vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Help - Forum Being hacked? (https://vborg.vbsupport.ru/showthread.php?t=175203)

lfpm 04-05-2008 09:26 AM

Help - Forum Being hacked?
 
Our Forum is being hacked or something?

Many members, without their knowledge are posting a smile which includes somekind of a link, anyone who opens that page, a popup appears and asks for the username and password, the popup location is on another site and when the members insert their username and password, the other site is getting them:

Here is an image (forum.tayyar.org is our forum url, while alhms.com is the site that is hacking us?)

http://forum.tayyar.org/h1.gif

This is the smile that is appearing in many threads and PMs by the members (the members are not aware that they are inserting it)

http://forum.tayyar.org/h2.gif

The smile contains this link: http://www.alhms.com/jz/smile.gif (click on it and the pop up will appear)

Any idea what is happening and how can i stop it?

Thank you

Opserty 04-05-2008 09:33 AM

You need to figure how the smilie is getting into the posts and messages. Disable your modifications and see if it still appears. What version of vBulletin are you running?

Tell your members not to enter their details, I think the domain/folder on which the image is hosted is protected by a login. Whether the site is collecting the Login Information I don't know.

But as you have correctly identified, the problem is with that image. That is what is causing the login to appear, you need to find out how it is getting there.

lfpm 04-05-2008 09:55 AM

The person who is doing it opened an account and posted that he is doing it, his IP match with several other IPs that our members posted with that smile (they told me they did not post, they inserted their username and password when the page poped up).

Now i turned the Forum off, and disabled all the modifications and tried to open a page, the pop up is still showing.

SEOvB 04-05-2008 09:59 AM

you need to remove the image from the posts

lfpm 04-05-2008 10:03 AM

Quote:

Originally Posted by FRDS (Post 1483483)
you need to remove the image from the posts

we are doing that, we emailed the person with his IP that he has 1 hour to disable what he is doing or we will report his IP to the authorities, http://www.alhms.com/jz/smile.gif is now not asking for username and pasword (he removed it) and we opened the Forum back:

http://forum.tayyar.org/f8/bug-reporting-33058/

Marco van Herwaarden 04-05-2008 10:14 AM

Quote:

Originally Posted by lfpm (Post 1483481)
The person who is doing it opened an account and posted that he is doing it, his IP match with several other IPs that our members posted with that smile (they told me they did not post, they inserted their username and password when the page poped up).

So you are saying that he used the accounts of other members to make those posts? Did he maybe steal their login info with that login popup?

lfpm 04-05-2008 10:42 AM

Ok, here is the source of the hacker: http://lebforces.org/forum/showthread.php?t=31501

When the pop up came up, i inserted the following "212.107.116.238 proxy4.cyberia.net.sa"

Now that use who opened that thread in the above link is putting what i sent.

--------------- Added [DATE]1207400355[/DATE] at [TIME]1207400355[/TIME] ---------------

Here is what is happening, first a user (the hacker) is a manually inserting a picture (the Smile), the picture contains link and when someone opens the thread, the pop up appears, members are seeing the pop up and inserting the username and password, the username and password is going to the hacker, who is using them and posting more of the same.

We know the source, but how can we stop it? I disabled html and it is still happening

Marco van Herwaarden 04-05-2008 02:22 PM

You can not stop this unless you disable external images completly.

The best is to educate your members never to enter their board details when presented with an unexpected password popup.

SEOvB 04-05-2008 02:39 PM

Ban his IP at the server level, I'm sure he'll get around it, then use a replacement variable to rename the image link, censor the domain its coming from, umm thats all i can think of that may help short of disabling all external images till he moves on.

lfpm 04-05-2008 03:08 PM

Quote:

Originally Posted by Marco van Herwaarden (Post 1483648)
You can not stop this unless you disable external images completly.

The best is to educate your members never to enter their board details when presented with an unexpected password popup.

Quote:

Originally Posted by FRDS (Post 1483660)
Ban his IP at the server level, I'm sure he'll get around it, then use a replacement variable to rename the image link, censor the domain its coming from, umm thats all i can think of that may help short of disabling all external images till he moves on.

Done all that,

Thank you


All times are GMT. The time now is 01:00 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01598 seconds
  • Memory Usage 1,737KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (4)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete