The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#11
|
|||
|
|||
![]()
me to my site is hacked
|
#12
|
||||
|
||||
![]()
I think they weren't after vB since they just injected stuff to spam, and I discover a new email account on my cP with high activity...
2 more files [since this is moved to a discussion forum] yomistarz.php PHP Code:
Why we don't counterattack? I mean, we are majority, we together know more than this pranksters... |
#13
|
|||
|
|||
![]()
Is that a spam php script?
|
#14
|
|||
|
|||
![]()
I got hacked with that script too, no clue how they got it on my server.
Though the only thing running on my web server is vbulletin. |
#15
|
||||
|
||||
![]()
Well, the problem was resolved in a few hours, I find this in cPanel's Cron Job section:
Quote:
|
#16
|
|||
|
|||
![]()
WOw... i have a "hackers problem" someone is injecting me shells in my site ("c99"....
|
#17
|
|||
|
|||
![]()
@iogames
I'm confused as to what you are trying to tell us here. You've not confirmed how they gained access. How did they get the files into your directories. ? Did you have a backdoor open or was it via another site on the shared hosting ? Would it not be more helpful to let people know exactly what version of vBulletin you have installed What hacks are installed. Also what else do you have running on your site. If people see something in common then it may help to close a vulnerability that may have been exploited. |
#18
|
||||
|
||||
![]()
Ok...
I was so busy that I didn't touch my site for days, till one day I got some spare time and start working on it again... I lost my access to cPanel, I just reset password and they send me to my email the current password, then I starting to look what was going on, and found those foreign files, they didn't remove nothing, then I started a assessment of the problem, and start posting: So basically don't know if there was to a third party script, or Shell injection, Hosters will never accept that there was fault on their part, I just received their help and advise... - CronJobs - Inserted files - FTP Logs - Raw Logs - .htaccess - Change of passwords - Check intengrity of the MySQL's dBs - Eliminate unknown files, etc... |
#19
|
|||
|
|||
![]()
heres the guys email address: grofihack@gmail.com
i decoded the base64 encoded part of the posted script |
#20
|
||||
|
||||
![]() Quote:
after they run out of tricks, they must start running ![]() |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|