Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
  #1  
Old 09-17-2013, 02:18 PM
Steve-Hoog Steve-Hoog is offline
 
Join Date: Sep 2010
Posts: 33
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Forum Destroyed By Hacker

In the last week we were still on 4.1.x and a hacker demolished our vB software; however, he did not touch the Database. Thank God

This hacker was:
Quote:
Greeting From BangoBnG
this website has been Hacked have fun,
Egypt - t.w.e@msn.com
-SeiF 2007-2013
Quote:
Age:16
Name:SeifAhmed
Country:Egypt
What is your experience with botnets:I am Trying To MAke DDos form BOts
What bots have you used before:vertexnet,zuse,Obtima
How often are you active:I am online evry day for 16 Hours
Are you willing to learn:yes
Do you have a little money to use:no :'(
All of your contact:
My Skype: Seifskp
Now we are on 4.2.1 and today someone was trying to get us but we caught them in time:

Quote:
ppp ppp@gmail.com 09-17-2013 09-17-2013 0
I have done a great deal of reading here and IMO opinion too much effort is being put into identify that you have been hacked and how to try to fix it; should we just eliminate their ability to get in our systems, and shouldn't this be the job of vB? Not the customers; and not the customers paying third parties? This is very depressing to say the least.
Reply With Quote
  #2  
Old 09-17-2013, 02:19 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I've been a vB licensee since 2005, never been hacked or defaced. Of course, I adroitly avoided getting vB4. Might have alot to do with it.
Reply With Quote
  #3  
Old 09-17-2013, 02:23 PM
obglobal.net obglobal.net is offline
 
Join Date: Jan 2013
Posts: 203
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Steve-Hoog View Post
shouldn't this be the job of vB? Not the customers; and not the customers paying third parties? This is very depressing to say the least.
Exactly! I've payed vBulletin for an insecure forum that's now down for the second time in 2 weeks because of a hacker. F'ing scumbag.

WHy are they selling me on a software they can't protect?

--------------- Added [DATE]1379431576[/DATE] at [TIME]1379431576[/TIME] ---------------

And it looks like they've gotten in to my cPanel, as well.
Reply With Quote
  #4  
Old 09-17-2013, 05:34 PM
Steve-Hoog Steve-Hoog is offline
 
Join Date: Sep 2010
Posts: 33
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Log of what my hacker friend did if this helps anyone else.

Quote:
119416 N/A 22:20, 12th Sep 2013 plugin.php 41.47.48.122
119415 N/A 22:20, 12th Sep 2013 plugin.php update 41.47.48.122
119414 N/A 22:20, 12th Sep 2013 plugin.php add 41.47.48.122
119413 N/A 22:20, 12th Sep 2013 plugin.php modify 41.47.48.122
119412 N/A 22:20, 12th Sep 2013 plugin.php product 41.47.48.122
--------------- Added [DATE]1379443378[/DATE] at [TIME]1379443378[/TIME] ---------------

I have only these three Plugins, can anyone advise if either is a risk?

Quote:
VSa - Advanced Forum Statistics 7.1 VSa - Advanced Forum Statistics
Edit Check Version Disable Export Uninstall

VSa - ChatBox 3.1.8 VSa - ChatBox
Edit Check Version Disable Export Uninstall

VSa - Visitors in Last X Hours 3.0.4 VSa - Visitors in Last X Hours
--------------- Added [DATE]1379508741[/DATE] at [TIME]1379508741[/TIME] ---------------

Has anyone turned off Registration and still been exploited?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:10 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.07407 seconds
  • Memory Usage 2,185KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (6)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (4)post_thanks_box
  • (4)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (4)post_thanks_postbit_info
  • (4)postbit
  • (4)postbit_onlinestatus
  • (4)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete