The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Was this someone trying to hack?
I received two database error e-mails and both of them have the same content - I changed the text to red for the part I'm worried about. It looks like they were trying to inject base64 code inbetween the IMG tags.
I also noticed that the IP address does not match the IP address in the profile for HotRoddCamaro. I did a search of users by IP address with a depth of 2 and it didn't find any matches. I did notice the IP address is local and isn't a chinese address. Was this someone doing something suspicious as it looks? Base64 in an img code? Just wondering if I should be doing an IP block. Quote:
|
#2
|
|||
|
|||
<a href="https://www.vbulletin.com/docs/html/troubleshoot_mysql_goneaway" target="_blank">https://www.vbulletin.com/docs/html/...mysql_goneaway</a>
|
#3
|
|||
|
|||
Thanks, but it's not the fact that MySQL "went away" - it's that they put almost 1.5mb worth of text in the tags in what *looks* like some sort of injection attack with base64 code inbetween the IMG tags. The fact that there was so much code in there is why the server timed out, I understand that.
|
#4
|
|||
|
|||
It's possible I suppose. But it kind of looks like inline image data, although to be honest I don't know how you'd do that (or even if you're supposed to be able to do it in vbulletin). But since it looks like it's the post contents, I don't see how it could be used as an attack any more than anything else you could include in a post.
|
#5
|
|||
|
|||
That normally happens when one of your members are trying to upload an infected image, most of the time they dont even know its infected .
One thing i normally do to stop this is adding "base64" to the censorship options which seems to stop it from being posted. You can also reduce the maximum characters for posts because these strings are often pretty long. |
#6
|
|||
|
|||
Thanks for the idea, Adam. Do you also think it's weird that the IP address does not match the known IP addresses for the username?
I'll add base64 to the censorship option though, I think that's a great idea. |
#7
|
|||
|
|||
Are you looking at the last known IP address on their profile or searching for all IP's used by that user ?
Also if you are using a reverse proxy make sure that IP address isnt your server IP, Although from what i can see the IP in that DB error from from Michigan |
#8
|
|||
|
|||
I tried both last known IP address and also searching for all IPs used by any user and it didn't find any matches. I agree with what you found - it's coming from Flushing, MI which would make sense since the site is Michigan-centric. Just don't know if it was a script kiddie trying something or what.
|
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|