vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Help! Site Being Hacked Right Now! (https://vborg.vbsupport.ru/showthread.php?t=128441)

DrainBamaged 10-06-2006 06:51 PM

Help! Site Being Hacked Right Now!
 
My site is being hacked AS I TYPE THIS.

I closed the board immediately.

The only file I saw changed was the Top X Stats php file, which my partner forgot to remove during its uninstallation.

Is there anything esle I need to do??

d8tabyte 10-06-2006 06:57 PM

ummm - ban the ip accessing your information?

DrainBamaged 10-06-2006 07:00 PM

Banned all the members doing it - does that cover the ip?

So far I've:

Shut down the board
Backed up everything important
Banned all members involved
Uninstalled all hacks involved
Deleted all *known* files involved
Notified the other owner

Anything else I need to do?

Revan, I see you're active in this thread - look at the chat please?

DementedMindz 10-06-2006 09:00 PM

update your Top X Stats and your fine

bigmonay2k 10-06-2006 09:22 PM

call the vbulletin police:cool: , j/k






I hope everything work out fine

BlueKnight 10-07-2006 12:14 AM

had this happen a few weeks ago... UGh what a mess. back up everything. shutdown your board should turn off any hooks like flashchat

Ntfu2 10-07-2006 12:25 AM

Flashchat isnt insecure. Its a cms file inside of flashchat that was insecure, but as already mentioned the problem was top x stats

ChavMagnet 10-07-2006 02:17 AM

Flashchat? doesnt this lead your members away from posting in your forums? and from what ive heard its buggy to hell.

DrainBamaged 10-07-2006 04:15 PM

Well, the site was near-dead anyway, it was just luck that made me catch them in the act. I only look at that site about once a month, but still, I don't want it hacked.

I have IPs and server logs, thread titles with URLs in them, etc., so I'm gonna take legal action against these people. I've already contacted one of their ISPs.

As of now, I had my hosting provider (the other owner) suspend the account for that page, because I'm sure they wouldn't accept defeat and stop trying to hack it. Once we decide what we're gonna do with it we'll put it back up.

Anyway, thanks for the help, and any further suggestions would be appreciated.

DementedMindz 10-07-2006 04:17 PM

DrainBamaged update your Top X Stats and it cant happen.

DrainBamaged 10-07-2006 04:28 PM

Alright, I'll add that to the to-do list before the site is re-launched.

cbr929rrerion 10-07-2006 06:01 PM

Thats BS..

I updated my Top X stats and its still happening...

TOP X IS STILL INSECURE AND YES I UPDATE DIT JUST A FEW DAYS AGO to the SO CALLED fixed version

DementedMindz 10-07-2006 06:04 PM

Strange I havent had a problem and yes they have tried. I also did this in Censorship Options I blocked
Code:

{meta} LANGUAGE= {http-equiv} content=0 content="0 <script>

cbr929rrerion 10-07-2006 06:12 PM

Quote:

Originally Posted by DementedMindz
Strange I havent had a problem and yes they have tried. I also did this in Censorship Options I blocked
Code:

{meta} LANGUAGE= {http-equiv} content=0 content="0 <script>

I will try that


All times are GMT. The time now is 02:05 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02990 seconds
  • Memory Usage 1,736KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_code_printable
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (14)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete