View Single Post
  #3  
Old 07-12-2013, 05:07 PM
TNCclubman's Avatar
TNCclubman TNCclubman is offline
 
Join Date: Sep 2008
Posts: 690
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

heres the post that was deleted...

My server is spamming through VBGallery 2.51. I am 100% sure that this is the case. Let me explain all that has gone on to prove this.

I was on another server that I have since left and move this site to a new server. The only site hosted on this server is the one I am referring to now. The reason I left was partly because of this spamming going on that is was sending out.

If I go into my ADMINCP plugins and turn off the VBGallery plugin then the spamming stops.

If I turn it back on it starts back up in a day or two. I have left the plugin turned off for almost two weeks and the server never sent out any spam. But as soon as it gets turned back on the spam starts getting sent out from my server again.

Here is another link that help me isolate it down to VBGallery. There is another user by thew name of beishe8 that also brings up that he had this same problem and how he narrowed it down to Photopost vBGallery misc.php. You can find his results on page two of this thread.
https://www.vbulletin.com/forum/show...mail-log/page2

Chuck can you verify this and put out a fix for it ASAP?

--------------- Added [DATE]1373652539[/DATE] at [TIME]1373652539[/TIME] ---------------

followed by this

No, I think you have misunderstood me. This is not getting posted to the forums it is going directly out through email straight off the server.
The person can use VBG to send a mass email to over 765 emails at one time and this is not users that are registered on the web site. This is any email address they paste in.

The person has found a way to use VBGallery as a mass emailing feature on a servers with VBG installed. They are using the server through VBG to send 765 email and more at a time through the server.

You say to Turn off the email to a friend feature. That is a vBulletin feature and not a VBG feature if I am correct, right? Please explain a little bit about turning this off as I cannot seem to find that feature in the VBG Admin section.

Here is a link I found tonight that might also have something to do with this
Exploit in VB Gallery 2.5.1

--------------- Added [DATE]1373652643[/DATE] at [TIME]1373652643[/TIME] ---------------

http://www.photopost.com/forum/how-d...y-2-5-1-a.html
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01226 seconds
  • Memory Usage 1,767KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete