We’re running the patched version. We’re not planning on upgrading to 4.1.2 because we put so much work into skinning 4.1.10. Which was a pain to begin with. As for mods, we turned all plugins off and we still get pop up redirects from this site. Its cookie is also constantly found in our cookies list. Do you have any idea as to what template this code might be present in? Can iframe be executed from any template? It seems to be positioned in the body of the forum. Where would I find those templates. I’ve already combed:
Forum head
Forum header
All css templates
Forum footer
and a few others.
--------------- Added [DATE]1573192701[/DATE] at [TIME]1573192701[/TIME] ---------------
Also since the source seems to be a php file, is it possible I could find the source of this malware in my vbulletin files in my file manager? I?ve read this same malware has been used on some wordpress forums and the source was discovered inside wordpress functions.php file.
|