vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Forum Hacked - Password Harvesting Plugin Installed (https://vborg.vbsupport.ru/showthread.php?t=150316)

mawby 06-21-2007 08:22 PM

Forum Hacked - Password Harvesting Plugin Installed
 
I spotted a plugin installed on my site today which I didn't recognise. It was named "Database Optimization", had vBulletin as the product, and was hooked into login_verify_success. The plugin was only a few lines of code, but it sent an email containing the users username and password everytime they logged into the forum!

After some investigations we've found that this hack started sending emails on the 17th at 4am GMT. At this time our server was running 3.6.4, with all released security fixes installed. We upgraded to 3.6.7 yesterday after a required PHP upgrade was done. At this point the hack no longer sent the users password out, so I presume a fix has been made to prevent plugins gaining access to the users passwords now.

However, I'm making this post firstly to alert others to the possible problem, but also to ask if anyone else has suffered from this type of hacking and does anyone know how it was done so I can try and make sure it doesn't happen again?

We had the following plugins installed;

'Version check' for all hacks
Ban Thread User
CSS Signature Size Enforcer
Cyb - Sub-Forum Manager
Extra Thread Fields Lite
Farcaster's Event Attendance
Geek Auto-Link
HELLCATs Realtime Page Compressor
ibProArcade for vBulletin
IpInfo
iTrader
Moderation Auto-PM
Post Edit History
Private Debates
Show Birthday Icon in Postbit
vbAccessDenied
vBadvanced CMPS
vbBannerRotator by Frapegliko
vBDebug Mode
vBPicGallery
Vbulletin World Map Plotter
Welcome Headers
Yet Another Mass Private Message System

Paul M 06-21-2007 09:45 PM

Nothing has changed around that hook between 3.6.4 and 3.6.7 so something else must have stopped it working.

mawby 06-22-2007 07:12 AM

Quote:

Originally Posted by Paul M (Post 1273545)
Nothing has changed around that hook between 3.6.4 and 3.6.7 so something else must have stopped it working.

That is what is worrying me and is one reason I've posted up about it. Having looked at the diffs myself I cannot see why this stopped working, but it did.

As you're an admin here I will PM you the contents of the plugin, maybe you could take a quick look and give your opinion if this hack is a problem in vB (past or present) or whether it only worked because of some other plugin I had installed.

As part of my upgrade I did make the following changes to the plugins I had installed so maybe one of these is the reason the hack stopped working?

Removed Chatbox 1.4
Updated Cyb - Forumhome Sub-Forums Manager from 2.1 to 2.4
Updated Farcaster's Event Attendance from 1.2.0 to 1.2.1
Updated vBPicGallery from 10.0.3 to 10.0.4
Updated vBadvanced CMPS from 2.2.1 (vB 3.6) to 3.0 RC1

G0F0RBR0KE 06-22-2007 07:23 AM

When it sends e-mail to users. What does the e-mail say?

mawby 06-22-2007 07:29 AM

Quote:

Originally Posted by EvilAkuma (Post 1273790)
When it sends e-mail to users. What does the e-mail say?

The subject is the users username, the contents is the users plain text password, nothing else is sent in the email.


All times are GMT. The time now is 05:28 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01673 seconds
  • Memory Usage 1,729KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (5)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete