The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
I spotted a plugin installed on my site today which I didn't recognise. It was named "Database Optimization", had vBulletin as the product, and was hooked into login_verify_success. The plugin was only a few lines of code, but it sent an email containing the users username and password everytime they logged into the forum!
After some investigations we've found that this hack started sending emails on the 17th at 4am GMT. At this time our server was running 3.6.4, with all released security fixes installed. We upgraded to 3.6.7 yesterday after a required PHP upgrade was done. At this point the hack no longer sent the users password out, so I presume a fix has been made to prevent plugins gaining access to the users passwords now. However, I'm making this post firstly to alert others to the possible problem, but also to ask if anyone else has suffered from this type of hacking and does anyone know how it was done so I can try and make sure it doesn't happen again? We had the following plugins installed; 'Version check' for all hacks Ban Thread User CSS Signature Size Enforcer Cyb - Sub-Forum Manager Extra Thread Fields Lite Farcaster's Event Attendance Geek Auto-Link HELLCATs Realtime Page Compressor ibProArcade for vBulletin IpInfo iTrader Moderation Auto-PM Post Edit History Private Debates Show Birthday Icon in Postbit vbAccessDenied vBadvanced CMPS vbBannerRotator by Frapegliko vBDebug Mode vBPicGallery Vbulletin World Map Plotter Welcome Headers Yet Another Mass Private Message System |
#2
|
||||
|
||||
![]()
Nothing has changed around that hook between 3.6.4 and 3.6.7 so something else must have stopped it working.
|
#3
|
|||
|
|||
![]() Quote:
As you're an admin here I will PM you the contents of the plugin, maybe you could take a quick look and give your opinion if this hack is a problem in vB (past or present) or whether it only worked because of some other plugin I had installed. As part of my upgrade I did make the following changes to the plugins I had installed so maybe one of these is the reason the hack stopped working? Removed Chatbox 1.4 Updated Cyb - Forumhome Sub-Forums Manager from 2.1 to 2.4 Updated Farcaster's Event Attendance from 1.2.0 to 1.2.1 Updated vBPicGallery from 10.0.3 to 10.0.4 Updated vBadvanced CMPS from 2.2.1 (vB 3.6) to 3.0 RC1 |
#4
|
|||
|
|||
![]()
When it sends e-mail to users. What does the e-mail say?
|
#5
|
|||
|
|||
![]()
The subject is the users username, the contents is the users plain text password, nothing else is sent in the email.
|
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|