vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   my forum got hacked and delete (https://vborg.vbsupport.ru/showthread.php?t=205781)

geevest.com 02-18-2009 11:39 AM

my forum got hacked and delete
 
hello i have a big trouble with my forum.
yesterday i go to internet cafe.and login in to my cpanel forum admincp.
and then in the next 5hours im open my site.
my forum site room got deleted. many room is deleted and my member get banned too.
i take dedicated server for this 309$ / month.
i ask to my support host for backup my database.
they have my last database at 18 februari 2009 (my site got hacked)
and they restore my database.but its not complete because they have my database after hacker deleted my forum.

and now they dont have database again.
what should i do for this? i make my forum for 1year. and i have 25.000 visitor / day.

tq very much.

UncoderMom 02-18-2009 11:43 AM

You dont save monthly backups to your hard drive? Dont they have a back up before Feb 18th?

OUCH

geevest.com 02-18-2009 11:46 AM

backup is everyday.but it always replace from before.

that my support host say :

Quote:

I will try to explain how the cpanel backups work a little better. Every night
a backup is run at 1:00 am. If the weekly backup is a week old, it is replaced
with the nightly backup. If the monthly backup is over a month old, it is also
replaced. This is what happened last night with both the weekly and monthly
backups, so unfortunately, the only backups you currently have are from last
night, and are not old enough for a restore to solve the problems that you are
having.

and now what should i do?

Virtualshiner 02-18-2009 11:48 AM

Do you have any older backups of your site? If not then you may just have to start again.

geevest.com 02-18-2009 11:50 AM

no i dont have backup for my site.
because my host say always backup my database everyday.
and now they say they backup my database everyday but it will be replace from before.

now i really sad.
i make money 2000$/month in this site.
i cant start my forum again.

Virtualshiner 02-18-2009 11:51 AM

They make it everyday however the backup from yesterday is after you were hacked so they can't help you with that as they don't keep every backup for your site.

You would have to start again if you don't have any backup unless you can solve it in any way?

UncoderMom 02-18-2009 11:54 AM

What is in your DB tables on the back up? Anything? Any info?

Is your forum accessible at all? Can you get into your admin cp?

--------------- Added [DATE]1234965282[/DATE] at [TIME]1234965282[/TIME] ---------------

Oooh and its just my opinion that they shouldnt BOTH be replaced in one night. JMO

snakes1100 02-18-2009 11:56 AM

You might want to check the server yourself for older backups as well, without a older backup, you CAN'T restore it back to a point before you go hacked, you can only try to repair the damage they did, move the users back to the groups they were in, then secure the site from that point on, the thread/post loss you will not be able to fix either without a backup.

As well, if they are doing backups with cpanel, cpanel backups are dated and shouldn't be over writing each other on a nightly basis.

geevest.com 02-18-2009 12:03 PM

here i check in my adminlog for hacker :

Code:

37681          zHaZha          01:40, 18th Feb 2009          forum.php          remove          forum id = 252          118.137.3.253
37680        zHaZha        01:40, 18th Feb 2009        forum.php                            118.137.3.253
37679        zHaZha        01:39, 18th Feb 2009        forum.php        kill        forum id = 254        118.137.3.253
37678        zHaZha        01:39, 18th Feb 2009        forum.php        remove        forum id = 254        118.137.3.253
37677        zHaZha        01:38, 18th Feb 2009        forum.php        modify                  118.137.3.253
37676        zHaZha        01:38, 18th Feb 2009        forum.php        modify                  118.137.3.253
37675        zHaZha        01:33, 18th Feb 2009        forum.php        remove        forum id = 74        118.137.3.253
37674        zHaZha        01:33, 18th Feb 2009        forum.php        modify                  118.137.3.253
37673        zHaZha        01:32, 18th Feb 2009        options.php        options                  118.137.3.253
37672        zHaZha        01:31, 18th Feb 2009        forum.php                            118.137.3.253
37671        zHaZha        01:31, 18th Feb 2009        announcement.php        kill        announcement id = 14        118.137.3.253
37670        zHaZha        01:31, 18th Feb 2009        announcement.php        remove        announcement id = 14        118.137.3.253
37669        zHaZha        01:30, 18th Feb 2009        forum.php        modify                  118.137.3.253
37668        zHaZha        01:30, 18th Feb 2009        banning.php        banuser                  118.137.3.253
37696          zHaZha          02:05, 18th Feb 2009          forum.php                                118.137.3.253
37695        zHaZha        02:04, 18th Feb 2009        forum.php        kill        forum id = 200        118.137.3.253
37694        zHaZha        02:04, 18th Feb 2009        forum.php        remove        forum id = 200        118.137.3.253
37693        zHaZha        02:03, 18th Feb 2009        forum.php                            118.137.3.253
37692        zHaZha        02:03, 18th Feb 2009        forum.php        kill        forum id = 131        118.137.3.253
37691        zHaZha        01:59, 18th Feb 2009        forum.php        remove        forum id = 131        118.137.3.253
37690        zHaZha        01:59, 18th Feb 2009        forum.php        modify                  118.137.3.253
37689        zHaZha        01:33, 18th Feb 2009        forum.php        kill        forum id = 74        118.137.3.253
37688        zHaZha        01:38, 18th Feb 2009        forum.php        kill        forum id = 74        118.137.3.253
37687        zHaZha        01:47, 18th Feb 2009        forum.php        remove        forum id = 1        118.137.3.253
37686        zHaZha        01:47, 18th Feb 2009        forum.php                            118.137.3.253
37685        zHaZha        01:45, 18th Feb 2009        forum.php        kill        forum id = 94        118.137.3.253
37684        zHaZha        01:45, 18th Feb 2009        forum.php        remove        forum id = 94        118.137.3.253
37683        zHaZha        01:41, 18th Feb 2009        forum.php                            118.137.3.253
37682        zHaZha        01:40, 18th Feb 2009        forum.php        kill        forum id = 252        118.137.3.253
37711          zHaZha          02:19, 18th Feb 2009          forum.php          remove          forum id = 73          118.137.3.253
37710        zHaZha        02:18, 18th Feb 2009        forum.php                            118.137.3.253
37709        zHaZha        02:14, 18th Feb 2009        forum.php        kill        forum id = 1        118.137.3.253
37708        zHaZha        02:12, 18th Feb 2009        forum.php        kill        forum id = 1        118.137.3.253
37707        zHaZha        01:48, 18th Feb 2009        forum.php        kill        forum id = 1        118.137.3.253
37706        zHaZha        01:58, 18th Feb 2009        forum.php        kill        forum id = 1        118.137.3.253
37705        zHaZha        02:14, 18th Feb 2009        forum.php        kill        forum id = 1        118.137.3.253
37704        zHaZha        02:15, 18th Feb 2009        forum.php        kill        forum id = 1        118.137.3.253
37703        zHaZha        02:12, 18th Feb 2009        forum.php        remove        forum id = 1        118.137.3.253
37702        zHaZha        02:12, 18th Feb 2009        forum.php        modify                  118.137.3.253
37701        zHaZha        02:12, 18th Feb 2009        forum.php                            118.137.3.253
37700        zHaZha        02:08, 18th Feb 2009        forum.php        kill        forum id = 193        118.137.3.253
37699        zHaZha        02:11, 18th Feb 2009        forum.php        kill        forum id = 193        118.137.3.253
37698        zHaZha        02:11, 18th Feb 2009        forum.php        kill        forum id = 193        118.137.3.253
37697        zHaZha        02:07, 18th Feb 2009        forum.php        remove        forum id = 193        118.137.3.253
37726          zHaZha          03:04, 18th Feb 2009          forum.php          modify                    118.137.3.253
37725        zHaZha        03:04, 18th Feb 2009        forum.php        edit        forum id = 250        118.137.3.253
37724        zHaZha        03:03, 18th Feb 2009        forum.php        modify                  118.137.3.253
37723        zHaZha        02:51, 18th Feb 2009        forum.php        remove        forum id = 73        118.137.3.253
37722        zHaZha        02:48, 18th Feb 2009        forum.php                            118.137.3.253
37721        zHaZha        02:43, 18th Feb 2009        forum.php        kill        forum id = 165        118.137.3.253
37720        zHaZha        02:43, 18th Feb 2009        forum.php        kill        forum id = 165        118.137.3.253
37719        zHaZha        02:36, 18th Feb 2009        forum.php        kill        forum id = 165        118.137.3.253
37718        zHaZha        02:38, 18th Feb 2009        forum.php        kill        forum id = 165        118.137.3.253
37717        zHaZha        02:38, 18th Feb 2009        forum.php        kill        forum id = 165        118.137.3.253
37716        zHaZha        02:36, 18th Feb 2009        forum.php        remove        forum id = 165        118.137.3.253
37715        zHaZha        02:34, 18th Feb 2009        forum.php                            118.137.3.253
37714        zHaZha        02:31, 18th Feb 2009        forum.php        kill        forum id = 167        118.137.3.253
37713        zHaZha        02:31, 18th Feb 2009        forum.php        remove        forum id = 167        118.137.3.253
37712        zHaZha        02:31, 18th Feb 2009        forum.php        modify                  118.137.3.253
37741          zHaZha          02:53, 18th Feb 2009          forum.php          kill          forum id = 73          118.137.3.253
37740        zHaZha        02:52, 18th Feb 2009        forum.php        kill        forum id = 73        118.137.3.253
37739        zHaZha        02:23, 18th Feb 2009        forum.php        kill        forum id = 73        118.137.3.253
37738        zHaZha        02:53, 18th Feb 2009        forum.php        kill        forum id = 73        118.137.3.253
37737        zHaZha        02:23, 18th Feb 2009        forum.php        kill        forum id = 73        118.137.3.253
37736        zHaZha        02:19, 18th Feb 2009        forum.php        kill        forum id = 73        118.137.3.253
37735        zHaZha        03:28, 18th Feb 2009        forum.php                            118.137.3.253
37734        zHaZha        03:27, 18th Feb 2009        forum.php        kill        forum id = 18        118.137.3.253
37733        zHaZha        03:27, 18th Feb 2009        forum.php        remove        forum id = 18        118.137.3.253
37732        zHaZha        03:12, 18th Feb 2009        forum.php                            118.137.3.253
37731        zHaZha        03:10, 18th Feb 2009        forum.php        kill        forum id = 149        118.137.3.253
37730        zHaZha        03:06, 18th Feb 2009        forum.php        kill        forum id = 149        118.137.3.253
37729        zHaZha        03:07, 18th Feb 2009        forum.php        kill        forum id = 149        118.137.3.253
37728        zHaZha        03:07, 18th Feb 2009        forum.php        kill        forum id = 149        118.137.3.253
37727        zHaZha        03:06, 18th Feb 2009        forum.php        remove        forum id = 149        118.137.3.253
37756          zHaZha          04:05, 18th Feb 2009          forum.php                                118.137.3.253
37755        zHaZha        04:02, 18th Feb 2009        forum.php        kill        forum id = 60        118.137.3.253
37754        zHaZha        04:03, 18th Feb 2009        forum.php        kill        forum id = 60        118.137.3.253
37753        zHaZha        04:05, 18th Feb 2009        forum.php        kill        forum id = 60        118.137.3.253
37752        zHaZha        04:05, 18th Feb 2009        forum.php        kill        forum id = 60        118.137.3.253
37751        zHaZha        04:03, 18th Feb 2009        forum.php        kill        forum id = 60        118.137.3.253
37750        zHaZha        04:02, 18th Feb 2009        forum.php        remove        forum id = 60        118.137.3.253
37749        zHaZha        04:02, 18th Feb 2009        forum.php                            118.137.3.253
37748        zHaZha        04:00, 18th Feb 2009        forum.php        kill        forum id = 235        118.137.3.253
37747        zHaZha        04:00, 18th Feb 2009        forum.php        remove        forum id = 235        118.137.3.253
37746        zHaZha        03:56, 18th Feb 2009        forum.php                            118.137.3.253
37745        zHaZha        03:56, 18th Feb 2009        forum.php        kill        forum id = 248        118.137.3.253
37744        zHaZha        03:56, 18th Feb 2009        forum.php        remove        forum id = 248        118.137.3.253
37743        zHaZha        03:56, 18th Feb 2009        forum.php        modify                  118.137.3.253
37742        zHaZha        03:55, 18th Feb 2009        forum.php        remove        forum id = 250        118.137.3.253
37771          zHaZha          04:13, 18th Feb 2009          forum.php                                118.137.3.253
37770        zHaZha        04:12, 18th Feb 2009        forum.php        kill        forum id = 84        118.137.3.253
37769        zHaZha        04:12, 18th Feb 2009        forum.php        remove        forum id = 84        118.137.3.253
37768        zHaZha        04:12, 18th Feb 2009        forum.php                            118.137.3.253
37767        zHaZha        04:12, 18th Feb 2009        forum.php        kill        forum id = 107        118.137.3.253
37766        zHaZha        04:12, 18th Feb 2009        forum.php        remove        forum id = 107        118.137.3.253
37765        zHaZha        04:10, 18th Feb 2009        forum.php                            118.137.3.253
