vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Malware - popup ads (https://vborg.vbsupport.ru/showthread.php?t=328118)

digif 06-25-2020 01:35 PM

Malware - popup ads
 
Hi,

Recently I've noticed that when I click on the website, popup comes up, even though I never added such ads on the forum.

URL: beneamata.com

How can I find where the code was added and through where did they manage to do that?

Thanks in advance

--------------- Added [DATE]1593120925[/DATE] at [TIME]1593120925[/TIME] ---------------

Ive upgraded version from 3.8.4 to 3.8.9, now there are no more popups, but I wanted to upgrade it to 3.8.11, it got stuck on 3.8.9 with the error:

Database error in vBulletin 3.8.9:
Invalid SQL:
ALTER TABLE adminlog CHANGE ipaddress ipaddress VARCHAR(45) NOT NULL DEFAULT '';
MySQL Error : Table 'elebocom_beneamata.adminlog' doesn't exist
Error Number : 1146
IP Address : IPADDRESS
Username :

Any ideas why?

--------------- Added [DATE]1593125969[/DATE] at [TIME]1593125969[/TIME] ---------------

Ive created the table, everything is now fixed, I've upgraded to 3.8.11, no more malware popups. Thread can go on lock.

DCD.RB 06-29-2020 06:03 AM

It sounds like they might have injected malicious code on the local php files themselves. When you upgraded, you replaced those files with original vB files.

I've seen this happen to wordpress sites.

I'd get your host to review your server to ensure it's not compromised.

digif 02-11-2021 06:40 PM

Hi guys,

Malware came back, now I have no idea how to get rid of it. Is it possible it came through some of the plugins?

I've removed a folder called 'nav' which was full of files with strange external domains, but still popups are here. Files were called 'nmd sela something'.

Any help appreciated.

Dr.CustUmz 02-13-2021 05:04 AM

Quote:

Originally Posted by digif (Post 2606169)
Is it possible it came through some of the plugins?

very likely, I browsed your forum and was unable to see any of these popups to pin point the ad (I dont use any adblockers)

If you could share a link to exactly where you are receiving these popups I could help.

digif 02-13-2021 01:33 PM

Quote:

Originally Posted by Dr.CustUmz (Post 2606195)
very likely, I browsed your forum and was unable to see any of these popups to pin point the ad (I dont use any adblockers)

If you could share a link to exactly where you are receiving these popups I could help.

Homepage, click on the side (blue background, one left mouse click is enough).

Dr.CustUmz 02-14-2021 08:45 AM

Quote:

Originally Posted by digif (Post 2606199)
Homepage, click on the side (blue background, one left mouse click is enough).

they are not appearing for me =/ I am also not receiving any blocked pop-up notifications, nor am I seeing anything in the console...

With that said this could be one of many issues:

You yourself could be infected with malware
You may have a malware infected browser extension (they're pretty common)
Or it may be a vBulletin product with ads injected and only visible to you (which in the sense of adding hidden ads to a product would make no sense, you would want as many viewers as possible to make any kind of profit)

Are any of your members reporting these popups?

I would register but I do not know Andrea's surname lol

digif 02-14-2021 09:37 AM

Quote:

Originally Posted by Dr.CustUmz (Post 2606215)
they are not appearing for me =/ I am also not receiving any blocked pop-up notifications, nor am I seeing anything in the console...

With that said this could be one of many issues:

You yourself could be infected with malware
You may have a malware infected browser extension (they're pretty common)
Or it may be a vBulletin product with ads injected and only visible to you (which in the sense of adding hidden ads to a product would make no sense, you would want as many viewers as possible to make any kind of profit)

Are any of your members reporting these popups?

I would register but I do not know Andrea's surname lol

Maybe try few times clicking on the background of the homepage. I get them when I run Firefox Private Window as I have adblock on the normal one.

I'm not logged in, so I dont think its only for users. Also, I dont get it on other websites so its not malware on pc.

Forum is inactive now, but I want to keep it clean as an archive, so I dont get reports from other users. If you want to register, answer is 'Ranocchia'.

Thanks for trying to help.

Dr.CustUmz 02-14-2021 11:58 AM

I have tried firefox, firefox private, chrome, chrome incognito, edge, and IE, all without adblocker. I'm just not getting any form of ads.

but what you can do when you see the ad inspect it in console.

Find the top most div of the ad, see where that is in your style, search the words in the html of the ad in your styles, plugins, ect.

snakes1100 02-14-2021 12:08 PM

I'd agree with Dr., i've checked it as well.

Sometimes those ads are IP specific, which may be why you dont get every user complaining about it the popups.

It looks like you have some scanning/checking to do in your file system & db.

digif 02-14-2021 02:27 PM

Quote:

Originally Posted by Dr.CustUmz (Post 2606220)
I have tried firefox, firefox private, chrome, chrome incognito, edge, and IE, all without adblocker. I'm just not getting any form of ads.

but what you can do when you see the ad inspect it in console.

Find the top most div of the ad, see where that is in your style, search the words in the html of the ad in your styles, plugins, ect.

I've recorded it:
https://screencast-o-matic.com/watch/crn2DZSwqm

Also, popup also comes up but after a while, so I didnt want to wait for it to record it.


All times are GMT. The time now is 11:19 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01256 seconds
  • Memory Usage 1,740KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (5)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete