vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   need help - forum.php has been hijacked (https://vborg.vbsupport.ru/showthread.php?t=300679)

VBUsers 07-31-2013 05:49 PM

need help - forum.php has been hijacked
 
I have my forum.php (main forum) showing an iframe to some a hole hacker that doesnt stop messing with my forum

http://www.hydrocanna.com/forum.php

can anyone tell me how they are doing this? I have checked the files and templates and cant find anything. Im not sure what file or how so please help me out

synseal 07-31-2013 06:45 PM

Have you tried overwriting forum.php with a fresh backed up one?.

VBUsers 07-31-2013 09:17 PM

Quote:

Originally Posted by synseal (Post 2436340)
Have you tried overwriting forum.php with a fresh backed up one?.


yes and ive looked at the file and none of th code is in there. I have over written everything on the site

kh99 07-31-2013 10:17 PM

Try using this: www.vbulletin.org/forum/showthread.php?t=281080

Also check the plugin manager to see if anything looks like it doesn't belong.

VBUsers 07-31-2013 11:33 PM

Quote:

Originally Posted by kh99 (Post 2436398)
Try using this: www.vbulletin.org/forum/showthread.php?t=281080

Also check the plugin manager to see if anything looks like it doesn't belong.


that worked! thanks a lot.

SupportAM 10-04-2013 01:47 PM

Okay I have the same problem and I replace all the files and I reloaded all files and I upgraded to 4.2.1 from 4.2.0 but forum.php is still going to the hijack page ..... where is it coming from It is not the physical forum.php file as i have looked at it.

ozzy47 10-04-2013 03:39 PM

This is what most people are following.

First you need to follow our advisory about deleting the install folder off your forums.

Then please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked

http://www.vbulletin.com/forum/blogs...vbulletin-site

Also please see these recent security announcements:

vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5
vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions

SupportAM 10-04-2013 04:24 PM

Hello ozzy,


I did all those steps (if you read my email, you will see that i did). Nothing has worked. Only thing left is restorng db from a back up and my web hosting take 200 for that. I am trying to avoid that.

--------------- Added [DATE]1380907613[/DATE] at [TIME]1380907613[/TIME] ---------------

and i didn't take db backup on my own. sadly

--------------- Added [DATE]1380907860[/DATE] at [TIME]1380907860[/TIME] ---------------

Sorry my bad ..... I wrote detail email in another thread. here it is.
---------------------------------------------
Okay I need help badly.
1. I have restored my older version of Web files.
2. Upgraded to newer version of VB ....now vb 4.2.1.
3. Cleaned suspect files.
4. Looked at the plugin.
Still nothing ..... My forum is showing forum.php that is not the physical forum.php on the webserver. There must be an entry somewhere that is displaying the page.
Here is the link to my page.

What else do i ahve to do ????

ozzy47 10-04-2013 07:39 PM

I did not see you mention that you tried the mod listed in post #4?

Nevermind just saw your post in that thread as well.

Lynne 10-04-2013 08:43 PM

Quote:

Originally Posted by SupportAM (Post 2449932)
1. I have restored my older version of Web files.
2. Upgraded to newer version of VB ....now vb 4.2.1.
3. Cleaned suspect files.
4. Looked at the plugin.
Still nothing ..... My forum is showing forum.php that is not the physical forum.php on the webserver. There must be an entry somewhere that is displaying the page.
Here is the link to my page.

What else do i ahve to do ????

I don't see anything in there about you checking for added admins, checking for modded templates, checking for modded phrases, checking for added notices, etc. Tons of things to be looking for in the admincp besides plugins.


All times are GMT. The time now is 06:57 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02912 seconds
  • Memory Usage 1,739KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete