The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
forum hacked
a few hours ago, when login to our vbulletin forum, i get a blank page with message "hacked by Xplo1T www.prvtzone.net www.belegit.net "
I already checked all php & js files, but none has been changed today, no htaccess files have been changed neither, so i'm guessing it has been done with a kind of redirect parameter in the database - anybody has an idea how i can fix this ? where in the database i should look for a parameter causing a redirect ? |
#2
|
|||
|
|||
I would NOT click either of those links!
I don't know anything about hacking and recovering from being hacked but just out of curiosity what does the location field say at the top of your page? Have you tried going to another forum page, such as online.php? Can you get into your adminCP? My advice: submit a support ticket to vBulletin. |
#3
|
||||
|
||||
Your Server Apache or LiteSpeed ?
|
#4
|
||||
|
||||
nevermind..
|
#5
|
|||
|
|||
thanks for the replies guys, it seems the hacker gained access through a vulnerability in the search.php page and via admincp he began changing admin pwd's & email adresses. The reason why index & forum.php were showing the hackers message was because he altered the template forumhome and replaced it with his html page.
Fortunately, vbulletin has a wonderful functionality of reversing templates so that fixed the problem. this topic can be closed |
#6
|
|||
|
|||
Quote:
|
#7
|
||||
|
||||
Quote:
|
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|