vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Hacked (https://vborg.vbsupport.ru/showthread.php?t=211749)

Powlo 04-20-2009 07:09 PM

Hacked
 
How do i go about reporting a succsessfull hacking attempt. Baring in mind there were no addons at the time and i have spoken to the hacker and he 'claims' that he has written a script that will allow him access to any 3.8 board.

Wired1 04-20-2009 08:35 PM

Go to vBulletin.com and report it there. How / why are you in communication w/ the "hacker"? Is he attempting to get money out of you?

TigerC10 04-20-2009 09:33 PM

Were you running the latest vB? And how did you "confirm" the hack?

Powlo 04-20-2009 10:43 PM

He replaced my htaccess (amongst other things) to redirect to his website. So i sign up and asked them why they were hacking me. Its a german site so i didnt fully understand all their responses but at least i got on talk terms with them and eventually they released my site.

Previously to that no matter how many times i replaced the file system and database from various backup dates they simply got over written.

He doesnt want anything from me but im not about to name him either as it is obvious what actions he will take. He has told me that it is vbulletin that has been exploited and not and modifications.

I have some server logs but im not to clear on what i am looking for.

Lynne 04-20-2009 11:17 PM

Ask you host for help.

It sounds to me like he has access to your server if he is replacing htaccess files. If so, your host will want to know about this and should help you figure out how they got in.

Wired1 04-21-2009 12:26 AM

Agreed, it's not vBulletin. You need server access via CPanel or remote access or something to change the htaccess file. vBulletin has no access to it.

Powlo 04-21-2009 09:51 AM

It seems from the logs that he gained access to my account then added or edited a plugin, which one i am unsure of because are far from detailed (which is something vb should really expand on) assuming the right plugin was used that could effectivly give him root access, right? The logs dont tell me which plugin was altered, is there another way to get this information?

He then appeared to download my style and copy all images, dont know why.

Although i have my site back i dont feel secure, what actions can i take to increase security.

I am pretty sure now that he used a modification to gain access to my account even though he says he didnt so i have already removed most of them. Some of the are critical but i believe are safe.

I read somewhere that changing your userid could help also the location of admincp, how would i do this?

napy8gen 04-21-2009 10:16 AM

here it is powlo.
http://www.vbulletin.com/forum/showthread.php?t=172234

Powlo 04-21-2009 10:30 AM

Thanks bud, i knew id seen it somewhere. ;)

Michael.A 04-21-2009 12:24 PM

here is what i think and all the coder and programmers on my forum think any vb higher then 3.7.5 is fun to take down sorry but yes . 3.8.x no good
i cant wit an tell 4.0


All times are GMT. The time now is 09:22 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01079 seconds
  • Memory Usage 1,729KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete