Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 03-07-2008, 05:47 PM
HawKe HawKe is offline
 
Join Date: May 2004
Location: South Carolina, USA
Posts: 14
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default vBulleting hacked by Quiettorture?

I'm having a very tough time figuring out exactly whether or not my instance of vBulletin has somehow been compromised or hacked (v3.6.8). Several (more than a few) of my members have alerted me that they are getting redirected to a dead website when visiting our forums with IE7. A few have indicated it happening on other vBulletin sites, but it does not happen anywhere else (non-vBulletin browsing).

The site they are being redirected to is www DOT quiettorture DOT com which appears to be dead. It also seems to be the site of a runescape clan according to a YouTube video.

If you Google it, please watch out for unsavory sites.

Here is what I can dig up so far:

Feedback from the thread on our site: http://forums.audioholics.com/forums...ad.php?t=41997

Another Italian thread that encountered it...

...and so did this site: http://www.e-budo.com/forum/showthread.php?p=460906

I'd love any feedback the community might have...
Reply With Quote
  #2  
Old 03-07-2008, 07:22 PM
SEOvB's Avatar
SEOvB SEOvB is offline
 
Join Date: May 2007
Location: Indianapolis
Posts: 2,451
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

check your templates for redirects
Reply With Quote
  #3  
Old 03-08-2008, 09:39 PM
fmntprsv fmntprsv is offline
 
Join Date: Sep 2007
Posts: 30
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hi, some users of my forum also talks the same. Curiously i don´t see this. I have vb 3.6.8 Patch 1, and also i have read the same of Hawke.

¿Anybody have this issue? Thanks in advance
Reply With Quote
  #4  
Old 03-09-2008, 03:05 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Did you read FRDS's post?
Reply With Quote
  #5  
Old 03-09-2008, 08:32 AM
fmntprsv fmntprsv is offline
 
Join Date: Sep 2007
Posts: 30
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yes dismounted i did read it. The template that i have used for more than four months and this issue happens since three days.

Thanks in advance
Reply With Quote
  #6  
Old 03-09-2008, 10:26 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yes, but if the hacker put arbitrary code into your templates, you wouldn't know but it'd still be there.
Reply With Quote
  #7  
Old 03-09-2008, 10:58 AM
fmntprsv fmntprsv is offline
 
Join Date: Sep 2007
Posts: 30
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Ok, i was search in the template for quiettorture, torture, quiet and only obtain this:

newreply_reviewbit_ignore_global

<phrase 1="$post[username]">$vbphrase[administrator_decided_x_quiet]</phrase>

and

Quote:
postbit_ignore_global

<table id="post$post[postid]" class="tborder" cellpadding="$stylevar[cellpadding]" cellspacing="$stylevar[cellspacing]" border="0" width="100%" align="center">
<tr title="<phrase 1="$post[postid]">$vbphrase[post_x]</phrase>">
<td class="thead" style="font-weight:normal" $post[scrolltothis]>
<if condition="$show['inlinemod']">
<input type="checkbox" name="plist[$postid]" id="plist_$postid" style="float:$stylevar[right]; vertical-align:middle; padding:0px; margin:0px 0px 0px 5px" value="$post[checkbox_value]" onclick="inlineMod.toggle(this)" />
</if>
<a style="float:$stylevar[right]" href="showpost.php?$session[sessionurl]p=$post[postid]" target="_blank" rel="nofollow" onclick="return display_post($post[postid]);">$vbphrase[view_post]</a>
<a name="post$post[postid]"><img class="inlineimg" src="$stylevar[imgdir_statusicon]/post_$post[statusicon].gif" alt="$post[statustitle]" border="0" /></a>
$post[postdate]<if condition="!$show['detailedtime']">, $post[posttime]</if> $post[firstnewinsert]
</td>
</tr>
<tr>
<td class="alt2">
<a href="member.php?$session[sessionurl]u=$post[userid]">$post[musername]</a>
</td>
</tr>


<tr>
<td class="alt1">
<if condition="$show['moderated']">
<div style="float:$stylevar[right]"><img src="$stylevar[imgdir_misc]/moderated.gif" alt="$vbphrase[moderated_post]" border="0" /></div>
</if>
<if condition="$show['deletedpost']">
<div style="float:$stylevar[right]"><img src="$stylevar[imgdir_misc]/trashcan.gif" alt="$vbphrase[deleted_post]" border="0" /></div>
</if>
<div class="smallfont">
<phrase 1="$post[username]">$vbphrase[administrator_decided_x_quiet]</phrase>
</div>

</td>
</tr>
</table>
and

Quote:
printthreadbit_ignore

<table class="tborder" cellpadding="$stylevar[cellpadding]" cellspacing="1" border="0" width="100%">
<tr>
<td class="page">

<table cellpadding="0" cellspacing="0" border="0" width="100%">
<tr valign="bottom">
<td style="font-size:14pt">$post[username]</td>
<td class="smallfont" align="$stylevar[right]">$post[postdate] $post[posttime]</td>
</tr>
</table>

<hr />

<if condition="$show['adminignore']">
<div class="smallfont">
<phrase 1="$post[username]">$vbphrase[administrator_decided_x_quiet]</phrase>
</div>
<else />
<div class="smallfont">
<phrase 1="$post[username]" 2="profile.php?$session[sessionurl]do=editlist">$vbphrase[message_hidden_x_on_ignore_list]</phrase></span>
</div>
</if>
</td>
</tr>
</table>
<br />
i thinks these instructions are legitimes of vbulletin...

Thanks in advance.. !
Reply With Quote
  #8  
Old 03-09-2008, 12:48 PM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Look at your plugin list, is there anything unusual there? Also, look in your .htaccess file.
Reply With Quote
  #9  
Old 03-09-2008, 01:58 PM
fmntprsv fmntprsv is offline
 
Join Date: Sep 2007
Posts: 30
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for your interest dismounted, i?m going to check my plugins, and my .htaccess it?s correct.

Thanks again, but it?s possible that the problem it?s a new spyware, more info at: www.forospyware.com%2Ft135658.html%23post654024
Reply With Quote
  #10  
Old 03-09-2008, 02:18 PM
Phaedrus Phaedrus is offline
 
Join Date: Jul 2006
Location: Colorado
Posts: 617
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Check your actual index.php files and home.php files. If somebody gets your FTP password they can upload new php with redirects in them. They are relatively easy to clean up. This happened to my site a while back when my server company was compromised.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 05:45 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02124 seconds
  • Memory Usage 2,256KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete