vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Forum Destroyed By Hacker (https://vborg.vbsupport.ru/showthread.php?t=302396)

Steve-Hoog 09-17-2013 02:18 PM

Forum Destroyed By Hacker
 
In the last week we were still on 4.1.x and a hacker demolished our vB software; however, he did not touch the Database. Thank God

This hacker was:
Quote:

Greeting From BangoBnG
this website has been Hacked have fun,
Egypt - t.w.e@msn.com
-SeiF 2007-2013
Quote:

Age:16
Name:SeifAhmed
Country:Egypt
What is your experience with botnets:I am Trying To MAke DDos form BOts
What bots have you used before:vertexnet,zuse,Obtima
How often are you active:I am online evry day for 16 Hours
Are you willing to learn:yes
Do you have a little money to use:no :'(
All of your contact:
My Skype: Seifskp
Now we are on 4.2.1 and today someone was trying to get us but we caught them in time:

Quote:

ppp ppp@gmail.com 09-17-2013 09-17-2013 0
I have done a great deal of reading here and IMO opinion too much effort is being put into identify that you have been hacked and how to try to fix it; should we just eliminate their ability to get in our systems, and shouldn't this be the job of vB? Not the customers; and not the customers paying third parties? This is very depressing to say the least.

Max Taxable 09-17-2013 02:19 PM

I've been a vB licensee since 2005, never been hacked or defaced. Of course, I adroitly avoided getting vB4. Might have alot to do with it.

obglobal.net 09-17-2013 02:23 PM

Quote:

Originally Posted by Steve-Hoog (Post 2446224)
shouldn't this be the job of vB? Not the customers; and not the customers paying third parties? This is very depressing to say the least.

Exactly! I've payed vBulletin for an insecure forum that's now down for the second time in 2 weeks because of a hacker. F'ing scumbag.

WHy are they selling me on a software they can't protect?

--------------- Added [DATE]1379431576[/DATE] at [TIME]1379431576[/TIME] ---------------

And it looks like they've gotten in to my cPanel, as well.

Steve-Hoog 09-17-2013 05:34 PM

Log of what my hacker friend did if this helps anyone else.

Quote:

119416 N/A 22:20, 12th Sep 2013 plugin.php 41.47.48.122
119415 N/A 22:20, 12th Sep 2013 plugin.php update 41.47.48.122
119414 N/A 22:20, 12th Sep 2013 plugin.php add 41.47.48.122
119413 N/A 22:20, 12th Sep 2013 plugin.php modify 41.47.48.122
119412 N/A 22:20, 12th Sep 2013 plugin.php product 41.47.48.122
--------------- Added [DATE]1379443378[/DATE] at [TIME]1379443378[/TIME] ---------------

I have only these three Plugins, can anyone advise if either is a risk?

Quote:

VSa - Advanced Forum Statistics 7.1 VSa - Advanced Forum Statistics
Edit Check Version Disable Export Uninstall

VSa - ChatBox 3.1.8 VSa - ChatBox
Edit Check Version Disable Export Uninstall

VSa - Visitors in Last X Hours 3.0.4 VSa - Visitors in Last X Hours

--------------- Added [DATE]1379508741[/DATE] at [TIME]1379508741[/TIME] ---------------

Has anyone turned off Registration and still been exploited?


All times are GMT. The time now is 07:10 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01064 seconds
  • Memory Usage 1,723KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (6)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (4)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete