The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
Hello,
I just opened my calendar and for today where should be birthdays I have message: Hacked By: CrAcKeR-BeSi: 24-10-2009 Hacked By: CrAcKeR-BeSi: 24-10-2009 <meta HTTP-EQUIV="REFRESH" content="0; url=http://villarustica.com.mk/": 24-10-2009 this message is also showen in events on home page. When you click on todays date you could see this: http://i34.tinypic.com/35ba17b.jpg Is this serious and where is hole. How can I prevent from this? ------------------ Edit : I found this line in my headinclude: <meta name="description" content="$vboptKalendar Hacked By: CrAcKeR-BeSi: 24-10-2009 Hacked By: CrAcKeR-BeSi: 24-10-2009 <meta HTTP-EQUIV="REFRESH" content="0; url=http://villarustica.com.mk/": 24-10-2009 ions[description]" /> How did they menage to put it there? |
#2
|
||||
|
||||
![]()
The only place I know of where that could be added is the admincp. Check your logs for anything suspicious.
|
#3
|
|||
|
|||
![]()
Hello Devanand,
which version of VB do you run? |
#4
|
|||
|
|||
![]()
There are a few possibilities, if your FTP/other stuff remains untouched, I would rule out a keylogging or trojan attempt. VB-wise, there are many exploits that are avalible publicly, always make sure everything you add to the forum has no public exploits (through google), and make sure you have the latest version of vBulletin installed.
|
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|