The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
|
#1
|
|||
|
|||
![]() Quote:
Code:
102106 N/A 18:13, 30th Aug 2013 user.php kill user id = 333162 198.203.28.247 102105 N/A 18:13, 30th Aug 2013 user.php remove user id = 333162 198.203.28.247 102104 N/A 18:13, 30th Aug 2013 user.php edit user id = 333162 198.203.28.247 102103 N/A 18:13, 30th Aug 2013 user.php find 198.203.28.247 102102 N/A 18:13, 30th Aug 2013 user.php modify 198.203.28.247 102101 N/A 18:13, 30th Aug 2013 plugin.php 198.203.28.247 102100 N/A 18:13, 30th Aug 2013 plugin.php kill plugin id = 8305 198.203.28.247 102099 N/A 18:13, 30th Aug 2013 plugin.php delete plugin id = 8305 198.203.28.247 102098 N/A 18:13, 30th Aug 2013 plugin.php modify 198.203.28.247 102097 N/A 18:05, 30th Aug 2013 plugin.php 198.203.28.247 102096 N/A 18:05, 30th Aug 2013 plugin.php doimport 198.203.28.247 102095 N/A 18:04, 30th Aug 2013 plugin.php files 198.203.28.247 When i saw this i deleted the install folder as advised and restored my database to the 29th of august as this had been done on the 30th i figured that it would undo any database or template alterations, Wrong, the next day the same user was back with admin access, i removed him again, and checked the admin logs and nothing had been done so i left it at that and just observed the site, the next day my templates had all been reverted to the originals so someone had access the admin cp again...... so then i figured it must be a file uploaded on the server because from what i've seen of the plugin being used gives them the ability to upload files to the server, so then i checked the file dates and found a suspicious "clock.php" file in the custom avatars folder that had been created the same day as the plugin above was installed so i removed that and restored another database backup from the 24th which is the day before the guy registered an account on my forums I've changed admin, cpanel, & ftp passwords so i'll see where it goes from here, just removing the install folder is not enough, here's an example of a file someone has uploaded as a backdoor back in to a forum http://www.paccin.org/deface.txt i guess their must be more files as well but this i all is could find on google |
![]() |
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|