![]() |
Forum hacked because of /install/upgrade.php delete it
v4.21 forum got hacked 3 times from raw forum no modification, no addon, fresh, clean DB...
I than look at the log it and pointed toward /install/upgrade.php I got curious and went to check how they could manage such a thing... and to my surprise... The page ask for the customer number... that fine... View source code on that page Code:
<!-- And guess what, It can be reversed in 5 minutes from what I've seen. Customer number are what, 12 symbols A-Z0-9 I guess there even DB that contain all possible MD5 with those values. So they get my customer number and execute the upgrade script and create a new account from the upgrade script... Why did you even bothered giving them the MD5 of the answer and the link to the admin control pannel? So yes, delete your install folder entirely or move it outside of your forum asap. |
That was announced on the 27th of August.
Please see these recent security announcements: vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5 vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions |
Why weren't we contacted by mail for such thing...
The only thing I've received was v4.22 recently which claim some exploit related to forumrunner xss or something which I've ignored and deleted forumrunner entirely. The only one reading the exploit announcement are those after they get hacked or those that want to hack forum... Guess it only those that upgraded to v5 that got the email and everyone else was left in the dark. |
It was in your ACP in the News section. I would also subscribe to this forum, http://www.vbulletin.com/forum/forum...nouncements_aa
That way you will get a email every time there is a announcement. You could also install this mod, AdminCP News as Posts or PMs by BOP5 (Get your Admin CP News PMed to you!) --------------- Added [DATE]1381969364[/DATE] at [TIME]1381969364[/TIME] --------------- Also there was a email sent, September third: Code:
vBulletin Security eBulletin |
Quote:
It was emailed... It was also in your ACP as a notice. Its also been all over the web on various forums and blogs. Guess only people that paid attention noticed it. |
Just looking back I got that email on Sep. 4th, also remember the notice in the admincp but really red flags come up for me when I had all kinds of Guests login into the admin panel I also had some random account named admin2 registered and in the administrator usergroup!!
|
Quote:
vBulletin Security eBulletin: Potential Exploit of vB4.1.x & 5.0.x Guess they meant vB4.1.x and higher... because vB4.2 was also affected... They should of simply claimed vB4.x I figured if you keep your version to the last version you're safe, I didn't bothered reading the news... Well they did contacted me... so it's partially my fault... |
Yeah this stuff happens, it is best to read through their emails completely, and even if it is not for your version number, it is sometimes best to follow it anyway. :)
|
All times are GMT. The time now is 07:40 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|