vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 Programming Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=15)
-   -   Help!!!! (https://vborg.vbsupport.ru/showthread.php?t=200203)

RTMdotORG 12-30-2008 05:18 PM

Help!!!!
 
i got hacked...

www.ripthemic.org

any ideas on how to delete the html code?

--------------- Added [DATE]1230668356[/DATE] at [TIME]1230668356[/TIME] ---------------

...........................

Dismounted 12-31-2008 05:19 AM

Your board looks fine.

RTMdotORG 12-31-2008 11:31 PM

yeah i got it fixed....
then they hacked us again...
vbfirewall prevented it 5 times...
my server told me they inserted it into the database...
any suggestions?
can rss feeds do this?

--------------- Added [DATE]1230773562[/DATE] at [TIME]1230773562[/TIME] ---------------

now its the way it was before i got it fixed the last time...
hacked again...

Lynne 12-31-2008 11:52 PM

Do you have phpMyAdmin? And is it protected? Disable all your mods when you next put the site up also. See if they can hack the site with your mods disabled. And look for any suspicious files on the server.

dyna88 01-01-2009 12:19 AM

Have you checked your server logs???

RTMdotORG 01-01-2009 12:22 AM

The first time this happened, i contacted my server and they fixed it...
they said it was injected into the database...
the very next day(today)...
I was hacked again...
i have vbfirewall and...
i received 5 emails saying it blocked 5 attempts from hacking...
then it bypassed and now im hacked....
fixed it once, then they hacked again....
www.ripthemic.org

heres wut it showed when prevented...

1||1230677435||66.156.165.120||do=viewsubscription ||http://www.ripthemic.org/forums/usercp.php||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 Firefox/2.0.0.17
1||1230677439||66.156.165.120||do=viewsubscription ||http://www.ripthemic.org/forums/usercp.php||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 Firefox/2.0.0.17
1||1230677448||66.156.165.120||do=viewsubscription ||http://www.ripthemic.org/forums/usercp.php||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 Firefox/2.0.0.17
1||1230734502||124.187.20.43||do=removesubscriptio n&t=3||http://ripthemic.org/forums/showthre...1||Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3
1||1230765308||67.167.16.183||do=viewsubscription| |http://www.ripthemic.org/forums/usercp.php||Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; InfoPath.2)


is it possible that people are having problems with subscriptions because theres a security issue???

all the actions have to do with subscriptions and everyone is talking about having issues with subscriptions....

i have a feeling vbfirewall has a security issue and id hate to accuse the creator of vbfirewall but you cant put it past anyone these days...

heres the link for vbfirewall
https://vborg.vbsupport.ru/showthread.php?t=196791

dyna88 01-01-2009 12:44 AM

I think the server logs would be more telling. Oh I was looking at your site and you will find two more attempts with my IP, the last six digits are 180.113 probably because I tried to directly access the viewsubscription function.

RTMdotORG 01-01-2009 12:49 AM

Quote:

Originally Posted by dyna88 (Post 1698255)
I think the server logs would be more telling. Oh I was looking at your site and you will find two more attempts with my IP, the last six digits are 180.113 probably because I tried to directly access the viewsubscription function.

nope...
no more attempts...

sparklywater 01-01-2009 01:50 AM

That vbFirewall mod looks fishy to me. If I were you I'd uninstall it and not rely on that.

Lynne 01-01-2009 02:32 AM

Read the vbfirewalled thread cuz I seem to recall them talking about problems with the subscriptions and a fix being posted. (sorry, I don't feel like reading it again.)

As suggested though, take a look at your server logs or ask your host to take a look at them and tell you how they are getting access to the database.


All times are GMT. The time now is 05:00 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01772 seconds
  • Memory Usage 1,738KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete