Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #21  
Old 09-03-2006, 08:20 PM
Nuguru Nuguru is offline
 
Join Date: Jun 2006
Posts: 93
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by puertoblack2003
hey guys it 's not only flash it's the topXstat hack too i was hacked as well and i was able to recover from it i was told by steve at .com that the topXstat also has a hole so i uninstalled it and i should be ok i don't know if it had an effect of the newer for 3.6 for i still using .4.
Hello,

I am using Top X Stats 1.6.1a on vb 3.5.4., is there a way to keep this mod and fix the security issue?


Thank You,

Nuguru
Reply With Quote
  #22  
Old 09-03-2006, 11:01 PM
The Finman's Avatar
The Finman The Finman is offline
 
Join Date: Jun 2006
Posts: 78
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Nuguru
Hello,

I am using Top X Stats 1.6.1a on vb 3.5.4., is there a way to keep this mod and fix the security issue?


Thank You,

Nuguru
Yes, this will take care of both problems

These little script kiddies are using some really lame (actually calling them "script kiddies" is being overly generous for these lamers) tricks (more like an annoyance), but here is a very simple fix.

Go into you AdminCP and under vB Options choose Censorship Options.

In the Censored Words window add this.

Code:
{meta} >>>> {http-equiv} "Refresh" """"
That will put an end this nonsense.
Reply With Quote
  #23  
Old 09-04-2006, 06:15 AM
Kohhal's Avatar
Kohhal Kohhal is offline
 
Join Date: Feb 2002
Location: Dublin, Ireland
Posts: 170
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I got hit aswell, removed Flashchat now as it's not worth having for the risks involved...
Reply With Quote
  #24  
Old 09-04-2006, 06:24 AM
Nuguru Nuguru is offline
 
Join Date: Jun 2006
Posts: 93
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by The Finman
Yes, this will take care of both problems

These little script kiddies are using some really lame (actually calling them "script kiddies" is being overly generous for these lamers) tricks (more like an annoyance), but here is a very simple fix.

Go into you AdminCP and under vB Options choose Censorship Options.

In the Censored Words window add this.

Code:
{meta} >>>> {http-equiv} "Refresh" """"
That will put an end this nonsense.
Hello Everyone,

I gotta say, it's times like this when we are all under the pressure of getting matters quickly dealt with that you can really see how users at vbulletin.org come together and help one another. Great job to all for the excellent exchange in communication and support. We'll beat those little shits!

Regards,

Nuguru
Reply With Quote
  #25  
Old 09-04-2006, 11:09 AM
trilOByte's Avatar
trilOByte trilOByte is offline
 
Join Date: Nov 2001
Location: England
Posts: 325
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I got hit as well last night.

The little nobs overwrote files all accross my site, they killed off virtuanews, photopost and vbulletin for a time and left just this message...

"by Thehacker own3d **** israel n0 war"

I was running flashchat, which I have now removed. The scarry thing is once they were in, it seems they had the freedom to roam right accross my domain. They replaced every index.html file in virtuanews with a hacked version and there are dozens in all the sub directory's.

Therer were several other people also hit from my host last night, with the same message.
Reply With Quote
  #26  
Old 09-04-2006, 12:51 PM
Rickie3's Avatar
Rickie3 Rickie3 is offline
 
Join Date: Nov 2004
Location: Australia/Tasmania
Posts: 770
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

thanx for the heads up and fixes people,really appreciate it
Reply With Quote
  #27  
Old 09-04-2006, 01:20 PM
b6gm6n's Avatar
b6gm6n b6gm6n is offline
 
Join Date: Aug 2002
Location: UK
Posts: 691
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I've removed FC for good because of this... i know it's not their fault...but still... don't want the hassle... anyways...another thing you can do to stop these kiddy-fiddlers is remove the version number from your vBulletin... it's legal and can stop these ++++nuts googling your forum for the right version or whatever... just incase

-b6
Reply With Quote
  #28  
Old 09-04-2006, 07:00 PM
trilOByte's Avatar
trilOByte trilOByte is offline
 
Join Date: Nov 2001
Location: England
Posts: 325
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

An update. The hackers came back tonight and somehow gained access again, even after uninstalling the flashchat plugin and all associated plugins, and totally removing all the flashchat files and deleting the chat dir. It seems they must have left some script behind to keep the door open. The first thing that happened was that my chat dir re-appeared and a new set of flashchat files dropped in from the ether.

If we can pin down this backdoor, script, pl file or whatever it is, I'll let you know.
Reply With Quote
  #29  
Old 09-04-2006, 07:35 PM
wacnstac wacnstac is offline
 
Join Date: Nov 2001
Posts: 312
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Please keep us updated, I've been hacked through flashchat too.
Reply With Quote
  #30  
Old 09-04-2006, 08:28 PM
F5-MVH F5-MVH is offline
 
Join Date: Sep 2006
Posts: 2
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

One of the other issues to deal with is new installs after the cleanups occur. For now we have new cronjobs looking for flashchat installs and removing the unneeded files.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:53 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06773 seconds
  • Memory Usage 2,259KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_code
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete