vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   OK, so my site got hacked... I think? Advice?! (https://vborg.vbsupport.ru/showthread.php?t=195537)

FleaBag 11-05-2008 08:49 PM

OK, so my site got hacked... I think? Advice?!
 
I have a second vB board which I mostly use for testing stuff out... I logged onto it yesterday and found that in some shape or form I've been hacked. The second time in my 12 years or so online... The last time was an old vB2 v3 Articles vulnerability... This test board however, had few hacks installed.

I've Googled for the names on the page but it doesn't yield many results, it seems my page is the only one online hacked in this way.

All vB URL's redirect to the page you can see in the above link, there is an embedded image - which is not actually a file on the server. I thought the FTP had been hacked but I logged in and all files are unchanged since my last upgrade. I then thought .htaccess had been changed in some way, but this is also unchanged...

ACP stuff works fine... So what's going on here? Where has my site gone?

I don't know if this is a vB issue (by issue I mean I left a door open somewhere, rather than an exploit) or server issue... The page does mention Safe Mode being off.

So if anyone could shed any light on what happened, how I stop it happening again and how I get rid of this trash it would be greatly appreciated!?

Oh and can anyone translate what the text on the page says?

The board is/was running 3.7.3 PL1. Thanks guys!

KW802 11-05-2008 08:57 PM

Check your templates to see if any of them have been modified (replaced with the HTML you're seeing instead of the usual vB templates). I came across a site that was hacked where several templates were replaced; everything behind the scenes worked but the templates were replaced. Also be sure, after you've recovered to a point where you can go from, to check your phrases & translations to make sure nothing was added. The site I mentioned with the template changes also had a second language added and some phrases altered.

FleaBag 11-05-2008 09:23 PM

Hi Kevin, thanks for the suggestions...

I must have been tripping last night, as I just tried to log into the ACP and I get the same defaced page on login.php?do=login. So no cookie can be set. :(

KW802 11-05-2008 09:34 PM

Quote:

Originally Posted by FleaBag (Post 1660136)
Hi Kevin, thanks for the suggestions...

I must have been tripping last night, as I just tried to log into the ACP and I get the same defaced page on login.php?do=login. So no cookie can be set. :(

If you're sure that none of the actual files on the server have been comprimised, then perhaps your admin password has been reset and you're seeing the 'invalid password' error page that has been defaced.

Try resetting your admin password.

Winterworks 11-05-2008 09:34 PM

Do you have two licenses or just one? It all depends on this.

FleaBag 11-05-2008 09:44 PM

Quote:

Originally Posted by KW802 (Post 1660139)
If you're sure that none of the actual files on the server have been comprimised, then perhaps your admin password has been reset and you're seeing the 'invalid password' error page that has been defaced.

Try resetting your admin password.

Thanks once more. I'll give that a shot now.

EDIT: Kevin I just realised, I need to set up a new account to do this... Which I don't have the ability to do. :(

Quote:

Originally Posted by Winterworks (Post 1660140)
Do you have two licenses or just one? It all depends on this.

What all depends on this?

Winterworks 11-05-2008 09:45 PM

Just answer the question and I can help you?

FleaBag 11-05-2008 09:53 PM

Oh right, I thought you meant there was an issue that only affected licensed boards lol.

Yes it is my friend, and I'm sure I'd be shut down here pretty fast if I didn't. :)

Winterworks 11-05-2008 09:56 PM

That's not my question :p It was how many licenses do you have?

FleaBag 11-05-2008 09:59 PM

Oh, right... Sorry I misread the question. I have two at present.


All times are GMT. The time now is 10:31 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01067 seconds
  • Memory Usage 1,737KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete