Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 09-14-2013, 10:16 PM
HarshlyCritical HarshlyCritical is offline
 
Join Date: Dec 2012
Posts: 2
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Forum home page hacked - at a loss.

First of all, I have read this: http://www.vbulletin.com/forum/blogs...ve-been-hacked

I have followed steps 1 and 2. Step 3 is unncessary because I have retained administrator privileges. Step 4 also seems unnecessary. If you'd like to see the damage, this is it:

http://www.horrorgameforums.com/

And this is where Steps 5 and 6 come in... They say in Step 5 that AdminCP "provides a tool to scan directories". Well, great. Where is it? I cannot find it.

According to the Control Panel Log, this user made a total of three changes... All to plugin.php. The first one says "files" under Action, the second one says "doimport" under Action, and the third one is blank. So I assumed that since it's some sort of nefarious plugin, I could remove it. Except, following Step 6, when I go under Plugin Manager (the only one without a strikethrough is vBulletin, so I hit "Edit") there are hundreds and hundreds of them. Am I really supposed to go through each and every one? I can't figure this out.

Even when I disable all plugins (I put a line in config.php to supposedly disable them all), my home page still displays that irritating page. Please, I've been going crazy for the last couple of hours and have no idea where to go with this.

Also, the user who did this made themselves an administrator. Unfortunately, I cannot remove them, even though I'm a superadmin! They somehow made themselves uneditable, even though config.php does not display this information. I've googled extensively and I can't figure this out...

Thanks for any help.
Reply With Quote
  #2  
Old 09-14-2013, 10:58 PM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The tool is under Maintenance --> Diagnostics run the Suspect File Versions

Reply With Quote
  #3  
Old 09-15-2013, 12:06 AM
HarshlyCritical HarshlyCritical is offline
 
Join Date: Dec 2012
Posts: 2
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ozzy47 View Post
The tool is under Maintenance --> Diagnostics run the Suspect File Versions


Thank you.

It says everything's fine except for config.php... Which I have edited a little bit, so that's to be expected.

How do I delete users that are "uneditable", if they aren't listed as uneditable in config? I can't figure that one out...
Reply With Quote
  #4  
Old 09-15-2013, 12:18 AM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Did you try doing that with all plugins disabled?
Reply With Quote
  #5  
Old 09-15-2013, 01:18 AM
TheLastSuperman's Avatar
TheLastSuperman TheLastSuperman is offline
Senior Member
 
Join Date: Sep 2008
Location: North Carolina
Posts: 5,844
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

http://www.vbulletin.com/forum/blogs...vbulletin-site

Edit: Also see my post here - https://vborg.vbsupport.ru/showpost....1&postcount=52

I bet they simply edited some templates, try reverting any newly customized templates via style manager before doing anything else. *Also please note the queries I list in my blog article, you can replace the words we are searching for w/ anything you wish for example:

PHP Code:
SELECT styleidtitletemplate FROM template WHERE template LIKE '%adf.ly%'
Reply With Quote
  #6  
Old 09-15-2013, 02:32 AM
bremereric's Avatar
bremereric bremereric is offline
 
Join Date: Aug 2011
Location: Tomball Texas
Posts: 203
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Replace your vb files from a previous backup. I had to do the same today. They hacked my default style which I copied the code from another and fixed and then the Home page was offering free money. I restored the program files from my hosting company and they are working like a charm. I also bought sitelock and they have their firewall up and running. VB will not protect your site. You will have to get something to do it also.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:45 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03472 seconds
  • Memory Usage 2,211KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_php
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (6)post_thanks_box
  • (6)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (6)post_thanks_postbit_info
  • (6)postbit
  • (6)postbit_onlinestatus
  • (6)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete