vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Search Engine redirect & trojan hack (https://vborg.vbsupport.ru/showthread.php?t=290921)

Gas Man 11-17-2012 08:27 PM

Search Engine redirect & trojan hack
 
First off, I'm very new to website stuff. I have ran many forum's before but only as moderator and admins, doing stuff only in the vb admin panel. Last year I purchased a local site from a friend that was getting out of it. With lots of help from some friends I got the site transfered to a new hosting company and upgraded it a bunch. Recently I haven't been able to have my old friend help, he's been busy, so I'm tackling things by myself.

I have been battling this over and over for a long time. Somehow my forum gets hacked so that when you click on a link from google or yahoo it gets redirected to some short url spam site. Sometimes from google, my avast will say it blocks a trojan.

The site is fine if I just use a bookmark, but once you try to go from a search engine, all heck breaks loose. I have the hosting company scan the site and they always find something like the following..

Quote:

It appears that the vbulletin database was injected with malicious code by the use of a commonly know vbadvance exploit:
I have 4.2.0 PL3 installed.

I do have 4 plug ins installed that I didn't install
https://vborg.vbsupport.ru/showthread.php?t=174381
https://vborg.vbsupport.ru/showthread.php?t=180651
http://www.vbadvanced.com/products.p...fo&productid=4

And as of yesterday (it's been happening way longer)
https://vborg.vbsupport.ru/showthread.php?t=248042

I do see that the CMPS is out of date, but they want to install it themselves, not just let me download it. They want lots of important info, that I'm not sure about handing out. Is that ok to give them for this, then just change passwords later???

Any other suggestions?? This is a horrible ridiculous thing and I'm sick of just having it cleaned to just have it back later.

Thanks in advance!!

--------------- Added [DATE]1353193292[/DATE] at [TIME]1353193292[/TIME] ---------------

Ok vbadvance only wants admin access to vb and ftp setup for the install. Guess that's not so bad.

snakes1100 11-17-2012 11:23 PM

I assume you do NOT have vbseo installed as i dont see it in your list of installed programs?

Ive fixed this in the past for some one that had this issue.

1. Move/Delete all current file related to the account.

2. Upload a new .htaccess file & place a deny all in it, w/ the exception of your IP.

3. Upload all new files for all programs installed.

4. Update all the programs on your site.

5. Verify proper permissions on said files.

6. Verify that you have no plugins or hacks that you didnt install in your forums.

Give google 1 or 2 days to reset, you should be all set.

Gas Man 11-18-2012 03:31 AM

I will have to do some research on that. That is all above my knowledge base...

Thanks for the input. All of that is needed to just stop hacks into my plug ins?


All times are GMT. The time now is 12:34 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01510 seconds
  • Memory Usage 1,717KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (3)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete