Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions

Reply
 
Thread Tools Display Modes
  #11  
Old 03-21-2016, 12:33 PM
Dave Dave is offline
 
Join Date: May 2010
Posts: 2,583
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

SSL is not the same as SSH though.
SSL makes it possible to get HTTPS on your website, SSH allows you to connect to the server and execute commands on the server.

The only advantage of SSL is that the data that's being exchanged between the client and server is encrypted, it will not block any hacks whatsoever.
Reply With Quote
  #12  
Old 03-21-2016, 01:00 PM
Scalemotorcars's Avatar
Scalemotorcars Scalemotorcars is offline
 
Join Date: Mar 2006
Location: NC
Posts: 619
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

@Dave

Looks like you read the post before I figured out you said SSH and not SSL and edited it.

--------------- Added [DATE]1458570552[/DATE] at [TIME]1458570552[/TIME] ---------------

Quote:
Originally Posted by RichieBoy67 View Post
You can also download the files and then do a text search in all the files using notepadd++...

If you thin you are hacked you can search for debase64 in the files and any of the non vbulletin files you can take a closer look at. Just because some may have it doesn't neccesarily mean they are hacked but it will help you narror things down.

Chances are though if your site is sending out emails it is your server and not your site. Perhaps someone has gotten your smtp passwords. Make sure you have relaying closed or authorization required.
Well I didn't find anything with debase64. And a search in all those Non VB or edited VB files returned 1200 hits for the keyword "mail"

Any way to narrow down that result?
Reply With Quote
  #13  
Old 03-21-2016, 01:45 PM
Dave Dave is offline
 
Join Date: May 2010
Posts: 2,583
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

VPS is not as expensive as a dedicated server though, you can get a decent VPS for around $20/month.

Try looking for "mail(" with the parentheses. Another thing you can look for is "base64_decode" and "popen" for any potential backdoors/PHP shells.
Reply With Quote
Благодарность от:
In Omnibus
  #14  
Old 03-21-2016, 02:02 PM
Scalemotorcars's Avatar
Scalemotorcars Scalemotorcars is offline
 
Join Date: Mar 2006
Location: NC
Posts: 619
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Dave I found 6 results on 6 different PHP scripts for base64_decode. All 6 have what looks like the same line but I also found those same lines of code in the stock VB 4- files. So... I guess thats normal. I didn't find anything looking for "Mail(" or popen.

--------------- Added [DATE]1458584124[/DATE] at [TIME]1458584124[/TIME] ---------------

Now Im 100% sure Ive been hacked. I found details on the malware here. http://blog.mxlab.eu/2016/03/21/new-...een-suspended/

I still have no ideal where its coming from. Could this be on my PC?
Reply With Quote
  #15  
Old 03-22-2016, 08:04 AM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

<a href="https://vborg.vbsupport.ru/showthread.php?t=304190" target="_blank">https://vborg.vbsupport.ru/showthread.php?t=304190</a>
Reply With Quote
  #16  
Old 03-22-2016, 08:11 AM
Dave Dave is offline
 
Join Date: May 2010
Posts: 2,583
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Could be adware on your computer but it can also be a malicious plugin that's installed on your forum. It's hard to say since we don't have access to your server.
Reply With Quote
  #17  
Old 03-22-2016, 08:11 AM
Gio~Logist's Avatar
Gio~Logist Gio~Logist is offline
 
Join Date: Jun 2004
Location: San Francisco
Posts: 2,575
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Have you taken a look at the original headers for the emails? Like others have said, it isn't necessarily a vB issue if spam emails are being sent out. This could be a NUMBER of things. It can even just be email spoofing.
Reply With Quote
  #18  
Old 03-29-2016, 02:45 PM
Scalemotorcars's Avatar
Scalemotorcars Scalemotorcars is offline
 
Join Date: Mar 2006
Location: NC
Posts: 619
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Ok so I implemented some country wide htaccess IP blocks (see attached files for a text copy) and I'm still getting spam in the Bounced Inbox. I would think the IP blocks would keep anyone in those countries from useing a file on my server but I have no ideal if it would block SQL injections. I still haven't figured out how to check the DB for malicious injected code.

Anyway back to the email headers and the originating IP addresses. From what I can see the bulk is coming from 4 countries with the most coming from Viet Nam, then India, Indonesia and finally Kuwait. The ip's for the most part keep changing.

Here's a few that are sending out the most speam.

Quote:
118.69.31.201 Viet Nam
103.210.48.155 India
117.253.185.12 India
37.38.205.61 Kuwait
42.116.211.84 Viet Nam
36.84.226.31 Indonesia
Below are the 2 txt files of just the Deny From for the HTaccess. (having all in one file was to big to upload to VB.org)

To me is seems like a massive amount of ip's to check before a page loads and I'm concerned it will cause load issues and delays. Can someone take a look at it and tell me if the size is ok on what once was a busy board before all this happened.
Attached Files
File Type: txt country-ip-block.txt (596.1 KB, 1 views)
File Type: txt country-ip-block-2.txt (746.8 KB, 1 views)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 05:25 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04283 seconds
  • Memory Usage 2,254KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (8)post_thanks_box
  • (1)post_thanks_box_bit
  • (8)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (8)post_thanks_postbit_info
  • (8)postbit
  • (2)postbit_attachment
  • (8)postbit_onlinestatus
  • (8)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • postbit_attachment
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete