The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
Well folks, My account was hacked....I was lucky enough to change my info back from the phpmyadmin backend. What this means though is my system seems to be vulnerable. I have vbExternal, Deluxe Login and AnyMedia mods installed. Are any of these mods hackable? Or is it just vb?
|
#2
|
||||
|
||||
![]()
First thing to do is check all your files. Look for anything that should not be there. A common practice once a hacker gets access is to leave a shell script of some kind, so they can get back at any time.
What type of damage did they do? Was it just an alteration of some of the pages or was there deeper access, possible to the database. I would suggest disabling all your mods and change all your passwords. Once some other replies come in on the security of the mods you can then determine if they are safe enough to reactivate. |
#3
|
|||
|
|||
![]()
Very much doubt it would be vBulletin itself. Jelsoft are professional coders
![]() The second mod sounds a bit iffy, what does it do? |
#4
|
|||
|
|||
![]() Quote:
I dunno but I wanna think it was a flaw in the deluxe login but I read through the entire mod post and no one complained of hack issues. Update - Ok i checked my ip trail and there seems to be no odd ip addresses so I will assume my account was not accesses yet. Secondly, My mods are disabled and there seems to be no file tampering. Is it possible to hack people via the password recovery method. I remember MSN used to have that problem so maybe it might be possible this way. UberMensch - I wouldn't say vb is 100% hack proof so I wouldn't want to rule it out because they have come across very vulnerable holes in the past. Is there a possibility that bots are attacking my site and changing the password alone? |
#5
|
||||
|
||||
![]() Quote:
Having said that, the fault most surely lies either with your server or a modification you've installed/made physically to your vBulletin installation. I'd suggest that you replace all your non-image files with fresh ones from the vBulletin.com Member's Area. There is also a feature in the vBulletin AdminCP under "Maintenance" which is called "Check for Suspect Files". Using this, you can see any files whose contents don't match what default vBulletin files should contain and also any non-native files in your forum directory. |
#6
|
|||
|
|||
![]()
Ok so I did a Suspect File check and found this file on the server:
modevfration.php >> apparently it is a php.backdoor trojan I am going to check into the other mods to see if there are any security breaches. Plus I got some info from the vbulletin.com forums on how to secure vb much more so I will be doing that. Thanks for the help so far and I will report back on my progress. I think I may know why the worm slipped in. I had HTML enabled for a forum where only I could post but I think having HTML is a bad idea period so it's disabled as well. |
#7
|
|||
|
|||
![]()
hi....i m the new vb comer...and my forum just got hack in 2 weeks ago. they can get in my admin anytime they want. i change and make the double password on my admin cp...but it desn't work. and then my friend tell me rename the admin cp folder. i mean " change uume.com/admincp to uume.com/XXX....after i did change. i never see him get in my admin again. i really want to know.....how can i see his hack file or trojan virus in my wed server? how can i test that? is that use the software or something eles?
|
#8
|
|||
|
|||
![]()
Binkuang, This is what Kirk Y said, and it worked for me -
Quote:
|
#9
|
|||
|
|||
![]()
the hacker just get back today....i really think he can't get in my admin cp......but not. i erase all file and post and the mysql database too. that is very sick. www.monkeylovepig.com is my froum. i lossed
i really not see the one called "Check for Suspect Files" in the Maintenance. the list have Database Backup , Repair / Optimize Tables , Update Counters,Diagnostics, Execute SQL Query, View PHP info. is that my forum is different? and also how to disabling all mods. |
#10
|
||||
|
||||
![]()
Changing your password is the first step, but it is not the only step and you cannot stop at that point. You need to find out how the hacker got access to your site, and if they left anything behind to allow them to access it again.
If you are on a shared host you may also want to check there support. I have seen times that, due to specific configurations, other accounts can place files in your web space, or worse edit files in your space. |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|