vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   My website contiunes to get hacked (https://vborg.vbsupport.ru/showthread.php?t=229979)

daveaite 12-11-2009 02:12 PM

My website contiunes to get hacked
 
I have been continually getting hacked over the past month. I've rolled back my server followed

https://vborg.vbsupport.ru/showthrea...securing+forum

by password protecting:
admincp/
modcp/
includes/
install/

renaming modcp/
admincp/

making myself an undeletable user

-reformatted my pc to prevent any viruses

They either change my index files around and brag about their hacking abilities ot they delete the entire contents of my public_html
----------------
What should I do? I have no clue how they are getting into my system. I've changed the cpanel password a ton of times. Maybe attachments entry?

About them?
Some arabic group

Tips? Help please.

Lynne 12-11-2009 02:20 PM

Are you on a shared webserver? Have you talked to your host about this? Have you looked at your access_logs to see if anything is in there regarding the hacking?

daveaite 12-11-2009 02:27 PM

I have talked to my web hosting. I feel like I've been bothering them too much lately by asking them to continually roll it back. It is on a shared hosting which makes me a bit worried, maybe it's time to switch...although I did buy 3 years of hosting.

They actually went ahead and changed the cpanel password for me, and it got defaced the next day.

This may be a coincidence but it started happening after I upgraded to vbulletin 4.0. I know its in beta, and I used to have this mod which now I think prevented this from happening: https://vborg.vbsupport.ru/showthrea...light=firewall

Lynne 12-11-2009 02:40 PM

I doubt they are hacking through v4 but if you look at the access_logs, you could verify that. Shared hosting is not as secure as having your own server. But, I'm no server expert, so I really can't offer much advise here.

abdobasha2004 12-11-2009 03:48 PM

Quote:

What should I do? I have no clue how they are getting into my system
it is a possibly a root shell on one of your vbulletin or website files

1- download a backup of your site
2- scan this backup by a powerful anti - virus (for me avira antivirus can do it)
3- your anti virus will detect the shell and will notify you with its path.
4- if you are sure that the file is not important delete it, otherwise open it and remove the shell (most propably coded text) , or just rewrite the file from a clean vbulletin version
5- make sure that there is no other files

best wishes

daveaite 12-11-2009 07:03 PM

Thanks for the quick feedback. I'll look into the virus scan method.

Matais 12-11-2009 07:29 PM

you have checked out your end haven't you?

could have a keylogger, spyware etc.

also what version of vbulletin are you on?

Speysider 12-13-2009 10:36 AM

Quote:

Originally Posted by Matais (Post 1928986)
also what version of vbulletin are you on?

See post #3, he says vBulletin 4 Beta.

Carnage 12-13-2009 11:13 AM

on shared hosting ensure that config.php is NOT world readable.

In an ftp client you may see options for user, group and other permissions. Turn off all the permissions belonging to 'other'

CarlitoBrigante 12-14-2009 07:22 PM

There is little doubt you have some backdoor installed in your system, or that you have some modification that works as a back door.

Make also sure, in case you have it installed, that vBSEO is upgraded to the latest package. 3.3.2 release needs to be re-upgraded as there was a security patch a while ago which did not cause a version number change.


All times are GMT. The time now is 06:42 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01046 seconds
  • Memory Usage 1,733KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete