The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#11
|
|||
|
|||
If reinstalling the default style using tools.php solves your problem, then this indicates that 1 of the following is happening:
- The hacker is able to change your MASTER_STYLE. This style is only accessible when the board is in debug-mode. Unless you are running in debug-mode, this can only be changed by a direct edit in the database. - The precompiled cached version of your templates is edited. Again this can only be done by direct editing of the database. The problem gets "solved" when the cache is rebuild (like is done when using tools.php). Both of these scenario's require that the hacker has direct access to your database, so i would start by focussing on how he gained access to your database and close this gap. You might want to contact your host about this. |
#12
|
|||
|
|||
Quote:
Is it possible they found an exploit in a plugin or something that allowed them to place this file on the server and then manage to hack the config.php file, all without having to actually hack the server? |
#13
|
|||
|
|||
If they can place a PHP file on your server and execute it, then it is not problem to get the contents of your config.php.
I don't know how they placed that file on your server, i doubt it was done thru standard vBulletin. More likely: FTP Access/Server Control Panel, vulnerable modification,... |
#14
|
||||
|
||||
Or maybe a disgruntled ex-Staff member with access to the server?
|
#15
|
|||
|
|||
We're still being hacked. We've changed the password to our server and we've upgraded our forum to the latest version and still these Saudi Arabian hackers keep hacking the forum. Earlier, in the week they were even hacking my account and taking over and now they are back at overwriting the forum skin again. I keep going in an deleting the files they place on the server that allows them to overwrite the forum and now im completely out of ideas on how to secure the forum.
|
#16
|
||||
|
||||
If they can place files on the server, then it (most likely) indicates a problem on the server level (eg. FTP or SSH). It could also be caused by another script.
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|