vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Forum and Server Management (https://vborg.vbsupport.ru/forumdisplay.php?f=232)
-   -   Site Hacked (https://vborg.vbsupport.ru/showthread.php?t=182560)

danielc2384 06-15-2008 12:41 PM

Site Hacked
 
I logged onto my forum a few minutes ago www.dollhousetvforum.com and it looks like I was hacked. A pop up box appears saying "you niggers got ******".
I'm really not sure what has happened or what to do.

I contacted my host and they basically offered no help.

What should I do?

Thanks

Baldilocks 06-15-2008 12:43 PM

Did you try re-uploading your index.php file?

danielc2384 06-15-2008 01:29 PM

Yep. No luck.

SEOvB 06-15-2008 01:47 PM

remove any .htaccess file and make sure you dont have any extra plugins that shouldn't be at global start

MTA-RP 06-15-2008 01:47 PM

Edit the .httaccess or w/e it's called.

danielc2384 06-15-2008 01:52 PM

I removed the .htaccess file from /public_html/
Still no luck.

My forum is stored in /public_html/dollhousetvforum/ and there is no .htaccess file in there.

ssslippy 06-15-2008 02:04 PM

I recomend you reupload all your files, and check for mods with security issues. Make sure you are also running the latest vb.

You can put a password require inside php files.

danielc2384 06-15-2008 02:09 PM

Quote:

Originally Posted by ssslippy (Post 1549980)
I recomend you reupload all your files, and check for mods with security issues. Make sure you are also running the latest vb.

You can put a password require inside php files.

In the process of upgrading from 3.7.0 to 3.7.1 now.
*crosses fingers*

How could they set up this password require without ftp access?

If they have the ftp info wouldn't they have changed the passwords and done more damage?

ssslippy 06-15-2008 02:12 PM

They dont always change the passwords. They could of also done a file insert cause you have HTML enabled somewhere on your forums. Lots of things can be done.

You should change your passwords.

Also what mods are you running?

danielc2384 06-15-2008 02:16 PM

Quote:

Originally Posted by ssslippy (Post 1549989)
They dont always change the passwords. They could of also done a file insert cause you have HTML enabled somewhere on your forums. Lots of things can be done.

You should change your passwords.

Also what mods are you running?

Thanks for the info.

Passwords have all been changed.



-------------------


Here is a list of the mods:

Admin Log In As User 3.0 This hack will allow admins to log in as any user.

Automatic Welcome PM 1.0.4 This Hack will automatically send welcome PMs to new members.

Bills PayPal Donate 1.32.366 Bills PayPal Donate

BuRaCH G?lgeli Kullan?c? Ba?l?g? 3.6.x.1.0.0 Sitenizdeki Kullan?c? isimlerini g?lgeli yapar.

Cyb - Advanced 'New Posts' 2.1 Cyb - Advanced 'New Posts'

Cyb - Auto Birthday Greeter 1.3 Cyb - Auto Birthday Greeter

Cyb - ChatBox 1.9.9 Cyb - ChatBox

Cyb - Sub-Forum Manager 2.5 Cyb - Sub-Forum Manager

EzIRC 1.0.3 IRC Chat Addon for vBulletin

Fake Users 1.0.0 Fake Users

Flashchat Integration 3.55 Integration of Flashchat and vBulletin 3.6

Form Hack 4.0 Create a form.

FractalizeR: Registration Form AJAX Enchancements 1.0 Enchances registration form with AJAX

HelpCenter 1.00 RC 1 A Support Ticket System!

Image Resizer 1.0.2 Automatically resizes images in posts!

Inferno vBShout Lite 2.5.0 Real time shoutbox

JustJoin 1.0.0 Just join us

KC - Announcement 1.0.0 Announcements by Kiril Cvetkov

Limited Guest Viewing 1.0.6 Limit guests to view a set number of threads before being locked out.

Members who have Visited 3.7.003 Display members who have visited the forum.

passiveVid 1.1.2 Automaticlly turns video links like youtube, myspace videos, google vidoes into the video players.

PhotoPlog 2.0.7 PhotoPlog: The Lite Gallery

Post Thank You Hack 7.4 Post Thank You Hack

Quick Reply Add On. 3.6.x Add On Editor Tools for Quickreply.

Site Life Status 1.0.4 This will tell you how long your site has been up and running.

Time Greeting 0.06 Changes "Welcome" to "Good Morning/Afternoon/Evening" in the navbar

UA sidebar 3.0.7

Usergroup Color Bar 1.0.0

v3 Arcade 1.0.7 A multiplayer gaming system for your vBulletin forum.

vB News Ticker 1.2 Latest News in a Ticker

vBExperience 3.7.12 Calculate activity of your users

vBExperience Level 2.0 vBExperience Level

Video Gallery 3.0B A video gallery hack that uses Video Sharing sites for hosting.

Yet Another Award System 3.6 2.1.4 Admin can give members awards, and award

ZH - No Avatar 1.0.0 If a member doesn't have an avatar a no avatar image appears

Zoints Profile System 2.1.4 The Zoints client forum profile linking system.

[Sniper] - Mood Manager 1.2.5 Allows users to manage there mood

--------------- Added [DATE]1213544292[/DATE] at [TIME]1213544292[/TIME] ---------------

I am currently updating to 3.7.1 and while uploading files I returned to the index page and the popup authorization box seems to have gone. The IP displayed on the popup authorization was 67.228.190.70

Instead of the page saying "done" when finished loading on the bottom left hand side of the browser, it says "connecting to 67.228.190.70".

hmmm

ssslippy 06-15-2008 03:07 PM

I recomend this, go through all your mods. See if they are in the graveyard. Update as needed. Also check your admin email for mysql errors.

danielc2384 06-15-2008 03:15 PM

Quote:

Originally Posted by ssslippy (Post 1550041)
I recomend this, go through all your mods. See if they are in the graveyard. Update as needed. Also check your admin email for mysql errors.

I hadn't checked my email for a few days and just found that my inbox is full of sql errors.
At least 100 emails saying "vBulletin Database Error!".

The emails read:

"Database error in vBulletin :

mysql_connect() [<a
href='function.mysql-connect'>function.mysql-connect</a>]: Can't
connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (2)
/home/********/public_html/dollhousetvforum/includes/class_core.php on line 311

MySQL Error :
Error Number :
Request Date : Thursday, June 12th 2008 @ 01:40:44 AM
Error Date : Thursday, June 12th 2008 @ 01:40:44 AM
Script : [B]http://www.dollhousetvforum.com/infernoshout.php[/url]
Referrer : http://www.dollhousetvforum.com/index.php
IP Address : *********
Username :
Classname : **********
MySQL Version :




Ok, I think we may be on to something.
"infernoshout.php" is a mod. Could that be causing the problem?

The latest message in the shout box was:



Shoutbox

Active Users: 0

Shoutbox Notice:
[Today 05:43 AM] *****:
[Today 05:42 AM] *****:
[Today 05:41 AM] *****:


That member (censored his name as ****) was banned by a moderator today.
He was the last person active in the shoutbox.
I'm guessing he did something through the shoutbox.



edit:

I just uninstalled the shoutbox and I am now receiving this email:

Code:

Database error in vBulletin 3.7.1:

Invalid SQL:

                        select s.*, u.username, u.displaygroupid, u.usergroupid, u.userid, o.*
                        from vb_infernoshout s
                        left join vb_user u on (u.userid = s.s_user)
                        left join vb_infernoshoutusers o on (o.s_user = s.s_user)
                        where
                        (
                                (s.s_private = -1)
                                OR
                                (s.s_private = '1')
                                OR
                                (s.s_private <> -1 AND s.s_user = '1')
                        )

                       
                        order by s.s_time desc
                        limit 20;

MySQL Error  : Table '******_vbulletin.vb_infernoshout' doesn't exist
Error Number  : 1146
Request Date  : Sunday, June 15th 2008 @ 09:23:54 AM
Error Date    : Sunday, June 15th 2008 @ 09:23:54 AM
Script        : http://www.dollhousetvforum.com/infernoshout.php
Referrer      : ***************
IP Address    : *****
Username      : *****
Classname    : ******
MySQL Version : 5.0.45-community


ssslippy 06-15-2008 03:36 PM

There is no exploits that I know of infernoshout however I would recomend you update to the latest version.

If you are uninstalling it you should also remove all the files associated with it.

danielc2384 06-15-2008 03:50 PM

Quote:

Originally Posted by ssslippy (Post 1550059)
There is no exploits that I know of infernoshout however I would recomend you update to the latest version.

If you are uninstalling it you should also remove all the files associated with it.

I don't think I'm going to bring it back since all my emails are linked to it.

I was running the 3.6 version of the mod. I then upgraded vBulletin to 3.7 and forgot to update the shoutbox. Not sure if that caused the problem.

Thanks for the help.

Much appreciated :)

ssslippy 06-15-2008 04:26 PM

I am part of the support team for infernotech and the mod runs fine however the 3.6 version which is no longer supported was not fully compatible with 3.7 due to the changes made in vb on how you could store options. Only issue I know of.

danielc2384 06-15-2008 04:46 PM

By reading this error code that was sent to my inbox, are you able to see what could have gone wrong with the shoutbox?

mysql_connect() [<a
href='function.mysql-connect'>function.mysql-connect</a>]: Can't
connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (2)
/home/******/public_html/dollhousetvforum/includes/class_core.php on line 311

MySQL Error :
Error Number :
Request Date : Thursday, June 12th 2008 @ 01:40:41 AM
Error Date : Thursday, June 12th 2008 @ 01:40:41 AM
Script : http://www.dollhousetvforum.com/infernoshout.php
Referrer : http://www.dollhousetvforum.com/index.php
IP Address : *******
Username :
Classname : *******
MySQL Version :

Scared56 06-15-2008 08:44 PM

All I can figure out is that it isn't connecting to your mySQL database correctly.

Possible problems could be the information was not entered correctly or the mySQL process was down. (Process as in where it was being hosted)

SEOvB 06-15-2008 08:48 PM

Quote:

Originally Posted by danielc2384 (Post 1550125)
By reading this error code that was sent to my inbox, are you able to see what could have gone wrong with the shoutbox?

mysql_connect() [<a
href='function.mysql-connect'>function.mysql-connect</a>]: Can't
connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (2)
/home/******/public_html/dollhousetvforum/includes/class_core.php on line 311

MySQL Error :
Error Number :
Request Date : Thursday, June 12th 2008 @ 01:40:41 AM
Error Date : Thursday, June 12th 2008 @ 01:40:41 AM
Script : http://www.dollhousetvforum.com/infernoshout.php
Referrer : http://www.dollhousetvforum.com/index.php
IP Address : *******
Username :
Classname : *******
MySQL Version :

your mysql server was down, not running, or lost its connection.

Vackrick 06-16-2008 02:15 AM

I Think U Got Ddos Attack

danielc2384 06-16-2008 02:20 AM

Thanks everyone for the info.

Question, if it was a Ddos Attack, is there a way of preventing them?

Boofo 06-16-2008 03:23 AM

Get a good firewall router or software firewall.

Dismounted 06-16-2008 06:13 AM

It is not necessarily a DDoS attack. The error simply implies that the MySQL daemon was down.

underdog1954 06-17-2008 03:28 AM

If you were running 3.6 before, be sure your config.php is the one that came with the 3.7 version... There is a difference, and that might be part of it, however, I've found that a lot of the older 3.6 mods are not compatible with 3.7... I recommend uninstalling your mods, and using only those that are 3.7 compatible... You'd be surprised and the difference they make. Just a suggestion...

:)

underdog

karnevil 06-17-2008 03:46 AM

Hi

We had that same error messsage getting progressively more regular - logging everyone out and putting the site down for up to five minutes a time.

''lost connection to mysql etc class_core line 311.''

We unistalled all our mods etc tried everything but still happened. We have moved to a different mysql server and thats fixed it, with all our mods back on.

I dont think its DDoS - we had a DDoS and our server host shut our site down for too much traffic. Which was helpful not.

ssslippy 06-17-2008 09:40 PM

It sounds like your MySQL was down or you could of hit a limit that your host has put in. Since shoutboxes tend to refresh often especially if you are running with AOP on it will rip your server up.

geevest.com 06-19-2008 01:22 AM

danielc u installed so many plugin in ur site.

Angel-Wings 06-22-2008 03:37 PM

Well - it's no dDOS attack - how to attack MySQL socket ? If it's really dDOS - which I highly doubt - it's an attack on the webserver though it seems that was running.
Second - don't waste your time with a firewall - this won't help at all against script based attacks and for sure not against Denial of Service attacks - except you block everything ;)
About the problem - reupload all files taken from the original sources and only from there. Then try to run some MySQL optimization scripts to see if there's a bottleneck somewhere.
Also - check if HTML is enabled anywhere (Posts, Signatures etc.) - if so - it maybe wasn't a real attack, someone could post:

Quote:

<html>
<head>
<script type="text/javascript">
alert("You got hacked");
</script>
</head>
<body></body></html>
Which is neither a security problem nor a hack. ;)

adamenty 09-07-2008 06:46 AM

Glad to see your forum is back up :)

gdoner 09-14-2008 12:14 AM

you are using too many mods.

Kinneas 09-16-2008 09:51 AM

Quote:

Originally Posted by gdoner (Post 1621598)
you are using too many mods.

Says who?


All times are GMT. The time now is 04:54 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01318 seconds
  • Memory Usage 1,817KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_code_printable
  • (7)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (30)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete