![]() |
my vB forums have been hacked - help
I am running vB 3.5.2 on Linux (with a patch from 3.5.3 I believe). Yes, I need to upgrade.
Was hacked: -removed- Can you make suggestions to start? Thanks. No new users listed in the administrator with admin rights, but there is a suspicious high-ID entry in table VBADMINISTRATOR. blakespot Look at source for page now - last line: Code:
<table cellpadding="0" cellspacing="0" border="0"> blakespot |
someone edited your forum title and replaced the text with a redirect...
that's the one thing you have to edit.. the forumid #10.. change its title. |
Quote:
Thoughts? Thanks. blakespot |
this is what we call an exploit... ;)
|
Also, I changed them back in the VBFORUM table, but the page still renders with the redirrects as the forum titles?! Is there some cache mechanism I must flush? Thanks.
blakespot |
you have to edit it from the admincp, not the database... and to be sure, post a new thread in that forum so the cache is updated there too.. :)
|
I can't edit it from the adminCP - the frame redirects to the hack site, as it renders the title as HTML, forcing a redirect... Can I not flush the cache another way? I've changed the names in the DB. Thanks.
Will but and upgrade to latest tonight... If I can get this clean first. blakespot |
I would be more worried about how they edited the forum title in the first place...
Go into your database and remove the redirect, and then go into ACP > Maintenance > Update Counters > Rebuild Forum Information. |
Thanks - I'll update tonight.
blakespot |
Upgraded to 3.6.5. Hopefully that exploit was addressed. I see reports of a Calendar vulnerability of that sort, but can't find reference to a forum-title vulnerability...
blakespot |
All times are GMT. The time now is 08:38 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|