vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Forum and Server Management (https://vborg.vbsupport.ru/forumdisplay.php?f=232)
-   -   Recovering from a Hack (https://vborg.vbsupport.ru/showthread.php?t=300828)

Wir3tap 08-04-2013 05:49 PM

Recovering from a Hack
 
So a few weeks ago some great help got me in with Fix It to fix our forums. There are still problems we are running into.

1.) When going to update plugs and enable them. It acts like its going to but gives this in the box.
Updating style information for each style

World at War ... (Templates) (StyleVars) (Replacement Variables) (CSS) ~ HaCkEd By EjRaM HaCkEr ~ isecurity7@gmail.com

That hacked by ejram is the hack that kept spamming our main page before we used fix it.

2.) If I try to run the vbulletin upgrade script. It says this.

On Processing Blog 17 of 18 It errors out with this message.

Unexpected Text:
<?xml version="1.0" encoding="windows-1252"?>
~ HaCkEd By EjRaM HaCkEr ~
isecurity7@gmail.com


Does anyone know where this hack could be?

Otherwise the forums are working just seems like updates can't be done.

--------------- Added [DATE]1375646712[/DATE] at [TIME]1375646712[/TIME] ---------------

Also, The only way we can view the forums, is if all of our plugins are disabled.

--------------- Added [DATE]1375647598[/DATE] at [TIME]1375647598[/TIME] ---------------

Ok I disabled every plugin, and removed the define('DISABLE_HOOKS', 1); from my config file. Now each time I go to enable a plugin it gives me this:

Updating style information for each style

World at War ... (Templates) (StyleVars) (Replacement Variables) (CSS) ~ HaCkEd By EjRaM HaCkEr ~ isecurity7@gmail.com

--------------- Added [DATE]1375648135[/DATE] at [TIME]1375648135[/TIME] ---------------

Ok Plugin - Everywhere Sidebar - Posted teh big white screen of the hacked message on main index.php or any of the site links. I have uninstalled this plugin, but still getting the Hacked messages for the Updating Styles

ForceHSS 08-04-2013 06:42 PM

Have you tried posting a support ticket yet. A link to your site might help someone here to locate the problem. Check server logs see how they got in. Using custom plugins sometimes allow hackers access to your site

Wir3tap 08-04-2013 07:01 PM

<a href="http://www.bfewaw.com" target="_blank">http://www.bfewaw.com</a> is the site, but the hacked message is only in admin stuff now.

Big Al 08-04-2013 08:29 PM

The site shows as blacklisted.
Quote:

Analyzed On 2013-08-04 22:23 GMT
Website Address bfewaw.com
Blacklist Status BLACKLISTED
Detection Ratio 1 / 26 (4 %)
Domain 1st Registered 2005-10-24 (8 years ago)
Google Page Rank Google Page Rank
Alexa Rank 10,610,734
Website Blacklist Report
Engine Status Info
Favicon SCUMWARE Alert DETECTED

Some information about the hacker? http://www.google.com.au/?gws_rd=cr#...w=1280&bih=792

This may help with sorting it out.? Good luck with getting rid of the hacker.

Hackers and those who support them are the scum of the earth IMHO.

Wir3tap 08-04-2013 09:16 PM

What does that exactly mean?

Big Al 08-04-2013 09:38 PM

It means that as of a few seconds ago a scan of your site shows it is blacklisted by http://www.scumware.org/search.scumware

This information may assist if you contact your host, so they can see there is a problem.

You may wish to contact scumware.org to re-evaluate your site to see if it is now clean.

Lynne 08-04-2013 11:47 PM

Did you make sure to use a database backup from before you were hacked? I'm guessing they either changed, or added, a plugin and that is causing the issue.

Wir3tap 08-05-2013 09:45 AM

Yeah unfortunately Lynne we didn't have a backup. :( So we are trying to find out where the hack is at.

borbole 08-05-2013 10:07 AM

Quote:

Originally Posted by Wir3tap (Post 2437254)
Yeah unfortunately Lynne we didn't have a backup. :( So we are trying to find out where the hack is at.

Where do you get the hack message? You should do a thorough checkup of your server space and database as well. Also contact your host so they can check their access logs around the time that your forum got hacked to see how they got in.

Quote:

Originally Posted by Wir3tap (Post 2437130)
http://www.bfewaw.com is the site, but the hacked message is only in admin stuff now.

I loaded your admin page and I did not see any hack message. Is it solved now?

Wir3tap 08-05-2013 11:51 AM

Here are screenshots.

The first is the message that pops up when you try to Enable a plugin. (It does not update the styles when you click enable.)

http://www.bfewaw.co.uk/Wir3tap/first.jpg

The 2nd is what pops up in error of stage 17 of updating VBulletin. When you scroll the bar to the side, it says the hacked Message

http://www.bfewaw.co.uk/Wir3tap/2nd.jpg


When we first got hacked, we couldn't get into anything. It didn't even show us the forums. It was just one white screen that said "Hacked By Ejram" and that email address, the same thing its saying in the screenshots.


All times are GMT. The time now is 11:29 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02604 seconds
  • Memory Usage 1,738KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete