vbsupport.ru/showthread.php?t=231481

I'm curious just how much Godaddy charges to restore the site

RichieBoy67 07-15-2014 01:15 PM

You are definitely missing files or have the wrong ones there.

Lynne 07-15-2014 03:07 PM

Also, verify that the information in your /includes/config.php file is correct. If they restored a database, perhaps they gave it a different name, or different mysql user. Also, check the table prefix and make sure that if there is one, that you entered it into the config.php file.

romebaby 07-16-2014 05:16 AM

Thanks for the responses everyone. You're supposed to delete the install folder after an upgrade for security reasons (so I read) and it was running fine without it before the hack. Godaddy charges 150 for a restore when you have more than one db (we have 4). I had a local backup from March but it was taking forever to upload so we paid for the restore to get it done quicker and for a more recent copy. Thanks Lynne - I triple checked the config file with Godaddy, everything was correct. Godaddy ended up re-importing the db and boom, worked. So there must have been an incomplete or corrupt db restore on the first attempt. We're up and running sort of. Offline while I backup, upgrade, patch, backup.

ForceHSS 07-16-2014 05:39 AM

Get your host to see how the hacker got in then fix the problem

romebaby 07-16-2014 05:53 AM

Email communicated with the hacker, as he was trying to get money from us. This is how he said he got in:

I exploited your site. Got that Admins HASH:SALT (which is the password encrypted). Once i gained acess i uploaded an AJAX code and upload a i47 shell. Then i looked at your config.php logged in to the SQL dump and dumped your database. Self killed the shell

I asked him to explain I exploited your site and he said "I ran a 4.2.x upgrade exploit."

Dave 07-16-2014 06:26 AM

Well that sounds rather like a young script kiddie lol. It's smart to keep an eye on the vBulletin announcements section, you never know if you're missing out on security updates.

RichieBoy67 07-16-2014 01:54 PM

Quote:

Originally Posted by romebaby (Post 2507020)
Email communicated with the hacker, as he was trying to get money from us. This is how he said he got in:

I exploited your site. Got that Admins HASH:SALT (which is the password encrypted). Once i gained acess i uploaded an AJAX code and upload a i47 shell. Then i looked at your config.php logged in to the SQL dump and dumped your database. Self killed the shell

I asked him to explain I exploited your site and he said "I ran a 4.2.x upgrade exploit."

I believe this exploit uses the upgrade.php file.

Are you sure you did not have the install directory in there at the time the site was hacked?

I would suggest you email all users and tell them to change log ins. in addition make sure you change all admin and server related log ins, database, ftp, etc.

Grab the admincp firewall and use it and be sure to protect your config using htaccess.

Lastly, many times these hackers lie to throw you off the trail. Check your server logs and see what went on yourself so you do not have to take his word for it.


All times are GMT. The time now is 10:04 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01659 seconds
  • Memory Usage 1,738KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete