Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
  #1  
Old 06-21-2009, 02:04 PM
spracing spracing is offline
 
Join Date: Jul 2007
Posts: 3
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default My forum hacked by Tw!sT3R

Hi everyone, recently my forum was hacked and now I can't get to anywhere on the site, ie. admin,etc...

Here is a pic of the opening page

Can anyone help me with what files they have attacked? I'm on version 3.7.2

Thank you very much!

Chris
Attached Images
File Type: jpg hacked.jpg (70.8 KB, 0 views)
Reply With Quote
  #2  
Old 06-21-2009, 02:10 PM
R1lover's Avatar
R1lover R1lover is offline
 
Join Date: Apr 2006
Location: Northern Ca
Posts: 428
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Log in via ftp and see which files have been modified....

my guess is the index page and .htaccess. But there could be changes to your database as well.

DO you have a backup?
Reply With Quote
  #3  
Old 06-21-2009, 04:53 PM
spracing spracing is offline
 
Join Date: Jul 2007
Posts: 3
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Unfortunately the only recent backup I have was after it was hacked (from my host) sad but true . I was out of town when it happened and didn't see this in time so the backup took place after it was hacked and before I was able to run my own.

Is there anything in those files I should search for that may help me locate the script/code?

Thanks for the quick reply R1lover

Chris
Reply With Quote
  #4  
Old 06-21-2009, 05:33 PM
Brandon Sheley's Avatar
Brandon Sheley Brandon Sheley is offline
 
Join Date: Mar 2005
Location: Google Kansas
Posts: 4,678
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You don't have a previous backup?
view the source of your pages, than search in your templates
why can't u login to your admincp?
http://www.forcedinductionforums.com/forums/admincp/
Reply With Quote
  #5  
Old 06-21-2009, 05:36 PM
Extricate Extricate is offline
 
Join Date: Apr 2009
Posts: 1
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Also, be sure to check the configuration file (./includes/config.php)
And make sure the hacker did not enter his user ID in there, under specific fields (as in; super administrator, etc.)
Else he'll be able to simply destroy your website again afterwards.

Do you know how the hacker gained access? (As in, FTP; cPanel, etc.)
Reply With Quote
  #6  
Old 06-22-2009, 12:37 AM
spracing spracing is offline
 
Join Date: Jul 2007
Posts: 3
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Loco, since its not a very used forum of mine I don't focus on it too much so sadly I had no recent backups after a bunch of changes, I know very stupid on my part.

As for logging in, my password for admin is no longer working so it just keeps sending my to the hacked image when I submit. Is there a way to change the password in the database? I use navicat but it looks like it's encrypted.

Extricate, I checked the config files and don't notice anything out of the norm like a username for super admin.
I'm not sure how they obtained access to the site, I've contacted host monster but they weren't of much help in tracking.

Anywhere else I should look? what kind of text out of the ordinary code lines should I look/search for and where?

Thanks
Chris
Reply With Quote
  #7  
Old 06-22-2009, 04:21 AM
R1lover's Avatar
R1lover R1lover is offline
 
Join Date: Apr 2006
Location: Northern Ca
Posts: 428
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Do you know your userid?

If so set it as the Super Admin and nobody else.... in the config file.

Next if you still can't login then reset your password via phpmyadmin, here an incrypted password for "admin"

replace the password for your account in the user table of the database.

PHP Code:
5de5a1e8a825ff8f12693882b2422c2e 
Then see if you can login, if you can then change that password via the admin panel.

Next I would re-upload all original vbulletin files. See where you are at from there.
Reply With Quote
  #8  
Old 06-22-2009, 04:55 AM
JamesC70 JamesC70 is offline
 
Join Date: Jun 2007
Posts: 219
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by spracing View Post
Extricate, I checked the config files and don't notice anything out of the norm like a username for super admin.
In config.php, do a search for
Code:
unalterable user
The result will be the user number(s) of the designated Admin account(s). In a default vBulletin install, this is user #1 and only user #1. (If you know you changed/added this, that's fine. Otherwise, any additional user #s will clue you in as to who may have been involved.)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:50 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03760 seconds
  • Memory Usage 2,237KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_code
  • (1)bbcode_php
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (8)post_thanks_box
  • (8)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (8)post_thanks_postbit_info
  • (8)postbit
  • (1)postbit_attachment
  • (8)postbit_onlinestatus
  • (8)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_attachment
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete