The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
My Forum Has Been Hacked-PLEASE HELP!
Okay I'm new to vB and I'm still getting to know the ins and outs of it and I really hate asking for help without first trying to fix any problems I have, but I can not fix this problem and I know it has got to be a minor hack, but I just can't figure out where to look.
Today I logged into my forum and noticed on a few of the pages where the names of the threads are listed there are 3 small links that say "watch movies-buy movies-movies download". they are in the middle of the thread, between the thread name and the last post (see attachments below). Now I have tried to look for the links in 'edit templates' but had no luck. Maybe someone on here can direct me in the right place to search? The links appear to be on the page because when I scroll they move upward with the threads. I also just checked my cPanel and in my forum directory there are a bunch of pages with names like "0a332aaf80d731a786131f1712d05670" but no info on the page when I open it up to view it...only "0.6" or "9"....any idea what these are? I don't remember them being there before....are they some sort of log? Anyway, if you have an idea of what file(s) I should edit please let me know...this is aggravating as all hell!! |
#2
|
||||
|
||||
Can you post the link to your forum? Those weired files, do they have any codes in them?
|
#3
|
||||
|
||||
Quote:
here's the link to one of the forum pages with the "watch movies" links... http://www.illadelstylez.com/forum/f...ketches-Canvas |
#4
|
|||
|
|||
I can't give much help with the inner workings of vBulletin, but yes, delete them files now.
--------------- Added [DATE]1289336423[/DATE] at [TIME]1289336423[/TIME] --------------- Nice forum by the way. |
#5
|
||||
|
||||
Quote:
--------------- Added 09 Nov 2010 at 16:52 --------------- Now I deleted all the weird files that I know for sure didn't belong in the directory but after I deleted them all (around 100+) a couple at a time keep popping up...the files are named "1b7fdbbea3567de746321d9915b3502c" and all have different numbers & letters...I'll delete those, refresh the directory then there's 2-3 new ones...WTF!!! Can anyone give me a name of an add-on or contribution that can scan the files? Something like "KISS File Safe" for OsCommerce....only for vBulletin...and is there any must-have security addons I should install? please help! |
#6
|
|||
|
|||
Hey, i am wondering why can anyone other than you ( root ) write
in your webserver directories ? Are they read only ? |
#7
|
||||
|
||||
Those files are something to do with it, as TheRage says, check the write permissions in your directory and change your root password asap, also for any FTP accounts you may have set up.
There have been additions made to FORUMHOME forumdisplay and threaddisplay templates. This code Code:
<!--343a46459562b88e7bf7d0a890b75727--><div style="position:absolute; left:324px; top: -100px;"><a href="http://www.extafilm.com/">watch movies</a>. <a href="http://www.moviethone.com/">movies download</a>. <a href="http://www.qubmovies.com/">buy movies</a></div><!--/343a46459562b88e7bf7d0a890b75727--> You need to run VB Diagnostics/Suspect File Versions and check all non VB files, most addon/hack files will have recognizable names and alien files can be spotted fairly easily in the report. I would also suggest you get your host to run a scan in your partition and make sure it's clean. |
#8
|
||||
|
||||
Quote:
|
#9
|
|||
|
|||
https://vborg.vbsupport.ru/showthread.php?t=203933
install instructions Download: http://www.vbulletin-germany.org/showthread.php?t=5467 this is a very handy plugin which will assist you with searching for this and where/what plug-in it may be coming from |
#10
|
|||
|
|||
Probably these links are generated in php files of vBulletin. There is an option in vBulletin that recognizes external files:
Admincp -> Manteinance -> Check Version File (3rd option). The files of plugins and other programs will appear. I'm sure that your vBulletin files (php files) has been modified and are linked with the strange "145384asdada5d6s54d6a5sd4a6sd" files. If I were you I will download the vBulletin package again and reupload all the files. If you get the same after this step, it means that your sql data base has been touched. Good luck. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|