vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Site constantly being hacked. (https://vborg.vbsupport.ru/showthread.php?t=282112)

soulz2003 04-27-2012 02:37 PM

Site constantly being hacked.
 
We are being bombarded with this person who thinks it funny to alter the website.

I am not sure what is going. At first he found an exploit with vbadvanced. Now he managed to with vbulletin forum system. We are running 4.1.9

Thanks

ForceHSS 04-27-2012 02:46 PM

It is more than likely one of your plugins that is letting him in check server logs from your host see how he is doing it

borbole 04-27-2012 02:47 PM

Quote:

Originally Posted by soulz2003 (Post 2324048)
We are being bombarded with this person who thinks it funny to alter the website.

I am not sure what is going. At first he found an exploit with vbadvanced. Now he managed to with vbulletin forum system. We are running 4.1.9

Thanks

How were you hacked? I mean what type of hack it was. If I were you I would contact the hosting company and ask them to check the access logs and see how the hacker was able to get in. In meanwhile do a thorough scan/checkup of your server space and database and change all your passwords (forum admin, ftp and cpanel). Also scan your pc too with an antivirus/antispyware.

If your db is damaged then restore your most recent one from before the hack and upgrade your forum a.s.a.p.

soulz2003 04-27-2012 02:50 PM

yeah we do daily backups thats not the problem. Right now i cannot since i am at work and they filter out my own site :p

That is a good idea i will have to check with our hosting company.

ForceHSS 04-27-2012 02:55 PM

Quote:

Originally Posted by soulz2003 (Post 2324052)
That is a good idea i will have to check with our hosting company.

your welcome

soulz2003 04-27-2012 03:24 PM

ah i think i know what he is doing. He is forwarding our entire domain to his turkish website.

In the morning he only fiddled with our VBA index.php but now he forwarded the entire site over.

ForceHSS 04-28-2012 12:03 AM

did he get into your hosting site

soulz2003 04-28-2012 05:20 PM

I upgraded the vbulletin. It was 4.0.9

He altered our htaccess. Set it up to forward it to his website. How can you gain entry to that?

I hope the vb upgrade helped.

ForceHSS 04-28-2012 06:13 PM

if he got access to the htacess file then that means he has got into the ftp or some other way into the db files change all passwords to everything talk to your host and ask them to check server logs to see how he got in. Then your host can block him from the server level

borbole 04-28-2012 07:39 PM

Quote:

Originally Posted by soulz2003 (Post 2324386)
I upgraded the vbulletin. It was 4.0.9

He altered our htaccess. Set it up to forward it to his website. How can you gain entry to that?

I hope the vb upgrade helped.

Most likely he got access through the server. Did you ask your host to check the access logs?


All times are GMT. The time now is 09:34 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02519 seconds
  • Memory Usage 1,725KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete