The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Has you site been hacked (please read)
Hi there
I now have found how they was hacking my site. They had uploaded 2 php files to my site and hide them in the archive folder. The files are called ang.php and r57.php i will not post the files on any site as they could be used again. I have e-mailed the hacker to ask him if he will tell me how he uploaded the files in the first place. I can tell you he is only 16 and still at school. So please everyone look out for these files and delete then if you see them. The only files that should be in your archive folder should be archive.php index.php global.php if you see any other files in there delete them. |
#2
|
||||
|
||||
Thanks for the heads up! I ahve that happen from time to time, they try to upload shell scripts.
May sure your archive folder is not chmod 777, I changed all of mine back to default and have to monitor the ones that are. Again, thanks for the lookout, hope you get your site! -Jason |
#3
|
||||
|
||||
It could be one of many things. What OS is your server running on? What services does it have running (MySQL, MSSQL, Dameware, Radmin, VNC etc)?
|
#4
|
||||
|
||||
r57.php is a remote shell used by hackers to control your root alot easier than brute forcing your ftp its not anything to do with vbulletin its seems some how they uploaded it either through a mod/hack your using not to sure
|
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|