Go Back   vb.org Archive > Community Discussions > Forum and Server Management

Reply
 
Thread Tools Display Modes
  #1  
Old 06-15-2008, 12:41 PM
danielc2384 danielc2384 is offline
 
Join Date: Jan 2008
Posts: 117
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Site Hacked

I logged onto my forum a few minutes ago www.dollhousetvforum.com and it looks like I was hacked. A pop up box appears saying "you niggers got ******".
I'm really not sure what has happened or what to do.

I contacted my host and they basically offered no help.

What should I do?

Thanks
Reply With Quote
  #2  
Old 06-15-2008, 12:43 PM
Baldilocks's Avatar
Baldilocks Baldilocks is offline
 
Join Date: Jan 2008
Location: Delaware, USA
Posts: 297
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Did you try re-uploading your index.php file?
Reply With Quote
  #3  
Old 06-15-2008, 01:29 PM
danielc2384 danielc2384 is offline
 
Join Date: Jan 2008
Posts: 117
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yep. No luck.
Reply With Quote
  #4  
Old 06-15-2008, 01:47 PM
SEOvB's Avatar
SEOvB SEOvB is offline
 
Join Date: May 2007
Location: Indianapolis
Posts: 2,451
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

remove any .htaccess file and make sure you dont have any extra plugins that shouldn't be at global start
Reply With Quote
  #5  
Old 06-15-2008, 01:47 PM
MTA-RP MTA-RP is offline
 
Join Date: Feb 2008
Location: 121.0.0.1
Posts: 1
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Edit the .httaccess or w/e it's called.
Reply With Quote
  #6  
Old 06-15-2008, 01:52 PM
danielc2384 danielc2384 is offline
 
Join Date: Jan 2008
Posts: 117
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I removed the .htaccess file from /public_html/
Still no luck.

My forum is stored in /public_html/dollhousetvforum/ and there is no .htaccess file in there.
Reply With Quote
  #7  
Old 06-15-2008, 02:04 PM
ssslippy ssslippy is offline
 
Join Date: Jan 2006
Posts: 877
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I recomend you reupload all your files, and check for mods with security issues. Make sure you are also running the latest vb.

You can put a password require inside php files.
Reply With Quote
  #8  
Old 06-15-2008, 02:09 PM
danielc2384 danielc2384 is offline
 
Join Date: Jan 2008
Posts: 117
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ssslippy View Post
I recomend you reupload all your files, and check for mods with security issues. Make sure you are also running the latest vb.

You can put a password require inside php files.
In the process of upgrading from 3.7.0 to 3.7.1 now.
*crosses fingers*

How could they set up this password require without ftp access?

If they have the ftp info wouldn't they have changed the passwords and done more damage?
Reply With Quote
  #9  
Old 06-15-2008, 02:12 PM
ssslippy ssslippy is offline
 
Join Date: Jan 2006
Posts: 877
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

They dont always change the passwords. They could of also done a file insert cause you have HTML enabled somewhere on your forums. Lots of things can be done.

You should change your passwords.

Also what mods are you running?
Reply With Quote
  #10  
Old 06-15-2008, 02:16 PM
danielc2384 danielc2384 is offline
 
Join Date: Jan 2008
Posts: 117
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ssslippy View Post
They dont always change the passwords. They could of also done a file insert cause you have HTML enabled somewhere on your forums. Lots of things can be done.

You should change your passwords.

Also what mods are you running?
Thanks for the info.

Passwords have all been changed.



-------------------


Here is a list of the mods:

Admin Log In As User 3.0 This hack will allow admins to log in as any user.

Automatic Welcome PM 1.0.4 This Hack will automatically send welcome PMs to new members.

Bills PayPal Donate 1.32.366 Bills PayPal Donate

BuRaCH G?lgeli Kullan?c? Ba?l?g? 3.6.x.1.0.0 Sitenizdeki Kullan?c? isimlerini g?lgeli yapar.

Cyb - Advanced 'New Posts' 2.1 Cyb - Advanced 'New Posts'

Cyb - Auto Birthday Greeter 1.3 Cyb - Auto Birthday Greeter

Cyb - ChatBox 1.9.9 Cyb - ChatBox

Cyb - Sub-Forum Manager 2.5 Cyb - Sub-Forum Manager

EzIRC 1.0.3 IRC Chat Addon for vBulletin

Fake Users 1.0.0 Fake Users

Flashchat Integration 3.55 Integration of Flashchat and vBulletin 3.6

Form Hack 4.0 Create a form.

FractalizeR: Registration Form AJAX Enchancements 1.0 Enchances registration form with AJAX

HelpCenter 1.00 RC 1 A Support Ticket System!

Image Resizer 1.0.2 Automatically resizes images in posts!

Inferno vBShout Lite 2.5.0 Real time shoutbox

JustJoin 1.0.0 Just join us

KC - Announcement 1.0.0 Announcements by Kiril Cvetkov

Limited Guest Viewing 1.0.6 Limit guests to view a set number of threads before being locked out.

Members who have Visited 3.7.003 Display members who have visited the forum.

passiveVid 1.1.2 Automaticlly turns video links like youtube, myspace videos, google vidoes into the video players.

PhotoPlog 2.0.7 PhotoPlog: The Lite Gallery

Post Thank You Hack 7.4 Post Thank You Hack

Quick Reply Add On. 3.6.x Add On Editor Tools for Quickreply.

Site Life Status 1.0.4 This will tell you how long your site has been up and running.

Time Greeting 0.06 Changes "Welcome" to "Good Morning/Afternoon/Evening" in the navbar

UA sidebar 3.0.7

Usergroup Color Bar 1.0.0

v3 Arcade 1.0.7 A multiplayer gaming system for your vBulletin forum.

vB News Ticker 1.2 Latest News in a Ticker

vBExperience 3.7.12 Calculate activity of your users

vBExperience Level 2.0 vBExperience Level

Video Gallery 3.0B A video gallery hack that uses Video Sharing sites for hosting.

Yet Another Award System 3.6 2.1.4 Admin can give members awards, and award

ZH - No Avatar 1.0.0 If a member doesn't have an avatar a no avatar image appears

Zoints Profile System 2.1.4 The Zoints client forum profile linking system.

[Sniper] - Mood Manager 1.2.5 Allows users to manage there mood

--------------- Added [DATE]1213544292[/DATE] at [TIME]1213544292[/TIME] ---------------

I am currently updating to 3.7.1 and while uploading files I returned to the index page and the popup authorization box seems to have gone. The IP displayed on the popup authorization was 67.228.190.70

Instead of the page saying "done" when finished loading on the bottom left hand side of the browser, it says "connecting to 67.228.190.70".

hmmm
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 07:21 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04973 seconds
  • Memory Usage 2,248KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete