vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Spammers using Moderators/Administrator accounts to Edit Old Posts (https://vborg.vbsupport.ru/showthread.php?t=262020)

Erika 04-14-2011 07:34 PM

Spammers using Moderators/Administrator accounts to Edit Old Posts
 
Hi -

I was wondering if anyone else has ever had this problem. Today I logged onto my site to find that one of my moderator and one of administrators accounts had been hacked. Over 2,000 older posts on my site made by these 2 staff members had been edited to insert spam links that appear under their original post like this:

________
Body Science

Does anyone know where I can begin to correct this problem? I've told everyone on staff they should change their passwords immediately, but other than that, I've got no idea where to begin??? I'm running VB 3.7.4

In addition, it looks as though some of these edits do appear in the moderator logs, but only a very few of them. I've banned all the IP addresses that made the changes from the few mod log entries that I can see. All of the IP's look like proxies.

Any suggestions?

borbole 04-14-2011 07:54 PM

Quote:

Originally Posted by Erika (Post 2184710)
Hi -

I was wondering if anyone else has ever had this problem. Today I logged onto my site to find that one of my moderator and one of administrators accounts had been hacked. Over 2,000 older posts on my site made by these 2 staff members had been edited to insert spam links that appear under their original post like this:

________
Body Science

Does anyone know where I can begin to correct this problem? I've told everyone on staff they should change their passwords immediately, but other than that, I've got no idea where to begin??? I'm running VB 3.7.4

In addition, it looks as though some of these edits do appear in the moderator logs, but only a very few of them. I've banned all the IP addresses that made the changes from the few mod log entries that I can see. All of the IP's look like proxies.

Any suggestions?

Contact your host to check their logs and see how they were able to hack into the admin accounts. Check your server space for any suspicious file/s. Then upgrade your forum to the latest version of your branch.

Alfa1 04-14-2011 08:32 PM

Likely its the security issue that was discovered in 3.8.5 and below. Upgrade to the latest version.
The issue allowed people to registered duplicate staff accounts.

Wreck713 05-17-2011 01:56 PM

I got this issue too. total suckage. Is there anyway to see all external links coming from your site ....... as its hard to clean this up properly ?

RyanC 06-02-2011 04:42 AM

I got it as well...

Wreck713 08-07-2011 06:02 PM

What measures did you all take to fix?

I was told this ... To fix the exploit you go into "Vbulletin Options > Registration Options > Username Regular Expression > input "^[A-Z0-9 ]+$"

and then added this in illegal usernames

@ ~ ` # $ % ^ ( ) + = { [ ] } | \ / ? < > , ; : " '

I'm hoping that fixes the exploit.

Alfa1 08-08-2011 05:19 PM

Also add the usernames of all your staff members to the illegal usernames.


All times are GMT. The time now is 07:09 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01067 seconds
  • Memory Usage 1,724KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (7)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete