vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Hacked again! 2nd time in 2 weeks! Cannot access ACP. (https://vborg.vbsupport.ru/showthread.php?t=302387)

obglobal.net 09-17-2013 12:51 PM

Hacked again! 2nd time in 2 weeks! Cannot access ACP.
 
This is ridiculous.

I don't know how to handle this kind of stuff! I can't even access my ACP to delete this dude.

Hacked by Ari Tiga Angka Enam.

Why is vBulletin so easy to hack? Someone please guide me through what to do via cPanel.

I lost about 50 posts last time because I reverted to a backup.

So over it.:down:

TheLastSuperman 09-17-2013 01:37 PM

Moved to vB4 General Discussion. I would guess that you overlooked something the first time around... a plugin was still present, the datastore table had a plugin within... a shell script on your server... any number of things honestly be sure to check using these links and be VERY THOROUGH grab a cup of coffee, do it right and above all else do not become frustrated that is the #1 thing many do and assume that since it started working after they uploaded files that its fine, no you need to be very in-depth after being hacked not only for your safety but for the safety of all your community members.

http://www.vbulletin.com/forum/blogs...vbulletin-site
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site

socialteenz 09-17-2013 01:41 PM

Did you remove the install directory? Check for all the users with admin privilege & change all your admin passwords.

obglobal.net 09-17-2013 02:02 PM

Quote:

Originally Posted by TheLastSuperman (Post 2446210)
Moved to vB4 General Discussion. I would guess that you overlooked something the first time around... a plugin was still present, the datastore table had a plugin within... a shell script on your server... any number of things honestly be sure to check using these links and be VERY THOROUGH grab a cup of coffee, do it right and above all else do not become frustrated that is the #1 thing many do and assume that since it started working after they uploaded files that its fine, no you need to be very in-depth after being hacked not only for your safety but for the safety of all your community members.

http://www.vbulletin.com/forum/blogs...vbulletin-site
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site

I got this from my hosting service:

I have checked your site and found the following suspicious files:

Code:
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/plugin.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/help.php
[HEX]php_nested_base64_510 : [15/09/13] /home/obglobal/public_html/admincp/nsuser.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/index.php
[HEX]php_nested_base64_510 : [17/09/13] /home/obglobal/public_html/admincp/black.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/admin.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/forum.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/index.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/showthread.php

Can someone PLEASE tell me how to clean these out? I really have no idea what to do and I'm desperate.

--------------- Added [DATE]1379430244[/DATE] at [TIME]1379430244[/TIME] ---------------

Quote:

Originally Posted by socialteenz (Post 2446212)
Did you remove the install directory? Check for all the users with admin privilege & change all your admin passwords.

Yeah, I did.

Can I change my passwprds via cPanel, do you know?

Spangle 09-17-2013 03:34 PM

Quote:

Originally Posted by obglobal.net (Post 2446220)
I got this from my hosting service:

I have checked your site and found the following suspicious files:

Code:
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/plugin.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/help.php
[HEX]php_nested_base64_510 : [15/09/13] /home/obglobal/public_html/admincp/nsuser.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/index.php
[HEX]php_nested_base64_510 : [17/09/13] /home/obglobal/public_html/admincp/black.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/admin.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/forum.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/index.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/showthread.php

Can someone PLEASE tell me how to clean these out? I really have no idea what to do and I'm desperate.

--------------- Added [DATE]1379430244[/DATE] at [TIME]1379430244[/TIME] ---------------



Yeah, I did.

Can I change my passwprds via cPanel, do you know?

Firstly I would check all those files, check them against what is uploaded when you do an install, then check them against what is those folders for each plugin.
Delete any that you cannot find.

off the top of my head this one looks a bit suspicious

/home/obglobal/public_html/admincp/black.php

socialteenz 09-17-2013 04:36 PM

Quote:

Originally Posted by obglobal.net (Post 2446220)
I got this from my hosting service:

I have checked your site and found the following suspicious files:

Code:
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/plugin.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/help.php
[HEX]php_nested_base64_510 : [15/09/13] /home/obglobal/public_html/admincp/nsuser.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/index.php
[HEX]php_nested_base64_510 : [17/09/13] /home/obglobal/public_html/admincp/black.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/admincp/admin.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/forum.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/index.php
[STR]Hacked_by_string : [17/09/13] /home/obglobal/public_html/showthread.php

Can someone PLEASE tell me how to clean these out? I really have no idea what to do and I'm desperate.

--------------- Added 17 Sep 2013 at 15:04 ---------------



Yeah, I did.

Can I change my passwprds via cPanel, do you know?

Yes, you can change the passwords via admincp.

Seems like you need to upload all vbulletin files again.

Check for vulnerable plug-in's too.

My bad, seems like superman summed it up nicely. Check his links.

Steve-Hoog 09-17-2013 05:06 PM

obglobal.net

Sounds like you got very close to the same thing I got. Our entire vB software was destroyed.

Basically I had to hire someone to clear out all files, reload the vB software, and then re introduce the database. And I can only thank God our database was not destroyed.

You definitely have a different hacker than I had; but I went by your URL and from what you posted in here I think you are screwed just like I was.

Steve


All times are GMT. The time now is 07:38 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01220 seconds
  • Memory Usage 1,740KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (4)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (7)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete