vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Spam emails (https://vborg.vbsupport.ru/showthread.php?t=281689)

sivaganeshk 04-17-2012 04:07 PM

Spam emails
 
Any one else having the same issue "a hacker is spending 100s of emails through my vb site." All my plugins are from vb.org(up to date) and I don't use any nulled scripts.

The email that is sent

Quote:

This is a message from Allan Cox ( mailto: ) from the College Students forum ( http://collegers.net/ ).

The message is as follows:

Hi,


Finally, we can drive the electric company out from our home...and not pay another cent on electr!city ever again.

The secret to Free..UNLIM!TED ENERGY is here, click or copy and paste the link below:
http://payspree.com/6038/pontiacgto


Best regards,


Allan
Affiliate




Please reply to magnetforpower@yahoo.com with OUT as the subject to be removed from our listing. Thanks.
I had contacted Payspree support and they had banned the affiliate account. However I still this vulnerability which send email.

The only way to stop it is disabling Plugins & hooks in AdminCP settings. Even when I disable all the plugin except CMS, blog, FB login, the emails are generated and sent.

Any action of relief ? :confused:

kh99 04-17-2012 04:12 PM

Did you look at your web server logs? You might be able to figure out which vb script is being called to send them.

sivaganeshk 04-17-2012 04:28 PM

The log is

Quote:

<username@collegers.net>
1334664710 0
-ident username
-received_protocol local
-body_linecount 62
-max_received_linelength 114
-auth_id username
-auth_sender username@collegers.net
-allow_unqualified_recipient
-allow_unqualified_sender
-local
XX
1
thuylh@iev-group.com

196P Received: from username by collegers.net with local (Exim 4.77)
(envelope-from <username@collegers.net>)
id 1SK7GA-0007mb-99
for thuylh@iev-group.com; Tue, 17 Apr 2012 07:11:50 -0500
025T To: thuylh@iev-group.com
064 Subject: Cut-down your electric bill with this leaked invention
060 X-PHP-Script: collegers.net/showthread.php for 66.249.71.39
052F From: "College Students forum" <info@collegers.net>
031 Auto-Submitted: auto-generated
032* Return-Path: info@collegers.net
056I Message-ID: <20120417121145.0a29cfb6d21c@collegers.net>
018 MIME-Version: 1.0
047 Content-Type: text/plain; charset="ISO-8859-1"
032 Content-Transfer-Encoding: 8bit
014 X-Priority: 3
033 X-Mailer: vBulletin Mail via PHP
039S Sender: <username@collegers.net>
038 Date: Tue, 17 Apr 2012 07:11:50 -0500

replaced username is my CP username

kh99 04-17-2012 04:32 PM

OK, that's some sort of emailing log (I don't know exactly what that is), but what I mean is the web server access log. For instance if the problem is in some_script.php then it seem like you would see a lot of those in a row in your access log.

sivaganeshk 04-17-2012 04:40 PM

where can I find ? CPanel or WHM ? and if possible which section/category

kh99 04-17-2012 04:41 PM

Ah...I wish I could tell you but to be honest I don't know. I'm not familiar with CPanel. We just use ssh and the apache logs are in a directory. You could ask your host, if that's easy, otherwise I'm sure someone else here will know.

BTW, I'm not sure this will lead to finding the problem, but it seems like a good place to start.

sivaganeshk 04-17-2012 05:02 PM

Thanks for the head up. There is a feature called "Raw Access Log".
Will check and get back with more information.

--------------- Added [DATE]1334768864[/DATE] at [TIME]1334768864[/TIME] ---------------

I deleted around 10 plugins and I am using only those most popular (and reliable) plugins.

Din see any emails bouncing yet(enabled the plugins for 6+ hours)


All times are GMT. The time now is 07:21 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01154 seconds
  • Memory Usage 1,726KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (7)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete