vbulletin hacked
I was recently called in to recover a friends vbulletin after it was hacked by ViRuS_HiMa,
a well known and fairly experienced hacker at turk-h.org
Since cpanel logging was not enabled, I do not know how he has entered the site but his technique was rewriting the spacer_open template in all styles with an eval(base64)
I would like very much to decode the eval(base64) so I can see if its simple html or if there is additional executions being made that I need to be aware of.
If anyone can assist with the decoding, please contact me.
Again, I do not know the point of entry (probably a Mod).
If anyone else has their forum hacked by ViRuS_HiMa, and it seems that no matter what you try,
it always shows the defacement, check your spacer_open templates in the database for eval(base64) encrypted text.
Thanks
|