It looks like they have been modifying their scripts.
We had one script kiddie try 3 variations of the meta refresh script. I assume the variations are designed to get by patches for the original.
I added my own fix in addition to cyb-advanced stats (basically the same as TopX Stats).
I simply went to vBulletin Options --> Censorship Options --> Censored Words and add these to your list of censored words.
Code:
content=0 content="0 LANGUAGE= JavaScript {meta} >> >>> >>>> >>>>> >>>>>> {http-equiv} "Refresh" """"
Even though they varied their scripts in order to get by the cyb-advanced stats and TopXStats patches the above fix still stripped out their varibles and they they have all left in a great big script kiddie huff. :laugh:
You know?...actually calling these lamers "script kiddies" is overrating their pathetic abilities.
Anyone using FlashChat needs to upgrade to version 4.6.2 and delete everything in your cmses (chat/inc/cmses/) directory
EXCEPT the version of vBulletin you are using (if you are using 3.6 then you want to LEAVE
vbulletin36CMS.php Etc). Especially delete anything that says
aedating in it's title as it has a serious security flaw in that file.
Also, if you running Apache then you can use an .htaccess file and addi it to the cmses directory.
The .htaccess file should contain the following inside of it
Code:
Order Deny,Allow
Deny from all
Read more about using .htaccess here
http://httpd.apache.org/docs/1.3/mod/mod_access.html
Also, something to think about is that a lot of people have "test" forums on their servers to try out new hacks and upgrades before installing them on their "live" board. Please remember that if you installed Cyb-Advanced Stats, TopXStats or FlashChat on your test board and they are still on there or unpatched then you are still at risk, especialy with FlashChat as they are gaining directory access through holes before 4.6.2.
So to recap...if you have Cyb - Advanced Forumhome Statistics
3.6.0 or
3.5.4 please update your version.
If you have Top "X" Stats
3.5.4 or
3.0.0 please update your version
If you have FlashChat please update it to
4.6.2
I also recommend adding this quick but highly effective fix.
There are other "fixes" available such as
vB 3.6.0 Disallow HTML code in Thread Titles, but the above doesn't require any template edits, and like I said has stopped all variations cold.
If you have been hit with these exploits (and you are able to log into your AdminCP)...go to
vBulletin Options --->
Plugin/Hook System--->Enable Plugin/Hook System
=NO and use the guides I have listed above.
Hope this helps.
