Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions

Reply
 
Thread Tools Display Modes
  #11  
Old 07-28-2007, 10:36 PM
EnIgMa1234 EnIgMa1234 is offline
 
Join Date: Mar 2006
Location: .:: Ireland ::.
Posts: 1,306
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Also dont forget to change your cpanel password
Reply With Quote
  #12  
Old 07-29-2007, 12:56 AM
mnm85 mnm85 is offline
 
Join Date: Jul 2007
Posts: 11
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The first attachment says: May god ++++ your forums, enough of this you dog your tiring me, watch me admin.

Second attachment says: ill play Bank admin, Your disappointing forum has been hacked, i will now change the index file, wait a while.

just wanted to help, don't take this the wrong way, if you do. Sorry...
Reply With Quote
  #13  
Old 07-29-2007, 11:20 AM
TvForce TvForce is offline
 
Join Date: Jul 2007
Posts: 10
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

this happened to me and you cant stop it no matter how hard you try. Once they have injected the database that is it. I had to restart fresh
Reply With Quote
  #14  
Old 07-29-2007, 08:09 PM
TunerNetwork TunerNetwork is offline
 
Join Date: Jul 2004
Location: CT
Posts: 153
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

ok, here's the latest, I installed a backup from two weeks ago, 7/11/07. I then updated to the newest versions, I changed all the pws, I then changed the names of my admin and modcp folders etc in the config. I set my admins id #'s in the config file so they can not be edited etc. I dont allow html etc. Now, for the .htpassword or whatever, how do I do that, Im not too familar with it. Should i password protect anything else etc.
Reply With Quote
  #15  
Old 07-29-2007, 08:15 PM
Delphiprogrammi Delphiprogrammi is offline
 
Join Date: Feb 2004
Location: Landen(Belgium)
Posts: 1,335
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Cpanel contains a utility that helps you with that click "password protect directorys" also you have two installers in a web accessible location that's asking to mess your board up delete those installers !!

Quote:
vbacmps_install.php File not recognized as part of vBulletin
vbalinks_install.php File not recognized as part of vBulletin
Reply With Quote
  #16  
Old 07-29-2007, 08:16 PM
EnIgMa1234 EnIgMa1234 is offline
 
Join Date: Mar 2006
Location: .:: Ireland ::.
Posts: 1,306
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Look in cpanel for password protect directorys
Reply With Quote
  #17  
Old 07-29-2007, 08:23 PM
TunerNetwork TunerNetwork is offline
 
Join Date: Jul 2004
Location: CT
Posts: 153
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Delphiprogrammi View Post
Cpanel contains a utility that helps you with that click "password protect directorys" also you have two installers in a web accessible location that's asking to mess your board up delete those installers !!
actually i just saw that and am trying and testing that now.

Ok, i just pw protected my cgi-bin folder, my admin and modcp folders. anything else?

I think I might have it pretty tight now, unless you guys can recommend anything else
Reply With Quote
  #18  
Old 07-29-2007, 10:22 PM
MRGTB MRGTB is offline
 
Join Date: Dec 2004
Posts: 548
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Delphiprogrammi View Post
Cpanel contains a utility that helps you with that click "password protect directorys" also you have two installers in a web accessible location that's asking to mess your board up delete those installers !!
WOW, talk about a security risk. Why have these installation files not been deleted? Thats asking to be hacked - handed on a plate!
Reply With Quote
  #19  
Old 07-30-2007, 01:18 PM
TunerNetwork TunerNetwork is offline
 
Join Date: Jul 2004
Location: CT
Posts: 153
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

K, those have been deleted. MRGTB, im not a coding pro etc, I posted on here for your help and I appreciate everyone's responses, as I feel my site is 100x more secured now because of your help.
Reply With Quote
  #20  
Old 08-01-2007, 02:33 PM
TunerNetwork TunerNetwork is offline
 
Join Date: Jul 2004
Location: CT
Posts: 153
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

well, lastnight, after i did the security fixes etc, I got the big...you've been hacked page on the index page. figured that was coming. I uploaded a backup etc, did all the security fixes etc. Anyone here experienced to look at my database and see if any files are there which arent supposed to be, there must be something there for them to keep getting access to the backend. I have it locked up tight, it's a pain even for me to get there lol

my aim is TN Zazza

I just removed the install and installer folders from my server, just downloaded them to my pc and removed them from online. Figured this would be a potential place to try and mess up

What i did is delete alot of mods that I was not really using anymore etc and am trying to clean up the board some. Here is my diagnostics list now, see anything bad, let me know:

Root:
arcade.php
fixoptions.php
mm_menu.js
modelapp.php
template.htm
vbfavorites.php
vbgarage.php

Clientscript:
activecell.htc
ncode_imageresizer.js

Admin:
arcade.php
vba_cmps_admin.php

Includes:
adminfunctions_links.php
adminfunctions_vba_cmps.php
class_dm_itrader.php
class_ucs_core.php
datastore_cache.php
functions_links.php
functions_ucs_shared.php
vba_cmps_include_bottom.php
vba_cmps_include_error.php
vba_cmps_include_template.php
vba_cmps_include_top.php
vba_cmps_plugin_newpost.php

Includes/Cron:
articlebot_vbcron.php
links_search.php
links_subscriptions.php
rsvp_notify.php
vba_global_error.php

Includes/XML:
bitfield_comments.xml
bitfield_profileviews.xml
cpnav_arcade.xml
cpnav_rpm.xml
cpnav_ucs.xml
cpnav_vbacmps.xml
hooks_ibproarcade.xml
hooks_v3arcade.xml
product-ibproarcade.xml

These are the ones that get the "File not recognized as part of vBulletin" message when I run the diagnostics. As you can see, a bunch of them are from my vbadvanced being installed.

Appreciate the input.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:55 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02333 seconds
  • Memory Usage 2,260KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete