Quote:
Originally Posted by postcd
Dear Mod creator, Dear Community,
the GlowHost Spam-o-matic is excelent, it helps me much. But im experiencing malicious infection regarding "GlowHost - Spam-O-Matic 2.1.2"
First time i had some lower version of your mod. And when i got filestore72.info malicious redirect when comming to my forum from Google (not directly). Then when i disabled your mod, it started working. So i upgraded to the latest version and after few days filestore redirect is back. So i disale mod, and redirect is away
Please any idea how i can debug the cause?! Thank you
|
Nothing to do with this add-on. Disabling any mod will flush the datastore and that will appear to banish the malware temporarily. It will be back after a day or two though until you track down and eradicate it.
There are numerous threads at vB.com, vB.org, and several other forums on this malware. It is enabled by poor server and password security, especially file and directory permissions. You need to lock down your server, update to the latest version of vBulletin and any add-ons, and then check all files from your AdminCP Maintenance menu. You need especially to disallow execution of any files in your upload directories (avatars, profile pics, etc.) and delete the entire install directory after every update.
It's also a good idea to ensure that you have password protected the vBulletin Admin at the server level and change all admin passwords to something secure.