The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Forum hacked, restored, now showing bare index
Probably 10th time in 4 years, my forum has been hacked. This time Turkish hackers inserted "class.php" into the /includes directory, my provider (Webhostinghub) is adamant they came through some VB backdoor, which I doubt.
VB 4.2.3 all vanilla, no Mods. Passwords for site and ftp different, 30-40 characters, free form text with blanks, uppercase, numbers. Wiped the site out and restored from last good known backup. All VB files are in ./public_html/forums, as in picture 1 Now it is showing bare index, as in picture 2. When going into "forum", it does show the site is down and under maintenance. But if anyone clicks on the pictures, it is free to look at them with no login. (I have moved pictures to another directory since until this is resolved but picture 4 shows how it was). Why is it going now into bare index not into the full site? |
#2
|
||||
|
||||
Did you look under diagnostics to see what files are left and check your plug ins as well..
--------------- Added [DATE]1441693369[/DATE] at [TIME]1441693369[/TIME] --------------- If you were hacked many times then chances are they did leave a "door" on your site which was never patched. |
#3
|
|||
|
|||
I wiped out the site, removed directories and created them afresh this morning.
Maintenance - diagnostics shows nothing strange. The site is vanilla, no plugins, nothing that did not come with VB. Hacking my site is rather like farming web services users hosted by that provider, using them as bots. Wells Fargo sent me once to stop spamming from my site. Only 2 out of 10 times they shut down the site with some message. |
#4
|
||||
|
||||
Sounds like you have a ton of stuff on there still Go under maintenance and run the diagnostics. Check your plug ins as well.
I really do not know what you mean by you wiped everything out. you reinstalled Vbulletin fresh or just uploaded clean files? In that case you did not overwrite the hacked files which may not only have been Vbulletin. There are many things you need to do even after you clean this to make sure it is secure but it looks like you have a long ways to go. |
#5
|
|||
|
|||
This is what it was:
.htaccess file was not in the root directory. After blasting the entire installation, it of course, did not come there from VB install. Dragged it from backup and all fine. That file contains redirection to the home page, without it it defaults to bare index. |
#6
|
||||
|
||||
Ok good. You installed a fresh copy of Vbulletin? I am a little confused but glad it is working anyways.
|
#7
|
|||
|
|||
Honestly, I don't know what is different this time. If the hacker who broke in yesterday is pleased to do again today, the same hole would be ready for him.
Whether they come through cPanel, site itself or through VB, nothing has changed, even if VB is fresh install. The hosting site said it was not through ftp. They also said password was not used to get in, how they know, through their logs probably. |
#8
|
||||
|
||||
Are you on shared hosting? That is the most common way that hackers get in and it IS the hosts fault in most cases NOT vBulletin if its a fresh install with no mods added on. Shared hosting is famous for not being very secure. I suggest if you are that you either change hosts or get a VPS instead where you can control the security.
|
#9
|
|||
|
|||
Yes, possible.
Yes again, shared hosting, it may well be their problem. As I said, seems the hackers waltz in and farm the users and their sites without apparent problem with their sites. They (webhostinghub.com) applied some measures that alert me when (some, what their poor security can detect) it happens. They quarantine the malicious code but still - it comes through their lack of security. Issues like this have a potential to drive a hosting company out of business. If any, the luck is my site is not commercial, no money loss. But hours lost to restore by me for someone who had ruined my site for fun. When I asked webhostinghub.com why don't they introduce 2 level login (with RSA dongle) they said it could fix cPanel only but not "3rd Party software", possibly implying VBulletin to be at fault. They confirmed nobody had compromised my passwords and logged in. I still believe it is cPanel, an independent vendor, who is at fault. No offers for help (paid) from this site would fix it. It is not VB, I think. |
#10
|
||||
|
||||
Well it could be hosting but my guess is that it is something you have missed.
Did you delete all the files on your server and reinstall fresh? Did you run the diagnostics to look for third party files? Have you been with this same host all the other times you were hacked? |
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|