vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Website hacked! (https://vborg.vbsupport.ru/showthread.php?t=119779)

Heidrich 06-28-2006 12:04 PM

Website hacked!
 
My website has been hacked by some turkish group. :mad: Someone registered at my site. When i connected to my sql directly i found they had changed userid 1, the admin...

I had the following:

vBulletin 3.5.4
vBadvanced 2.1.0
DLM manager
VBgameserver hack
Teamspeak display hack

My best guess is they used some exploit in the vb gameserver hack. I'm now resetting my site using only:

vBulletin 3.5.4
vBadvanced 2.1.0
DLM manager

Are these three secure enough to use at this moment without getting hacked?

Second i used Mysql front to make back-ups of my database. Yesterday i used the same program to restore the sql file and guess what it didn't work :mad:

Because i just switched to vBulletin from phpnuke i had the phpnuke database which i could use, so only lost 2 weeks of data.

My second question what is a good program to use to back up your database and to restore it. PhPmyadmin is no option because i don't want it installed on my webspace. The only thing it will do is add another why to kill off my database. :confused: Another vB user pointed out to ssh, but are there any good programs out there that would do the job?

Thanks for all the help, i really need it!!!

Marco van Herwaarden 06-28-2006 02:09 PM

I can only say that vBulletin 3.5.4 should be secure enough, there are no known security issues. About the other 2 i can't make a judgement.

Back ups (if you host don't make them yet) can best be made from the shell. Beside a terminal emulation programm, no other software needed.

For instructions see the chapters in the vBulletin manual:
Backing-up your MySQL Database Manually
Restoring your MySQL Database Manually

davidw 06-28-2006 04:23 PM

Did you have SSH or telnet enabled?

Andromeda2875 06-28-2006 04:38 PM

This is precisely the same thing that happened to me that I made a post about here and got my butt chewed out for it.

davidw 06-28-2006 05:12 PM

With all due respect, your statements in thread
Quote:

Is this really how crappy vbulletin is? I mean You can not fix security holes in the software. Very unhappy. I may have to go to IPB. Terribly disappointing.
here made an attempt at lashing out at the software without regards to investigating the problem, is NOT
Quote:

Originally Posted by Andromeda2875
precisely the same thing

as stated. In this thread, the poster is requesting help. I had to do some research to find that thread as I was unfamiliar with it.

Please either stay on topic and offer assistance or do not respond. If you would like to discuss this further, please PM me.

Zachery 06-28-2006 08:45 PM

Aside from all of the bashing there was quiet a few good suggestions and pratices that could have been taken and followed.

Andromeda2875 06-28-2006 09:29 PM

I did take all the steps that where offered to me.

Trana 06-28-2006 10:57 PM

Quote:

Originally Posted by Andromeda2875
I did take all the steps that where offered to me.

No, you insisted that it was a security hole in VB amid continuous suggestions that the problem lay elsewhere. Then you claimed that people were attacking you when they offered up any other possible explanation.

So what happened? Did you find out who was hacking your server every day? Where was the vulnerability?

davidw 06-29-2006 12:55 AM

Heidrich, I was on phpNuke when I was brutally hacked and from the way it is being described, my attack was similar to yours. One thing I took note of was SSH traffic. I had previously been hacked once before, a minor defacing, but I made note of the SSH traffic on that as well. This time it was much larger. It was then I requested my SSH and telnet disabled - in fact, all avenues of access other than ftp and http closed. Knock on wood, I've not had anything happen since. It was this last hacking that I had decided to move to vbulletin - away from phpNuke. Fortunately, since I worked for my ISP, and we were going to migrate to a newer box anyways, I built our next hosting box. The crack had corrupted the old mysql database. Even recreating the site wouldn't fix it. I hope your fix is easier than mine was.

Andromeda2875 06-29-2006 03:17 AM

Quote:

Originally Posted by Trana
No, you insisted that it was a security hole in VB amid continuous suggestions that the problem lay elsewhere. Then you claimed that people were attacking you when they offered up any other possible explanation.

So what happened? Did you find out who was hacking your server every day? Where was the vulnerability?


As I stated, it was vbulletin.


All times are GMT. The time now is 01:01 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01519 seconds
  • Memory Usage 1,739KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (4)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete