![]() |
Website hacked!
My website has been hacked by some turkish group. :mad: Someone registered at my site. When i connected to my sql directly i found they had changed userid 1, the admin...
I had the following: vBulletin 3.5.4 vBadvanced 2.1.0 DLM manager VBgameserver hack Teamspeak display hack My best guess is they used some exploit in the vb gameserver hack. I'm now resetting my site using only: vBulletin 3.5.4 vBadvanced 2.1.0 DLM manager Are these three secure enough to use at this moment without getting hacked? Second i used Mysql front to make back-ups of my database. Yesterday i used the same program to restore the sql file and guess what it didn't work :mad: Because i just switched to vBulletin from phpnuke i had the phpnuke database which i could use, so only lost 2 weeks of data. My second question what is a good program to use to back up your database and to restore it. PhPmyadmin is no option because i don't want it installed on my webspace. The only thing it will do is add another why to kill off my database. :confused: Another vB user pointed out to ssh, but are there any good programs out there that would do the job? Thanks for all the help, i really need it!!! |
I can only say that vBulletin 3.5.4 should be secure enough, there are no known security issues. About the other 2 i can't make a judgement.
Back ups (if you host don't make them yet) can best be made from the shell. Beside a terminal emulation programm, no other software needed. For instructions see the chapters in the vBulletin manual: Backing-up your MySQL Database Manually Restoring your MySQL Database Manually |
Did you have SSH or telnet enabled?
|
This is precisely the same thing that happened to me that I made a post about here and got my butt chewed out for it.
|
With all due respect, your statements in thread
Quote:
Quote:
Please either stay on topic and offer assistance or do not respond. If you would like to discuss this further, please PM me. |
Aside from all of the bashing there was quiet a few good suggestions and pratices that could have been taken and followed.
|
I did take all the steps that where offered to me.
|
Quote:
So what happened? Did you find out who was hacking your server every day? Where was the vulnerability? |
Heidrich, I was on phpNuke when I was brutally hacked and from the way it is being described, my attack was similar to yours. One thing I took note of was SSH traffic. I had previously been hacked once before, a minor defacing, but I made note of the SSH traffic on that as well. This time it was much larger. It was then I requested my SSH and telnet disabled - in fact, all avenues of access other than ftp and http closed. Knock on wood, I've not had anything happen since. It was this last hacking that I had decided to move to vbulletin - away from phpNuke. Fortunately, since I worked for my ISP, and we were going to migrate to a newer box anyways, I built our next hosting box. The crack had corrupted the old mysql database. Even recreating the site wouldn't fix it. I hope your fix is easier than mine was.
|
Quote:
As I stated, it was vbulletin. |
What proof of this do you have specificly? Have you done security audits? Have you uninstalled all of your modifications and ran with only the default vBulletin code? If not you cannot say beyond a doubt that there was not something else aside from vBulletin allowing you access.
|
Quote:
As vBadvanced main website is still running i'll guess that script is more then okay. The only factor remaining is Download and Links manager. Do any users of this hack have any problems? About SSH i believe my host doesn't allow telenet or ssh connections to the database. I'll check. I have went through the corrupt backup and found in the admin logs that they changed my templates to my board. If i understand correctly there are no back-up programs (software) for mysql available? Thanks for the help sofar all!! |
Oh goodness no, there are tons, via ssh is the best way with the mysqldump utility. vBulletin also provides a backup feature via the admincp but its not 100% reliable due to php/webserver restrictions. Make a dump and check the last few lines, vBulletin will tell you if it had completed
|
Quote:
Can you please point me to a good tut. for ssh as i'm new to it.:) -> edit: just saw Marco's post. Will check those out thanks. |
Ive had the same problem..
Thats why im the only admin :) ________ List of Chrysler engines specifications |
Quote:
https://vborg.vbsupport.ru/showthread.php?p=877421 |
my webiste is on a windows server and .htaccess won't work.:confused: Are there any other like htaccess, but for windows server?
Ow i don't know if it's allowed to post, but i take my changes: The IP of the guy that "hacked" me: 88.240.173.99 Here is what he did: Quote:
|
I'm going to run that IP by a friend of mine who was hacked 2-3 weeks ago. It looks familiar.
|
Quote:
|
Quote:
Maybe an idea for vBulletin.org to seperate all downloads in two. Secure and issues? Because time goes by and looking at all the mods in here you don't really know what you can use and what you can't. |
If we get a security report about a mod we take actions to correct it and notify anytone whos clicked install.
|
Here are the IP addresses {of the attackers} which targeted my friend's website.
88.226.184.31 88.226.76.220 |
I had this happen to my forum and they used flashchat as a way to upload files.
If you are using flashchat, I suggest upgrading to their latest version or remove it completely. Or host it on a seperate hosting plan away from your main forum/site. |
All times are GMT. The time now is 01:24 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|