The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
I'm having a very tough time figuring out exactly whether or not my instance of vBulletin has somehow been compromised or hacked (v3.6.8). Several (more than a few) of my members have alerted me that they are getting redirected to a dead website when visiting our forums with IE7. A few have indicated it happening on other vBulletin sites, but it does not happen anywhere else (non-vBulletin browsing).
The site they are being redirected to is www DOT quiettorture DOT com which appears to be dead. It also seems to be the site of a runescape clan according to a YouTube video. If you Google it, please watch out for unsavory sites. Here is what I can dig up so far: Feedback from the thread on our site: http://forums.audioholics.com/forums...ad.php?t=41997 Another Italian thread that encountered it... ...and so did this site: http://www.e-budo.com/forum/showthread.php?p=460906 I'd love any feedback the community might have... |
#2
|
||||
|
||||
![]()
check your templates for redirects
|
#3
|
|||
|
|||
![]()
Hi, some users of my forum also talks the same. Curiously i don´t see this. I have vb 3.6.8 Patch 1, and also i have read the same of Hawke.
¿Anybody have this issue? Thanks in advance |
#4
|
||||
|
||||
![]()
Did you read FRDS's post?
|
#5
|
|||
|
|||
![]()
Yes dismounted i did read it. The template that i have used for more than four months and this issue happens since three days.
Thanks in advance |
#6
|
||||
|
||||
![]()
Yes, but if the hacker put arbitrary code into your templates, you wouldn't know but it'd still be there.
|
#7
|
|||
|
|||
![]()
Ok, i was search in the template for quiettorture, torture, quiet and only obtain this:
newreply_reviewbit_ignore_global <phrase 1="$post[username]">$vbphrase[administrator_decided_x_quiet]</phrase> and Quote:
Quote:
Thanks in advance.. ! |
#8
|
||||
|
||||
![]()
Look at your plugin list, is there anything unusual there? Also, look in your .htaccess file.
|
#9
|
|||
|
|||
![]()
Thanks for your interest dismounted, i?m going to check my plugins, and my .htaccess it?s correct.
Thanks again, but it?s possible that the problem it?s a new spyware, more info at: www.forospyware.com%2Ft135658.html%23post654024 |
#10
|
|||
|
|||
![]()
Check your actual index.php files and home.php files. If somebody gets your FTP password they can upload new php with redirects in them. They are relatively easy to clean up. This happened to my site a while back when my server company was compromised.
|
![]() |
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|