37764        zHaZha        04:10, 18th Feb 2009        forum.php        kill        forum id = 243        118.137.3.253
37763        zHaZha        04:10, 18th Feb 2009        forum.php        remove        forum id = 243        118.137.3.253
37762        zHaZha        04:09, 18th Feb 2009        forum.php        modify                  118.137.3.253
37761        zHaZha        04:07, 18th Feb 2009        usergroup.php        modify                  118.137.3.253
37760        zHaZha        04:07, 18th Feb 2009        usergroup.php        update        usergroup id = 5        118.137.3.253
37759        zHaZha        04:06, 18th Feb 2009        usergroup.php        edit        usergroup id = 5        118.137.3.253
37758        zHaZha        04:06, 18th Feb 2009        usergroup.php        modify                  118.137.3.253
37757        zHaZha        04:05, 18th Feb 2009        subscriptions.php        modify                  118.137.3.253
37786          zHaZha          10:24, 18th Feb 2009          user.php          find                    118.137.3.253
37785        zHaZha        10:24, 18th Feb 2009        user.php        find                  118.137.3.253
37784        zHaZha        10:24, 18th Feb 2009        user.php        modify                  118.137.3.253
37783        zHaZha        10:23, 18th Feb 2009        email.php        genlist                  118.137.3.253
37782        zHaZha        10:23, 18th Feb 2009        user.php        changehistory        user id = 3        118.137.3.253
37781        zHaZha        10:22, 18th Feb 2009        user.php        edit        user id = 3        118.137.3.253
37780        zHaZha        10:22, 18th Feb 2009        usertools.php        pmfolderstats        user id = 3        118.137.3.253
37779        zHaZha        10:21, 18th Feb 2009        user.php        changehistory        user id = 3        118.137.3.253
37778        zHaZha        10:21, 18th Feb 2009        user.php        edit        user id = 3        118.137.3.253
37777        zHaZha        10:21, 18th Feb 2009        user.php        pruneusers                  118.137.3.253
37776        zHaZha        10:20, 18th Feb 2009        user.php        prune                  118.137.3.253
37775        zHaZha        10:13, 18th Feb 2009        banning.php                            118.137.3.253
37774        zHaZha        10:12, 18th Feb 2009        banning.php        dobanuser        username = davina        118.137.3.253
37773        zHaZha        10:12, 18th Feb 2009        banning.php        banuser                  118.137.3.253
37772        zHaZha        10:12, 18th Feb 2009        user.php        modify                  118.137.3.253
37801          zHaZha          10:29, 18th Feb 2009          user.php          prune_updateposts                    118.137.3.253
37800        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37799        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37798        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37797        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37796        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37795        zHaZha        10:29, 18th Feb 2009        user.php        dopruneusers                  118.137.3.253
37794        zHaZha        10:28, 18th Feb 2009        user.php        pruneusers                  118.137.3.253
37793        zHaZha        10:27, 18th Feb 2009        user.php        prune                  118.137.3.253
37792        zHaZha        10:27, 18th Feb 2009        banning.php        banuser                  118.137.3.253
37791        zHaZha        10:27, 18th Feb 2009        usertools.php        merge                  118.137.3.253
37790        zHaZha        10:25, 18th Feb 2009        usertools.php        pmuserstats                  118.137.3.253
37789        zHaZha        10:25, 18th Feb 2009        usertools.php        pmstats                  118.137.3.253
37788        zHaZha        10:25, 18th Feb 2009        passwordcheck.php        check                  118.137.3.253
37787        zHaZha        10:25, 18th Feb 2009        passwordcheck.php                            118.137.3.253
37816          zHaZha          10:29, 18th Feb 2009          user.php          prune_updateposts                    118.137.3.253
37815        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37814        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37813        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37812        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37811        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37810        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37809        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37808        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37807        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37806        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37805        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37804        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37803        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37802        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37831          zHaZha          10:30, 18th Feb 2009          user.php          prune_updateposts                    118.137.3.253
37830        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37829        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37828        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37827        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37826        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37825        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37824        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37823        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37822        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37821        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37820        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37819        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37818        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37817        zHaZha        10:29, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37846          zHaZha          10:30, 18th Feb 2009          user.php          prune_updateposts                    118.137.3.253
37845        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37844        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37843        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37842        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37841        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37840        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37839        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37838        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37837        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37836        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37835        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37834        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37833        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37832        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37861          zHaZha          10:35, 18th Feb 2009          help.php          answer                    118.137.3.253
37860        zHaZha        10:34, 18th Feb 2009        user.php        edit        user id = 64606        118.137.3.253
37859        zHaZha        10:34, 18th Feb 2009        user.php        find                  118.137.3.253
37858        zHaZha        10:34, 18th Feb 2009        user.php        modify                  118.137.3.253
37857        zHaZha        10:34, 18th Feb 2009        help.php        answer                  118.137.3.253
37856        zHaZha        10:33, 18th Feb 2009        usertools.php        pmfolderstats        user id = 64606        118.137.3.253
37855        zHaZha        10:33, 18th Feb 2009        user.php        edit        user id = 64606        118.137.3.253
37854        zHaZha        10:32, 18th Feb 2009        user.php        find                  118.137.3.253
37853        zHaZha        10:32, 18th Feb 2009        user.php        modify                  118.137.3.253
37852        zHaZha        10:31, 18th Feb 2009        accessmask.php        modify                  118.137.3.253
37851        zHaZha        10:31, 18th Feb 2009        user.php        prune                  118.137.3.253
37850        zHaZha        10:30, 18th Feb 2009        user.php        prune                  118.137.3.253
37849        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37848        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37847        zHaZha        10:30, 18th Feb 2009        user.php        prune_updateposts                  118.137.3.253
37876          zHaZha          10:42, 18th Feb 2009          banning.php          doliftban          username = Davina          118.137.3.253
37875        zHaZha        10:42, 18th Feb 2009        banning.php        liftban                  118.137.3.253
37874        zHaZha        10:42, 18th Feb 2009        banning.php        modify                  118.137.3.253
37873        zHaZha        10:41, 18th Feb 2009        banning.php        banuser                  118.137.3.253
37872        zHaZha        10:41, 18th Feb 2009        user.php        edit        user id = 64606        118.137.3.253
37871        zHaZha        10:41, 18th Feb 2009        user.php        find                  118.137.3.253
37870        zHaZha        10:41, 18th Feb 2009        user.php        modify                  118.137.3.253
37869        zHaZha        10:36, 18th Feb 2009        user.php        modify        user id = 64606        118.137.3.253
37868        zHaZha        10:36, 18th Feb 2009        user.php        update        user id = 64606        118.137.3.253
37867        zHaZha        10:35, 18th Feb 2009        user.php        edit        user id = 64606        118.137.3.253
37866        zHaZha        10:35, 18th Feb 2009        banning.php                            118.137.3.253
37865        zHaZha        10:35, 18th Feb 2009        banning.php        dobanuser        username = davina        118.137.3.253
37864        zHaZha        10:35, 18th Feb 2009        banning.php        banuser                  118.137.3.253
37863        zHaZha        10:35, 18th Feb 2009        user.php        modify        user id = 64606        118.137.3.253
37862        zHaZha        10:35, 18th Feb 2009        user.php        update        user id = 64606        118.137.3.253
37891          zHaZha          17:19, 18th Feb 2009          options.php          options                    222.124.201.178
37890        zHaZha        17:19, 18th Feb 2009        options.php                            222.124.201.178
37889        zHaZha        17:19, 18th Feb 2009        forum.php        modify                  222.124.201.178
37888        zHaZha        17:19, 18th Feb 2009        options.php        options                  222.124.201.178
37887        zHaZha        17:19, 18th Feb 2009        options.php                            222.124.201.178


hacker delete forum one by one.
they just deleted via admincp. not login in my cpanel host.
now what should i do? i dont have backup database for my forum site.

snakes1100 02-18-2009 12:08 PM

Numerous ppl have already told you what to do.

geevest.com 02-18-2009 12:09 PM

Quote:

Originally Posted by snakes1100 (Post 1747857)
Numerous ppl have already told you what to do.

i dont get what u mean sir.

snakes1100 02-18-2009 12:12 PM

have you even tried to login to the server via ssh and look for a backup older that yesterday?

geevest.com 02-18-2009 12:15 PM

no im not check.do i need to say to my support host?
i think its possible.bcos my support host say they dont have backup again just that. (18 feb 2009 1:00)

Marco van Herwaarden 02-18-2009 12:22 PM

They say they also make weekly and monthly backups, so an older backup should still exist.

Quote:

yesterday i go to internet cafe.and login in to my cpanel forum admincp.
Tip: Never (did i say never?) login to sensitive data while using a PC in an internet cafe. A lot are infected with keyloggers and other malware.

geevest.com 02-18-2009 12:27 PM

yes :( marco. i hate it :(
they dont have any old my database.

Quote:

Hello,

I am sorry, we do not have any other backups to restore for you. You may want
to start periodically downloading your backups to your local workstation or
another server to help prevent this in the future.
Quote:

Hello,

Unless you have another backup the only option would be to reinstall the
forum. I am sorry I could not be of further assistance.
Quote:

Hello,

Without a backup, you may have to manually correct the problems that you were
seeing on the forum. What was the actual damage that was done to your forum?
:(( now i dont know what should i do to make my forum online again.
anyone can give me suggestion for this?

Marco van Herwaarden 02-18-2009 12:31 PM

We can not use some magic to restore things that have been deleted. If they are not there and not in a backup, then it is gone. Not much we can do about that.

snakes1100 02-18-2009 12:32 PM

No Magic? :eek:

geevest.com 02-18-2009 12:34 PM

and now i lost my forum? :((
is there anything that i must do for get my forum back?

nexialys 02-18-2009 12:37 PM

you did not read anything in the words from Marco or the others, didn't you ?!

geevest.com 02-18-2009 12:38 PM

im sorry because im so sad.

nexialys 02-18-2009 12:40 PM

we know the feeling, we all lost something one day, and crashing a forum because of no backup is seen here once per week at least...

your only thing is to re-install your forum entirely, with a clean version, and put an announcement or a notice for all to invite your active users to re-register because of the database death...

did the cracker deleted the entire database, or just the forum content?!

geevest.com 02-18-2009 12:41 PM

my support host say :

Quote:

Hello,

I logged into the server and verified that the daily, weekly, and monthly
backups were all dated February 18, between 1:00 and 3:00 am. You can see the
backups here:

/backup/cpbackup/daily
/backup/cpbackup/weekly
/backup/cpbackup/monthly

snakes1100 02-18-2009 12:45 PM

weekly & monthly backups are just that, weekly and monthly, they should not be over written on a daily basis.

from the sounds of it, your host dont have the backups set correctly in cpanel, i assume the great techs at LW set the server up for you?

geevest.com 02-18-2009 01:32 PM

well they dont hack my forum site.
they just delete any room category in my forum.
they logged in as admin and deleted the forum category.

ssslippy 02-18-2009 01:36 PM

Based off the fact that your weekly monthly and daily backup are all the same u are out of luck. You can check for previous backups I doubt they are there. Your backup schedule also should keep a full weeks(each daily) of data so u can roll back to a non corrupted.

snakes1100 02-18-2009 02:28 PM

Well, as slippy put it as well as myself, the backup system was setup incorrectly in cpanel, it didnt retain anything, it simply was over writing everything on a daily basis, the LW tech that staged this server and setup the backup system, screwed the pooch.

Here is another brief story about LW and its not to bash them, it may be only a few of them that are inept.

Member here gets new server, LW sets up firewall, server runs for crap for 5 days, high loads, users cant get in etc, techs battle this for 5 days!

LW keeps telling her, you need more RAM, here is a price quote for 16gb's 24gb's & 32gb's, mind u she already has 8gb's of RAM lol.

To keep it short, i disabled the firewall addon script ddos.sh (addon for APF) and all was well.

As i stated this isnt to bash LW, i had always heard good things about them, the point is, everyone, you need to make sure your backups are working and that you download them to your computer at home/work or to where ever, do not depend on a 2nd drive, do not depend on a NAS at the host, always get your own copies on a daily basis.

geevest.com 02-18-2009 04:40 PM

hi snakes1100,.thank you very much for helping me.
but now im wait my host.
i dont know this issue is fixed or not. i will give information again in here.

here what my support say :
Quote:

We have a database backup from Feb 18 02:15 for the reza_forum database that
is 213M in size if you would like us to restore this data. The servers backup
system rotated all weekly and monthly archives at that time so nothing older
than that is currently present on the system.
they have my backup database feb 18. 02:15
i hope my database back again.i really pray to god :D
btw i dont know why if i lost my forum and must restore from 6months ago.
thats very sick . i hate it. i build my forum in 1year. :(

--------------- Added [DATE]1234982993[/DATE] at [TIME]1234982993[/TIME] ---------------

oh damn*d my support say :

Quote:

Per your request the rez_forum database backup from Feb 18 02:15 has been
restored. I understand this may not be helpful but it is the only backup data
present on the backup drive. As it has been explained previously, the cpanel
backup function rotated your weekly and monthly backup archives last night.
Here is a listing of the timestamps on each backup file for the reza user:

-rw------- 1 root root 6.4G Feb 18 02:34 /backup/cpbackup/daily/reza.tar.gz
-rw------- 1 root root 6.4G Feb 18 02:34 /backup/cpbackup/monthly/reza.tar.gz
-rw------- 1 root root 6.4G Feb 18 02:34 /backup/cpbackup/weekly/reza.tar.gz

Unless you have an alternate backup source this is all we have to restore your
data from.

TNCclubman 02-18-2009 06:13 PM

you might be able to restore some of it so all may not be lost.

Re-install vBulletin from fresh. Then open up the database they have backed up for you, even if its only half and the rest is lost. check which tables are complete in the backup, copy them to the clipboard, delete the table in your vBulletin with phpmyadmin, and run an sql query in the database (with phpmyadmin) by pasting what you have copied (the single table) in the big white square and click 'write'

Some parts may be saved this way instead of starting over. Hopefully your user table was in tact, thats the most important.

UKBusinessLive 02-18-2009 06:24 PM

So Sad when something like this happens especially with a large site with a regular income :(

The Thing to do, what i do is at least i make a full CPanel Back up and then i download the backup file onto my memory stick and that goes into my safe.

Once a week i do this, you can never reply on your host as this shows, Are you prepared to lose everything because you didn't take 5 minutes to make a remote backup.

Do it Now, go on Make a full backup and burn it to a cd or memory stick and keep it safe.

As for the OP, I hope you can Salvage what you can, My thoughts are with you :(

Kaelon 02-18-2009 06:25 PM

Out of curiosity, do you we know how this forum got hacked? Are other vBulletin forums vulnerable to this?

UKBusinessLive 02-18-2009 06:27 PM

Quote:

Originally Posted by Kaelon (Post 1748276)
Out of curiosity, do you we know how this forum got hacked? Are other vBulletin forums vulnerable to this?

Its in the first Post. Guy goes to internet Cafe and logs into admin cp, Then goes home.

Someone probably logged into his account on the same PC, Perhaps he didn't log off :eek:

I think the admins are more vulnerable than the software

geevest.com 02-18-2009 06:52 PM

im already logout in my admincpanel
i think its because keylogger.

pein87 02-18-2009 07:03 PM

Can I make a suggestion friend if you can afford to pay $300+ a month on a host save up for a few months a buy your own server. php apache and mysql are all free and easy to set up or checp to have installed or you can use lamp or wamp depending on the os you use. Lamp for linux wamp for windows. Then use sql dumper which is awesome and better then phpmyadmin at back ups since it has some things set incase of time outs for php scripts. i use it on my home server and it handles my sites back ups which are about 13MB's or more. I hope this helps you and sets you free from hosted drama.

UKBusinessLive 02-18-2009 07:10 PM

Quote:

Originally Posted by geevest.com (Post 1748315)
im already logout in my admincpanel
i think its because keylogger.

As Marco says, NEVER go into your important files from a Public Computer, its just so Dangerous.

I hope you can salvage something of this :up:

geevest.com 02-19-2009 03:26 AM

yeah and now my support host didnt respect about this.
they never reply my email again (liquidweb)

Marco van Herwaarden 02-19-2009 09:35 AM

In the end it is always your responsibility (read: your loss if things go wrong) to ensure there is a good backup. This will mean:

- Regular checks if your host make the backups he has promissed.
- Regular copy of the backup to a different medium (FTP to your PC, other server (at other hosting), etc..)
- Regular test if the backups are complete and can be used to restore your site.
- Be familiar with the backup schedule and make sure that it fits your needs (how long are you prepaired to rollback in case of an issue)

abdobasha2004 02-19-2009 12:46 PM

In worst case scenario if you cant get the backup be sure you well get back well again with your members, domain, idea ...
My advice is to decrease hosting costs for now
I am sorry I have no idea how you can get the whole forum back
Never ming Keep up the good work
Try to find any back up on your hard drive

ssslippy 02-19-2009 08:28 PM

Normal vbulletin forums are fine but you must be aware of keeping things up to date. Out of date vbulletin is vulnerable. Check what you install and keep things up to date.

ahmed_a_najim 02-22-2009 04:58 AM

Hello
realy i don't know what to say
but is the database you restore it with data or evry think deleted
if you have data you can login to myphpadmin and serach for how the hecker hacked your site and tray to repair the database

i know that the backup is tacking evry day and you must have
daly , weekly , monthly backup
the host must have more the system for backups
if thay don't and you don't have any backup so help you God

please don't loss the hope you must tray again and again .

sory for my bad english

i hope i find a replay from you saing in it the your forum back online

djxcee 02-22-2009 07:23 AM

This is probably the worst situation for any webmaster. Hope all goes well for you.


All times are GMT. The time now is 09:15 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02238 seconds
  • Memory Usage 1,976KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_code_printable
  • (11)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete