Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
  #1  
Old 01-13-2014, 04:24 PM
Rizzler Rizzler is offline
 
Join Date: Jun 2011
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Forum hack please help

Hello

I had my forum hacked today and the frontpage defaced. Any file i try to go to gives me the hackers message on the front i removed every file on the server and reuploaded them, set the config.php with the database information and also added define('DISABLE_HOOKS', true); into the PHP, now after i did this there was no change, the hackers message is still in the database wich makes me guess that he maybe changed FORUMHOME as suggested when i tried searching google for answers, i can access the database from Phpmyadmin BUT i cannot access the forum adminCP i can access the login windows but when i press "login" it redirects me to login.php wich gives me the hackers message again, what do i do from php my admin to get my forums back online ?
Reply With Quote
  #2  
Old 01-13-2014, 04:40 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Link to the site?

If the INSTALL folder still exists on your server, delete it.
Reply With Quote
  #3  
Old 01-13-2014, 04:49 PM
Rizzler Rizzler is offline
 
Join Date: Jun 2011
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The site is over at welikeanime.com and i can go to admincp/ but i cannot login. The installfolder is deleted from the root folder since the install.
Reply With Quote
  #4  
Old 01-13-2014, 04:56 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I get nothing but a blank page, there's no code in reading page source.
Reply With Quote
  #5  
Old 01-13-2014, 05:16 PM
Rizzler Rizzler is offline
 
Join Date: Jun 2011
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

my stupid host removed the default style in the "style" table in the database when scaning, i tried to restore it it but now i just get blank pages. i have a test forum with another license that also was defaced and the code bellow is on all pages i try to access like login.php index.php or simillair. It was on the frontpage where you also get a white page now but after the problems in the "style" table the page is just white, anything you can figure out?

it's for most .php files in root like if i go to mysite.com/login.php or index.php instead i get the hackers message


Malware:

Code:
<html>

<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<title>HACKED BY Mr.M0R0 MOROCCAN HACKER</title>
</head>

<body>

<p align="center"><img border="0" src="http://stupidwebsite.com/46/95/864954/65130309_p.gif"></p>

<p align="center">&nbsp;HACKED AND DEFACED BY Mr.MORO MOROCCAN HACKER</p>

<p align="center">&nbsp;WHAT THE HELL IS GOING ON HERE YOUR SECURITY IS LIKE A SHIT</p>

<p align="center">&nbsp;++++ING UNSECURE SERVERS I REALLY HATE IT. NO APOLOQIZE , NO MERCY</p>

<p align="center">&nbsp;NO PITTY , NO SORRY , BUT DO NOT WORRY NO FILES DELETED ONLY YOUR INDEX</p>

<p align="center">&nbsp;HAS BEEN CHENGED SO TRY TO EDIT QUICKLY GOOD LUCK . FOR MORE INFO CONTACT ME ON :</p>

<p align="center">&nbsp;Mr.MoRo@HOTMAIL.FR</p>

<p align="center">&nbsp; BYE</p>

</body>  

  

</p>

</html>
Reply With Quote
  #6  
Old 01-13-2014, 05:20 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

That's coming from a file on the server, not the database.

PM me with FTP credentials and i will have a look.
Reply With Quote
  #7  
Old 01-13-2014, 08:38 PM
TheLastSuperman's Avatar
TheLastSuperman TheLastSuperman is offline
Senior Member
 
Join Date: Sep 2008
Location: North Carolina
Posts: 5,844
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It's more than likely this one: http://www.vbulletin.com/forum/forum...=1387659347561

See post #13

.. If not then it's the other variant where the hacker edits your master style replacing all templates with the same identical code which is rather bothersome as you can imagine .
Reply With Quote
  #8  
Old 01-14-2014, 10:50 AM
Rizzler Rizzler is offline
 
Join Date: Jun 2011
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I would like to thank Max Taxable for helping me with this issue, thank you very very much!
Reply With Quote
Благодарность от:
TheLastSuperman
  #9  
Old 01-14-2014, 11:12 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Rizzler View Post
I would like to thank Max Taxable for helping me with this issue, thank you very very much!
I did some PM networking and little else. The party responsible for the actual help is a really good egg.
Reply With Quote
2 благодарности(ей) от:
RSNF, TheLastSuperman
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:59 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06481 seconds
  • Memory Usage 2,244KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_code
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (9)post_thanks_box
  • (3)post_thanks_box_bit
  • (9)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (2)post_thanks_postbit
  • (9)post_thanks_postbit_info
  • (9)postbit
  • (9)postbit_onlinestatus
  • (9)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete