Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 12-14-2007, 12:36 PM
Bradley_Wint Bradley_Wint is offline
 
Join Date: Jul 2007
Posts: 543
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default I Just got hacked...What Now?

Well folks, My account was hacked....I was lucky enough to change my info back from the phpmyadmin backend. What this means though is my system seems to be vulnerable. I have vbExternal, Deluxe Login and AnyMedia mods installed. Are any of these mods hackable? Or is it just vb?
Reply With Quote
  #2  
Old 12-14-2007, 01:14 PM
Calash's Avatar
Calash Calash is offline
 
Join Date: Jun 2006
Location: East Coast, USA
Posts: 297
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

First thing to do is check all your files. Look for anything that should not be there. A common practice once a hacker gets access is to leave a shell script of some kind, so they can get back at any time.

What type of damage did they do? Was it just an alteration of some of the pages or was there deeper access, possible to the database.

I would suggest disabling all your mods and change all your passwords. Once some other replies come in on the security of the mods you can then determine if they are safe enough to reactivate.
Reply With Quote
  #3  
Old 12-14-2007, 01:15 PM
UberMensch UberMensch is offline
 
Join Date: Jun 2006
Posts: 33
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Very much doubt it would be vBulletin itself. Jelsoft are professional coders

The second mod sounds a bit iffy, what does it do?
Reply With Quote
  #4  
Old 12-14-2007, 01:28 PM
Bradley_Wint Bradley_Wint is offline
 
Join Date: Jul 2007
Posts: 543
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Calash View Post
First thing to do is check all your files. Look for anything that should not be there. A common practice once a hacker gets access is to leave a shell script of some kind, so they can get back at any time.

What type of damage did they do? Was it just an alteration of some of the pages or was there deeper access, possible to the database.

I would suggest disabling all your mods and change all your passwords. Once some other replies come in on the security of the mods you can then determine if they are safe enough to reactivate.
They only hacked my account so far. I have changed my passwords and disabled the one mod that is attached to vb. the vbexternal and deluxe login are separate so i left those.

I dunno but I wanna think it was a flaw in the deluxe login but I read through the entire mod post and no one complained of hack issues.


Update - Ok i checked my ip trail and there seems to be no odd ip addresses so I will assume my account was not accesses yet. Secondly, My mods are disabled and there seems to be no file tampering. Is it possible to hack people via the password recovery method. I remember MSN used to have that problem so maybe it might be possible this way.

UberMensch - I wouldn't say vb is 100% hack proof so I wouldn't want to rule it out because they have come across very vulnerable holes in the past.


Is there a possibility that bots are attacking my site and changing the password alone?
Reply With Quote
  #5  
Old 12-14-2007, 05:52 PM
Kirk Y's Avatar
Kirk Y Kirk Y is offline
 
Join Date: Apr 2005
Location: Tallahassee, Florida
Posts: 2,604
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Bradley_Wint View Post
UberMensch - I wouldn't say vb is 100% hack proof so I wouldn't want to rule it out because they have come across very vulnerable holes in the past.
Vanilla vBulletin is 99.9% secure. Not to mention, these "vulnerable holes" you mentioned almost always (1) require an extravagantly outlandish and extreme set of circumstances, variables, and conditions be met for any security breach to occur and (2) are fixed before most of the Internet at large knows they exist.

Having said that, the fault most surely lies either with your server or a modification you've installed/made physically to your vBulletin installation.

I'd suggest that you replace all your non-image files with fresh ones from the vBulletin.com Member's Area.

There is also a feature in the vBulletin AdminCP under "Maintenance" which is called "Check for Suspect Files". Using this, you can see any files whose contents don't match what default vBulletin files should contain and also any non-native files in your forum directory.
Reply With Quote
  #6  
Old 12-14-2007, 07:32 PM
Bradley_Wint Bradley_Wint is offline
 
Join Date: Jul 2007
Posts: 543
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Ok so I did a Suspect File check and found this file on the server:

modevfration.php >> apparently it is a php.backdoor trojan

I am going to check into the other mods to see if there are any security breaches. Plus I got some info from the vbulletin.com forums on how to secure vb much more so I will be doing that. Thanks for the help so far and I will report back on my progress.

I think I may know why the worm slipped in. I had HTML enabled for a forum where only I could post but I think having HTML is a bad idea period so it's disabled as well.
Reply With Quote
  #7  
Old 12-21-2007, 04:38 AM
binkuang binkuang is offline
 
Join Date: Dec 2007
Posts: 77
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

hi....i m the new vb comer...and my forum just got hack in 2 weeks ago. they can get in my admin anytime they want. i change and make the double password on my admin cp...but it desn't work. and then my friend tell me rename the admin cp folder. i mean " change uume.com/admincp to uume.com/XXX....after i did change. i never see him get in my admin again. i really want to know.....how can i see his hack file or trojan virus in my wed server? how can i test that? is that use the software or something eles?
Reply With Quote
  #8  
Old 12-21-2007, 03:07 PM
Bradley_Wint Bradley_Wint is offline
 
Join Date: Jul 2007
Posts: 543
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Binkuang, This is what Kirk Y said, and it worked for me -
Quote:
There is also a feature in the vBulletin AdminCP under "Maintenance" which is called "Check for Suspect Files". Using this, you can see any files whose contents don't match what default vBulletin files should contain and also any non-native files in your forum directory.
Reply With Quote
  #9  
Old 12-21-2007, 03:13 PM
binkuang binkuang is offline
 
Join Date: Dec 2007
Posts: 77
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

the hacker just get back today....i really think he can't get in my admin cp......but not. i erase all file and post and the mysql database too. that is very sick. www.monkeylovepig.com is my froum. i lossed


i really not see the one called "Check for Suspect Files" in the Maintenance. the list have Database Backup , Repair / Optimize Tables , Update Counters,Diagnostics, Execute SQL Query, View PHP info. is that my forum is different? and also how to disabling all mods.
Reply With Quote
  #10  
Old 12-21-2007, 03:43 PM
Calash's Avatar
Calash Calash is offline
 
Join Date: Jun 2006
Location: East Coast, USA
Posts: 297
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Changing your password is the first step, but it is not the only step and you cannot stop at that point. You need to find out how the hacker got access to your site, and if they left anything behind to allow them to access it again.

If you are on a shared host you may also want to check there support. I have seen times that, due to specific configurations, other accounts can place files in your web space, or worse edit files in your space.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:50 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04351 seconds
  • Memory Usage 2,272KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete