View Single Post
  #8  
Old 09-10-2013, 03:39 PM
TheLastSuperman's Avatar
TheLastSuperman TheLastSuperman is offline
Senior Member
 
Join Date: Sep 2008
Location: North Carolina
Posts: 5,844
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pjkcards View Post
I've deleted the install directory, found several admin users and removed their admin permissions, disabled hooks in config.php, but still haven't resolved it yet. I haven't installed a fresh vB version yet since that will remove all my customizations.

I'll update here if I get it working.

Edit: I've also noticed it is the main theme that redirects, and all it child themes. Other themes work fine w/o redirect.

--------------- Added [DATE]1378795611[/DATE] at [TIME]1378795611[/TIME] ---------------

In the FORUMHOME template, it was modified by a hacker account, and was modified to be:
<META HTTP-EQUIV="Refresh" CONTENT="0;URL=http://adf.ly/VRAFS">

Check that file, and revert it.
Quote:
Originally Posted by Treeleaf View Post
I've also chased these fixes with no luck yet.

--------------- Added [DATE]1378824479[/DATE] at [TIME]1378824479[/TIME] ---------------

I'll eat my words, you had it right Pjkcards. Once you get the info out of the template, it's gone. Thanks so much for this.

Bows.
Quote:
Originally Posted by xenite View Post
The redirects are being inserted into the database through the ADMINCP. Replacing the scripts won't accomplish anything.

Your best bet is to look at the Admin Log and see which functions the bogus admin accounts accessed. Then go to those tools and look at the most recently changed/added data. This could be notices, templates, plugins -- anything where you can embed HTML code that is executed.
IF and I mean IF you have the redirect yet your FORUMHOME template is fine in your styles, then they have edited your master style see here - https://vborg.vbsupport.ru/showpost....1&postcount=52

The only way that is possible is by them uploading shell scripts that then allow them to modify files to place the site in debug mode, heck you can do that for one single user via a quick plugin. Check for files such as lol.php and others, also check above your forum root in public_html and others for files such as lol.php or similar names, check timestamps of files as one could be a shell script and yes do replace all your vBulletin files with 100% fresh files, download the same version (patched of course) and then overwrite all files - REMEMBER to delete the /install/ folder before uploading.
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01114 seconds
  • Memory Usage 1,777KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_quote
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete