Quote:
Originally Posted by Toorak Times
I got smashed 5 times BOP, my database is still psychopathic. have a look if you like...PLEASE!!!
|
I would suggest you look for .php files in the following directories- I've found them in these directories while cleaning up hacked sites before (check all sub-folders of these folders as well)-
/customavatars
/customgroupicons
/customprofilepics
/images
/signaturepics
If you have attachments stored in a web accessible location check that folder too.
These folders should not contain .php files.
As for being in your database the only real place they could be is in a plugin. Check and make sure you don't have any plugins listed in Plugin Manager (not product manager) at the top listed under the "vBulletin" product. If you do make sure these are plugins you created yourself and double-check the code. This is the most often exploited spot.
Second most exploited in my experience is hidden as a plugin of Forum Runner but this will be cleaned if you re-run the upgrade script which I recommend you do if you've been hacked.
Any 3rd party products should be re-installed after a hack to make sure their plugins are the original values and don't contain backdoors left by the hacker.