vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Forum home page hacked - at a loss. (https://vborg.vbsupport.ru/showthread.php?t=302302)

HarshlyCritical 09-14-2013 10:16 PM

Forum home page hacked - at a loss.
 
First of all, I have read this: http://www.vbulletin.com/forum/blogs...ve-been-hacked

I have followed steps 1 and 2. Step 3 is unncessary because I have retained administrator privileges. Step 4 also seems unnecessary. If you'd like to see the damage, this is it:

http://www.horrorgameforums.com/

And this is where Steps 5 and 6 come in... They say in Step 5 that AdminCP "provides a tool to scan directories". Well, great. Where is it? I cannot find it.

According to the Control Panel Log, this user made a total of three changes... All to plugin.php. The first one says "files" under Action, the second one says "doimport" under Action, and the third one is blank. So I assumed that since it's some sort of nefarious plugin, I could remove it. Except, following Step 6, when I go under Plugin Manager (the only one without a strikethrough is vBulletin, so I hit "Edit") there are hundreds and hundreds of them. Am I really supposed to go through each and every one? I can't figure this out.

Even when I disable all plugins (I put a line in config.php to supposedly disable them all), my home page still displays that irritating page. Please, I've been going crazy for the last couple of hours and have no idea where to go with this.

Also, the user who did this made themselves an administrator. :D Unfortunately, I cannot remove them, even though I'm a superadmin! They somehow made themselves uneditable, even though config.php does not display this information. I've googled extensively and I can't figure this out...

Thanks for any help.

ozzy47 09-14-2013 10:58 PM

The tool is under Maintenance --> Diagnostics run the Suspect File Versions


HarshlyCritical 09-15-2013 12:06 AM

Quote:

Originally Posted by ozzy47 (Post 2445674)
The tool is under Maintenance --> Diagnostics run the Suspect File Versions



Thank you.

It says everything's fine except for config.php... Which I have edited a little bit, so that's to be expected.

How do I delete users that are "uneditable", if they aren't listed as uneditable in config? I can't figure that one out...

ozzy47 09-15-2013 12:18 AM

Did you try doing that with all plugins disabled?

TheLastSuperman 09-15-2013 01:18 AM

http://www.vbulletin.com/forum/blogs...vbulletin-site

Edit: Also see my post here - https://vborg.vbsupport.ru/showpost....1&postcount=52

I bet they simply edited some templates, try reverting any newly customized templates via style manager before doing anything else. *Also please note the queries I list in my blog article, you can replace the words we are searching for w/ anything you wish for example:

PHP Code:

SELECT styleidtitletemplate FROM template WHERE template LIKE '%adf.ly%'


bremereric 09-15-2013 02:32 AM

Replace your vb files from a previous backup. I had to do the same today. They hacked my default style which I copied the code from another and fixed and then the Home page was offering free money. I restored the program files from my hosting company and they are working like a charm. I also bought sitelock and they have their firewall up and running. VB will not protect your site. You will have to get something to do it also.


All times are GMT. The time now is 07:13 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01119 seconds
  • Memory Usage 1,726KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_php_printable
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (6)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete