vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Hacked, Found these Files (https://vborg.vbsupport.ru/showthread.php?t=192080)

joethaman 09-27-2008 09:34 PM

Hacked, Found these Files
 
So, I was hackedlast night and was going through the files and found these in the forum/signatures directory. My question is how they actually got into this directory and how can I keep this from happening again?

They all seem to be hacking files.

2008.sct.php
Treasury.php
update.php
pass_c_pannel.php

I've attached them so you guys can take a look at them but now they are gone.

Quarterbore 09-27-2008 10:17 PM

These should not be posted here. I will share what they do after they are removed!

Thanks for removing those!

You have a PM with my best guess from what I got from quickly looking at the code.

Note that my antivirus software indicated that two of the four were not even safe to have on a PC so anybody that downloaded those be careful with those as there was special characters and code so if you open those with the wrong software you could have a nasty surprise!

EDIT: OK, I looked at the file more on my junker computer and the special characters look to be Russian Characters or something of the sort. Still, some alarming script in there and while it should not be posted in a site like this I may well try to write a script that can look for some of these code tricks in an uploaded script.

joethaman 09-27-2008 10:33 PM

Removed

ExTincTi0N 09-27-2008 10:34 PM

Hmmm I wish how people could upload that kinda stuff to your site so I can make sure it doesn't happen to me.

joethaman 09-27-2008 10:52 PM

Only thing I could thinkof at the moment was to remove the ability to upload a signature picture.

The one thing I noticed was when I went to backup my forum, it wouldn't allow me to download those files, and only those.

fum1n 09-27-2008 11:42 PM

They could have been uploaded by using a Local File Inclusion (LFI) exploit , this is where basically a user embeds $wget someshell.php in the exif data of an image, uploads it and then opens the url on a vulnerable script ( I believe vBA Portal is vulnerable to this type of attack )

The files you found where most likely PHP RATs, basically gives the user who opens them in there browser, pretty much full access to your accounts directory and possibly the /home/ directory + other accounts on server if they aren't CHMODed correctly. You can install a server sided anti virus what will automatically detect and delete shells like that or alternately implement an Apache script like mod_security.

Want to find out who did it and how, you should check your raw access logs and do a CTRL+F and enter any of them .php files, then get the IP what accessed them and look what other pages they accessed, most likely you will find there exploit.


All times are GMT. The time now is 07:08 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01005 seconds
  • Memory Usage 1,714KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (6)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete