Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 06-21-2007, 08:22 PM
mawby mawby is offline
 
Join Date: Jun 2004
Location: Wiltshire, England
Posts: 145
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Forum Hacked - Password Harvesting Plugin Installed

I spotted a plugin installed on my site today which I didn't recognise. It was named "Database Optimization", had vBulletin as the product, and was hooked into login_verify_success. The plugin was only a few lines of code, but it sent an email containing the users username and password everytime they logged into the forum!

After some investigations we've found that this hack started sending emails on the 17th at 4am GMT. At this time our server was running 3.6.4, with all released security fixes installed. We upgraded to 3.6.7 yesterday after a required PHP upgrade was done. At this point the hack no longer sent the users password out, so I presume a fix has been made to prevent plugins gaining access to the users passwords now.

However, I'm making this post firstly to alert others to the possible problem, but also to ask if anyone else has suffered from this type of hacking and does anyone know how it was done so I can try and make sure it doesn't happen again?

We had the following plugins installed;

'Version check' for all hacks
Ban Thread User
CSS Signature Size Enforcer
Cyb - Sub-Forum Manager
Extra Thread Fields Lite
Farcaster's Event Attendance
Geek Auto-Link
HELLCATs Realtime Page Compressor
ibProArcade for vBulletin
IpInfo
iTrader
Moderation Auto-PM
Post Edit History
Private Debates
Show Birthday Icon in Postbit
vbAccessDenied
vBadvanced CMPS
vbBannerRotator by Frapegliko
vBDebug Mode
vBPicGallery
Vbulletin World Map Plotter
Welcome Headers
Yet Another Mass Private Message System
Reply With Quote
  #2  
Old 06-21-2007, 09:45 PM
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Location: Nottingham, UK
Posts: 23,748
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Nothing has changed around that hook between 3.6.4 and 3.6.7 so something else must have stopped it working.
Reply With Quote
  #3  
Old 06-22-2007, 07:12 AM
mawby mawby is offline
 
Join Date: Jun 2004
Location: Wiltshire, England
Posts: 145
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Paul M View Post
Nothing has changed around that hook between 3.6.4 and 3.6.7 so something else must have stopped it working.
That is what is worrying me and is one reason I've posted up about it. Having looked at the diffs myself I cannot see why this stopped working, but it did.

As you're an admin here I will PM you the contents of the plugin, maybe you could take a quick look and give your opinion if this hack is a problem in vB (past or present) or whether it only worked because of some other plugin I had installed.

As part of my upgrade I did make the following changes to the plugins I had installed so maybe one of these is the reason the hack stopped working?

Removed Chatbox 1.4
Updated Cyb - Forumhome Sub-Forums Manager from 2.1 to 2.4
Updated Farcaster's Event Attendance from 1.2.0 to 1.2.1
Updated vBPicGallery from 10.0.3 to 10.0.4
Updated vBadvanced CMPS from 2.2.1 (vB 3.6) to 3.0 RC1
Reply With Quote
  #4  
Old 06-22-2007, 07:23 AM
G0F0RBR0KE G0F0RBR0KE is offline
 
Join Date: Mar 2005
Posts: 987
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

When it sends e-mail to users. What does the e-mail say?
Reply With Quote
  #5  
Old 06-22-2007, 07:29 AM
mawby mawby is offline
 
Join Date: Jun 2004
Location: Wiltshire, England
Posts: 145
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by EvilAkuma View Post
When it sends e-mail to users. What does the e-mail say?
The subject is the users username, the contents is the users plain text password, nothing else is sent in the email.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 03:47 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03757 seconds
  • Memory Usage 2,196KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (5)post_thanks_box
  • (5)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (5)post_thanks_postbit_info
  • (5)postbit
  • (5)postbit_onlinestatus
  • (5)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete