Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 03-05-2009, 12:29 AM
Senzuri Senzuri is offline
 
Join Date: Mar 2007
Posts: 25
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Site Hacked

Hi,

My site was recently defaced and I'm trying to figure out how he did it so I can prevent future attacks. I'm guessing he would have probably used an RFI exploit due to the fact that I haven't been regularly updating my sites software. Below is a list of all the mods I've been using as well as the versions. I'm hoping that someone will be able to help identify how he did.

VB version: v3.7.2 Patch Level 2

Admin Log In As User 3.0
April Fools Banning 1.0
Auto Move Closed Threads 1.1.1
Casino .92
Community News Letter Light 1.0.0 1.0.0
Cyb - Advanced Permissions Based on Post Count 4.4
FractalizeR: Registration Form AJAX Enhancements 1.1.1
ibProArcade for vBulletin 2.6.7
Limited Guest Viewing 1.2.1
Members who have Visited 3.7.003
MGC chatbox Evo 0.5.0
MGC Chatbox Evo Commands 0.0.0
Mobile Device Detection 1.0.0
Multiple Login Detector 1.03
Next Generation Postbit Legacy View 1.0.0
NoSpam! 4.0
passiveVid 1.1.2
Post Thank You Hack 7.6
Separate Sticky and Normal Threads 2.0.0
Stop the Registration Bots 1.0.3
TCattd - The Image Resizer 1.2.6
Top Posters 3.7.002
Usergroup Color Bar 1.0.0
vBCredits 1.4
Welcome Headers 5.0.2
Word Replacements 1.0.0
Reply With Quote
  #2  
Old 03-05-2009, 12:45 AM
fattony69 fattony69 is offline
 
Join Date: Jun 2007
Location: Philly
Posts: 353
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Why aren't you using the newest vbulletin? Pardon me for saying this, all the boards that are 3.7.2 patch 2 I know of are nulled and were reported by me.
Reply With Quote
  #3  
Old 03-05-2009, 12:51 AM
Senzuri Senzuri is offline
 
Join Date: Mar 2007
Posts: 25
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by fattony69 View Post
Why aren't you using the newest vbulletin? Pardon me for saying this, all the boards that are 3.7.2 patch 2 I know of are nulled and were reported by me.
Are you kidding? I haven't updated my forum because I've been lazy and I've also had problems when upgrading. I've had a VB subscription for 2 years which has cost me a bit, go troll someone elses thread kthx.

Also if anyone can help, I'd appreciate it
Reply With Quote
  #4  
Old 03-05-2009, 02:58 AM
R1lover's Avatar
R1lover R1lover is offline
 
Join Date: Apr 2006
Location: Northern Ca
Posts: 428
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

There is really no way for anyone here to tell how they got in, first you need to figure out what they changed to hack your site, then that will lead to clues maybe on how they did it.
Reply With Quote
  #5  
Old 03-05-2009, 02:59 AM
fattony69 fattony69 is offline
 
Join Date: Jun 2007
Location: Philly
Posts: 353
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Senzuri View Post
Are you kidding? I haven't updated my forum because I've been lazy and I've also had problems when upgrading. I've had a VB subscription for 2 years which has cost me a bit, go troll someone elses thread kthx.

Also if anyone can help, I'd appreciate it
I am not saying you are. I am just saying it is common. Jeez. I am trying to help. Are you using bluehost?
Reply With Quote
  #6  
Old 03-05-2009, 03:12 AM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

If you can, look through your access_logs to see if you can see what they did to get hack the site (if it was through a mod). If you don't have access to the logs, you should ask your host for them soon because they might not keep them for long at all.

Go read the threads for all the mods you listed and see if any security issues have been brought up. Were you up-to-date on all the mods?
Reply With Quote
  #7  
Old 03-05-2009, 03:40 AM
TNCclubman's Avatar
TNCclubman TNCclubman is offline
 
Join Date: Sep 2008
Posts: 690
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

From experience, the more mods you install, the more vulnerable you are. I wouldnt install more than 3 max... seriously, ask yourself if its worth getting hacked when you go and install something 'cute'. Plus it makes upgrades a major pain in tha arse.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:49 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04310 seconds
  • Memory Usage 2,213KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (7)post_thanks_box
  • (7)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (7)post_thanks_postbit_info
  • (7)postbit
  • (7)postbit_onlinestatus
  • (7)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete