The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
![]()
I was reading in the morning that someone was hacked and I thought: I'm gonna find the time to write a good 'Guide for the Hacked' for users not to get hysterical about the problem and ZAZ! my site was hacked :P but I don't get all scare, good thing that I know by memory the structure of my server/files... but must be interesting analyze/dissect the attacks for future references...
I don't know if it's improper to post this, please advise me if so... but here the main file who steals you cP's Password: CONFIGSCAN.PHP *** Script removed, no need to post a script to hack a site *** p.s. I fixed very calmly my problem ![]() |
#2
|
||||
|
||||
![]()
wouldn't they still need a way to get that file on your server?
|
#3
|
||||
|
||||
![]()
This was gonna be my question. That is what I would be freaking out over!
|
#4
|
||||
|
||||
![]()
In fact I said: I always take it with calm... not that I'm a expert
![]() I just check head-over-heels, and although I said to my Hosting Service that might my a Shell thing they say is script-related thing... so I don't discuss and go to the logs and clean everything and change passwords... It came with many 'strange foreign files' Any idea what that script compromise? p.s. I consider a tootache more important that a vBulletin's board hacked --------------- Added [DATE]1221886742[/DATE] at [TIME]1221886742[/TIME] --------------- and everything start here: Quote:
![]() |
#5
|
||||
|
||||
![]() Quote:
![]() |
#6
|
||||
|
||||
![]()
'Naija Bois Too Much '
![]() Info in the files, I called my Nigerian friend OSUJI, and he told me is a bragging gang term... |
#7
|
||||
|
||||
![]()
To avoid that this file finds out your password,change the config.php file so that it is not a one-liner,but more lines.Especially the password parts.
|
#8
|
||||
|
||||
![]()
The only thing I regret is to lose my SuperSecure password: it was a word I created with Latin & Greek roots, combined with numbers and must be entered sitting over your head singing Jingle bells in Zulu
![]() The only FTP connection I see is on 9/14/2008 Quote:
![]() |
#9
|
||||
|
||||
![]()
i remember reading something on how to protect the config.php there's info here to protect your file using htaccess http://www.sitebuddy.com/php/VBullet...with_.htaccess hope that help
![]() |
#10
|
||||
|
||||
![]()
Or CHMOD it to 600
![]() ![]() |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|