vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Help, being hacked! (https://vborg.vbsupport.ru/showthread.php?t=67758)

Locutus2999 07-29-2004 04:36 PM

Help, being hacked!
 
All, running a modified version of vb2.3.0

Starting yesterday we keep getting hacked, someone keeps getting control of userid 1 which happens to be my account with full admin rights, they first defaced it with a bunch of arab anti-american garbage, now they are logging in and deleting forums. I changed the password for my account, and now I just banned it.

Anyone know how they are doing this so I can fix it? Upgrading is not really an option at this point.

Any help is appreciated, thanks.

Modin 07-29-2004 04:43 PM

It's tough to tell how they are doing it.

If you changed your password, then they probably aren't guessing it. They could just be getting access to your database. Do you have an insecure version of phpmyadmin installed, one with out a password? (if it has a password, change it)

List off what hacks you have installed, one may be vulnerable.

Last case would be to look through your Apache access logs, it's a pain, but it'll let you know what IP has been accessing certain admin only files.

-Modin

Locutus2999 07-29-2004 04:46 PM

They are using the admin control panel, all the hacks were done by me personally. They dont have access to my database because if they did, they wouldn't be deleting forums and changing users from the admin control panel I dont think.

I saw some mention of a hole in the "I forgot my password" function?

The admin logs show the IP of "217.23.37.85" under my account.

Colin F 07-29-2004 04:56 PM

See this thread: http://www.vbulletin.com/forum/showthread.php?t=108741

Locutus2999 07-29-2004 05:16 PM

Well, I already had the calander disabled, I went ahead and removed the calander.php file altogether since we dont use it.


All times are GMT. The time now is 01:50 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.00996 seconds
  • Memory Usage 1,713KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (5)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete