vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   sercurity issue V4.1.4 (https://vborg.vbsupport.ru/showthread.php?t=268169)

Nipponowners 08-08-2011 02:46 PM

sercurity issue V4.1.4
 
guys please help..

Ive got the add-on VSA-Donate on my forum. For some reason (i dont know why) someone is able to acess the vbulletin CP panel and change the paypal adress for my website!

ive changed the password numerous times and ive never given it to ANYONE..

i have no idea what to do, i dont want people to pay the club a donation and it not come to the club if you know what i mean..

i thionk this is a serious security issue and i need it sorting out..

PLEASE HELP ME

regards
dan

--------------- Added [DATE]1312819077[/DATE] at [TIME]1312819077[/TIME] ---------------

the "Hacker" has been able to upload pluin's/addons and change coding....


HELP ME:(

borbole 08-08-2011 03:03 PM

Quote:

Originally Posted by Nipponowners (Post 2230905)
guys please help..

Ive got the add-on VSA-Donate on my forum. For some reason (i dont know why) someone is able to acess the vbulletin CP panel and change the paypal adress for my website!

ive changed the password numerous times and ive never given it to ANYONE..

i have no idea what to do, i dont want people to pay the club a donation and it not come to the club if you know what i mean..

i thionk this is a serious security issue and i need it sorting out..

PLEASE HELP ME

regards
dan

--------------- Added [DATE]1312819077[/DATE] at [TIME]1312819077[/TIME] ---------------

the "Hacker" has been able to upload pluin's/addons and change coding....


HELP ME:(

Upgrade your forum to the latest version as it fixed such a security issue. Or at least apply the patch.

https://www.vbulletin.com/forum/show...17#post2191617

Paul M 08-08-2011 03:08 PM

What exactly are you saying is an issue ?

If you believe the mod has an issue then I suggest you disabled or remove it, and contact the author to confirm if there really is an issue.

Nipponowners 08-08-2011 03:30 PM

ive totally removed the plug-in and will have to see what my programmer says. put as i said whoever has done this has been able to add and code plug in's.

i shall update to the latest version and contact the person who made the vsa-donations add-on

thanks for the help

regards
dan

Boofo 08-08-2011 03:31 PM

Sounds like you might have a rogue staff member.

nerbert 08-08-2011 05:37 PM

Check your control panel log in Statistics and Logs. Check for unknown names and cross check IP addresses.

EDIT: with this kind of stuff going on you had better have your user id number in undeletable and unalterable users in includes/config.php on the server.


All times are GMT. The time now is 03:50 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01346 seconds
  • Memory Usage 1,720KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (6)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete