![]() |
Need Help about hacking
Hello all i have a problem today i got so many email about database errors
i think someone try to hack but fail not complete sure i got this emails Code:
Database error in vBulletin 4.2.0: Code:
Database error in vBulletin 4.2.0: Code:
Database error in vBulletin 4.2.0: Some one try to hack me ? Someone got my database ? any help |
You had better update and patch ASAP: http://www.vbulletin.com/forum/forum...or-vbulletin-4
|
Check for a new plugin added named "vbulletin" in the hook location "init_startup" containing a load of base64 encoded stuff, if it's there you have been hacked and you should disable/remove it and have a check for any files uploaded to your forum (left menu -> maintenance -> diagnostics -> suspect file versions)
|
how i check in "vbulletin" in the hook location "init_startup" containing a load of base64 encoded stuff ???
|
From the admincp go to plugin manager in the left column then check for a product titled "vbulletin" that has the hook location "init_startup", click edit and if in contains the word base64 and a load of random text then you need to disable it.
|
If you need help let me know.. Definitely follow the above advice asap. Also disable forumrunner until you upodate.
|
Delete the forumrunner directory or rename it to something random asap in case you haven't patched it yet.
|
Quote:
|
Quote:
What some have been doing is injecting their base64 code at the very bottom (scroll to find, they add tons of white space so you won't notice right off the bat unless you scroll down, i.e. if a scrollbar exist when viewing via phpmyadmin, scroll scroll scroll :cool:) and more so we see this with myfilestore than any other type of exploit (also if you're dealing with that in particular, myfilestore redirect then also check the file datastore_cache.php which is located in /includes/datastore/ for any mal code). |
There is a good chance that debase64 code was already added to all of the files as well at this point.
--------------- Added [DATE]1468970657[/DATE] at [TIME]1468970657[/TIME] --------------- Quote:
|
Quote:
https://vborg.vbsupport.ru/external/2016/07/7.png @RichiBoy67' Already disable Forumrunner can i delete all forumrunner files ? https://vborg.vbsupport.ru/external/2016/07/8.png --------------- Added [DATE]1469003640[/DATE] at [TIME]1469003640[/TIME] --------------- Superman, i really dont know what you say because you write so many words and my english is not good and i am little confuse please give me the perfect idea :( Can i delete forumrunner files ? or install the patch because i dont want to upgrade my VB version at this time i have 4.2.0 and many addons working fine, if i update my VB after some addons are not working so need a help for my confusion |
@tanzeelniazi
Yes, you can go ahead & delete forumrunner directory. You won't break any add on by upgrading to 4.2.0 to the latest. Make sure your on php5.4.0 or greater. Always have a backup before upgrading. |
I see some addons are not update for 4.2.2 etc so i can not upgrade my VB.
If i remove forumrunner directory after my problem will be solved ? --------------- Added [DATE]1469016443[/DATE] at [TIME]1469016443[/TIME] --------------- Now delete forumrunner dir Now i safe ? |
Quote:
However, since you are running vB 4.2.0, you are not safe, it has other security holes, patched in later versions. |
You need to upgrade and if they added a plug in or injected any debase64 code into your files you still have an issue..
|
my forum is safe from other methods but now i get 1 more error
yesterday i delete forumrunner directory but today 1 more error is coming Code:
Database error in vBulletin 4.2.0: |
Quote:
|
I just delete forumrunner folder from cpanel, i think its the only 1 folder name is forumrunner so already delete
|
Did you uninstall the plug in before removing the files?
|
No i just disable after remove forumrunner folder, its mean first i uninstall then remove ?
|
Exactly. :)
|
I use this piece of PHP code to find base64 and other uglies that might have been injected or placed on my server.
Note: This will not look through your hooks, this looks through all the PHP files on your server. It'll most likely bring up a large list, so I recommend skimming through the list and finding anything that mentions base64_decode() Then open up that file and find the base64 string in it and decode it yourself with an online decoder or using the php base64_decode($string) Place this in your forum root and then navigate to it ( http://www.yourforumhere.com/base64-check.php best of luck: base64-check.php PHP Code:
|
All times are GMT. The time now is 07:42 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|