vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Site hacked (https://vborg.vbsupport.ru/showthread.php?t=307285)

Big Country 01-21-2014 02:46 AM

Site hacked
 
TONS of SPAM, 1000's of blog entries, and the freaky thing is there is a "new administrator".
"aku" no IP addy, nothing, I have no idea HOW it got there.
anyways. deleted some users and I noticed that I was NOT able to delete one user, no matter how many times I tried, the user would still be there.
using Spam-O-Matic,, guess that has been defeated given the number of new users.

questions, HOW do I mass delete blogs?

I shut down the site and some of these spammers are STILL posting blogs while the site is down :mad:.

help WOULD be appreciated. thanks.

ozzy47 01-21-2014 02:49 AM

Please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site
Also please see these recent security announcements:
vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5
vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions

Big Country 01-21-2014 02:55 AM

Quote:

Originally Posted by ozzy47 (Post 2475716)
Please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site
Also please see these recent security announcements:
vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5
vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions

thank you, still fishing for a way to kill all the blogs.

ozzy47 01-21-2014 03:05 AM

I would start by securing the site first, then repair the damage.

ForceHSS 01-21-2014 03:07 AM

Check in plugin manager hackers add there own sometimes so if removed then can make more accounts.

Big Country 01-21-2014 03:19 AM

thanks guys, working on it, guess Ill be down for a few days while I tackle things.
:mad:

ozzy47 01-21-2014 03:25 AM

Yeah unfortunately these things tend to happen sometimes, just make sure you follow everything thoroughly, or you will have more problems.

New Joe 01-21-2014 05:42 AM

Do you have a back up of the data base before the hack?
maybe that could help if you did.

Big Country 01-21-2014 06:33 PM

sadly I do not have recent back ups.

getting errors when prunning/deleting some users
Quote:

Deleting User JesseLowe
Fatal error: Call to a member function query_read() on a non-object in /home1/*/***/public_html/includes/class_dm_blog_user.php on line 218

tbworld 01-21-2014 10:33 PM

Most good hosting services retain a backup for their own purpose. There is usually a fee involved for retrieving your database/files from their backup system, unless it is included in your host service pack. Depending on the size of your board this might be an option for you.

ozzy47 01-21-2014 10:44 PM

Problem is there is no telling if the issue was in the backup or not.

tbworld 01-21-2014 11:13 PM

Quote:

Originally Posted by ozzy47 (Post 2475862)
Problem is there is no telling if the issue was in the backup or not.

True, True - The infection date would have to be known. Usually, the service is not cheap either since they have to parse the backup image.:)

ozzy47 01-21-2014 11:16 PM

I still would like to know what allowed them in, probably the install folder was still there sounds like.

tbworld 01-21-2014 11:19 PM

Quote:

Originally Posted by ozzy47 (Post 2475862)
Problem is there is no telling if the issue was in the backup or not.

True, True - The infection date would have to be known. If backups are not included in your service package, it can get quite pricey: as they usually have to parse the backup image. :)

Big Country 01-26-2014 01:28 AM

well, to a degree, its good I have very few actual members, most joined when the forum started, so anyone with user ID past 10 needs to go, I need to find out a way to delete ALL blogs and ALL members, Ill just make the few original members back .
wondering if it might be easier to use a new database.

no backups, hostgator only archives 1 wwek orso I was told. the forum was left alone for a long time as we had many other things to deal with and just noticed this mess.

going to the blogs section is a mess
http://www.patraditionalbowhunters.com/blog.php

no user names attached to blogs, my permissions should not allow this.

seems we got hacked right around SEPT of last year, no one noticed as we were not active for a long time.


still getting errors tryong to delete some users using the "prune" function

Deleting User VerlaQQJB
Fatal error: Call to a member function query_read() on a non-object in /home1/***/public_html/includes/class_dm_blog_user.php on line 218


All times are GMT. The time now is 11:44 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01104 seconds
  • Memory Usage 1,748KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (4)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (15)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete