Quote:
Originally Posted by Lestat_
thanks for the replies guys, it seems the hacker gained access through a vulnerability in the search.php page and via admincp he began changing admin pwd's & email adresses. The reason why index & forum.php were showing the hackers message was because he altered the template forumhome and replaced it with his html page.
Fortunately, vbulletin has a wonderful functionality of reversing templates so that fixed the problem. this topic can be closed 
|
You need to identify the admin userid numbers in config.php as unalterable/undeletable users. This will prevent password and other changes.