The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#31
|
|||
|
|||
YEAH YOU are rite if they hack in to the server then this permission are not going to matter.ofcourse they will hack it again .it will be like a theif has entered in the house and after that you are locking the door. must search for the good hosting company.
|
#32
|
|||
|
|||
It took some time but I figured out my hacker came from IP: 84.121.141.217
IP owner info (Whois) Quote:
Quote:
Quote:
|
#33
|
||||
|
||||
Thanks. 84.0.0.0-84.255.255.255 added to my cpanel ip deny manager. I don't expect any legit visitors from NL, so I can get away with that!
|
#34
|
|||
|
|||
Your "hacker" has used an IP address that is asigned to a Spanish ISP. So he is just 1 of the customers of this ISP. He is not located in the Netherlands.
PS RIPE is the european registrar and it's headquarters are located in the Netherlands, this has got nothing to do with your hacker. |
#35
|
||||
|
||||
Thanks for the clarification. I'm not expecting anyone legit from Spain either, so I'm still safe denying the whole range.
|
#36
|
|||
|
|||
Any updates on this vulnerability? I had a site hacked twice exactly the same way (base64 encrypted php code was inserted at table 'template' , field 'template' , key record 'spacer_open', which was evaluated and defaced the website). My vBulletin version is 3.7.3 PL1. Modules used (all latest available version):
|
#37
|
|||
|
|||
It seems that the only module installed alike with bilderback's configuration is "Separate Sticky and Normal Threads".
I still haven't found how attackers managed to rewrite the spacer_open template in all styles with an eval(base64) function... Anyone with the same problem? |
#38
|
||||
|
||||
In our case, there was a php shell script already planted somewhere on the BlueHost shared server.
Amazingly and rare, the hacker actually communicated in the forum for some time. http://thebestforumever.com/archives...c-ur-site.html |
#39
|
|||
|
|||
Quote:
|
#40
|
|||
|
|||
Quote:
Quote:
Quote:
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|