Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #31  
Old 08-21-2008, 08:31 PM
PAKIDIL PAKIDIL is offline
 
Join Date: Jan 2007
Posts: 264
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Digital Jedi View Post
My point is, if they've hacked into your server, your file permissions aren't going to matter. They will have access to everything anyway.
YEAH YOU are rite if they hack in to the server then this permission are not going to matter.ofcourse they will hack it again .it will be like a theif has entered in the house and after that you are locking the door. must search for the good hosting company.
Reply With Quote
  #32  
Old 08-25-2008, 12:39 PM
Quarterbore Quarterbore is offline
 
Join Date: Mar 2005
Location: Valley Forge PA
Posts: 538
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It took some time but I figured out my hacker came from IP: 84.121.141.217

IP owner info (Whois)
Quote:
OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL

ReferralServer: whois://whois.ripe.net:43

NetRange: 84.0.0.0 - 84.255.255.255
CIDR: 84.0.0.0/8
NetName: 84-RIPE
NetHandle: NET-84-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: SUNIC.SUNET.SE
NameServer: TINNIE.ARIN.NET
NameServer: NS3.NIC.FR
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at Query the RIPE Database
RegDate: 2003-11-17
Updated: 2004-03-16

# ARIN WHOIS database, last updated 2008-08-23 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.



Deferred to specific whois server: whois.ripe.net...


% This is the RIPE Whois query server #1.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See Whois Database Copyright
Quote:
Whois record :

[Querying whois-ita.nominalia.com]
[whois-ita.nominalia.com]

NOMINALIA INTERNET S.L. - Whois Server Version 1.4

The Registry database contains ONLY .COM, .NET and .ORG domains.

Domain name: ONO.COM
Created on: 2003-07-28
Updated on: 2008-01-17
Expires on: 2008-12-14
Registrant Name: CABLEUROPA SA
Contact: Cableuropa SA
Registrant Address: C\ Basauri, 7
Registrant City: Aravaca
Registrant Postal Code: E-28023
Registrant Country: ES
Administrative Contact Organization: Cableuropa S.A
Administrative Contact Name: Nicolas Chapa
Administrative Contact Address: Basauri 7-9 Urbanizacion La Florida
Administrative Contact City: Aravaca
Administrative Contact Postal Code: 28023
Administrative Contact Country: ES
Administrative Contact Email: dominios@ono.es
Administrative Contact Tel: +34 911809300
Administrative Contact Fax: +34 911809600
Technical Contact Organization: Cableuropa S.A
Technical Contact Name: Gerente de Servicios de Internet
Technical Contact Address: Basauri 7,9-Urbanizacion La Florida
Technical Contact City: Aravaca
Technical Contact Postal Code: 28023
Technical Contact Country: ES
Technical Contact Email: dominios@ono.es
Technical Contact Phone: +34 911809300
Technical Contact Fax: +34 911809600
Primary Name Server Hostname: DNS01.ONO.COM
Secondary Name Server Hostname: DNS03.ONO.COM


>>> Last update of whois database: Sun Aug 24 12:48:31 2008 <<<
Related IPs:
I locked out the hacker's IP and all related IPs. Perhaps this will help someone else
Reply With Quote
  #33  
Old 08-25-2008, 11:44 PM
Videx's Avatar
Videx Videx is offline
 
Join Date: Feb 2007
Posts: 3,085
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks. 84.0.0.0-84.255.255.255 added to my cpanel ip deny manager. I don't expect any legit visitors from NL, so I can get away with that!
Reply With Quote
  #34  
Old 08-26-2008, 08:15 AM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Your "hacker" has used an IP address that is asigned to a Spanish ISP. So he is just 1 of the customers of this ISP. He is not located in the Netherlands.

PS RIPE is the european registrar and it's headquarters are located in the Netherlands, this has got nothing to do with your hacker.
Reply With Quote
  #35  
Old 08-26-2008, 11:48 AM
Videx's Avatar
Videx Videx is offline
 
Join Date: Feb 2007
Posts: 3,085
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for the clarification. I'm not expecting anyone legit from Spain either, so I'm still safe denying the whole range.
Reply With Quote
  #36  
Old 09-10-2008, 12:40 PM
bebeko bebeko is offline
 
Join Date: Oct 2006
Posts: 20
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Any updates on this vulnerability? I had a site hacked twice exactly the same way (base64 encrypted php code was inserted at table 'template' , field 'template' , key record 'spacer_open', which was evaluated and defaced the website). My vBulletin version is 3.7.3 PL1. Modules used (all latest available version):
  • MorbiD SuitE [9 Flavours] | LYCHEE new| 3.7.2
  • Cyb - Advanced Permissions Based on Post Count
  • Automatic Thread Tagger
  • Periodic Prune Pms [ Cron Job - Fully Controlable ]
  • Separate Sticky and Normal Threads
  • Embed XHTML valid YouTube and Google Video into your posts
  • Automatic Inactive Users Pruning - vB3.7 RC2
  • vbAnonymizer
  • GTCustom Pages - Create Custom Pages With Ease
  • Send emails with HTML as HTML
Reply With Quote
  #37  
Old 09-16-2008, 04:14 PM
bebeko bebeko is offline
 
Join Date: Oct 2006
Posts: 20
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It seems that the only module installed alike with bilderback's configuration is "Separate Sticky and Normal Threads".
I still haven't found how attackers managed to rewrite the spacer_open template in all styles with an eval(base64) function...
Anyone with the same problem?
Reply With Quote
  #38  
Old 09-18-2008, 11:15 PM
Bilderback's Avatar
Bilderback Bilderback is offline
 
Join Date: Sep 2007
Location: Illinois
Posts: 214
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

In our case, there was a php shell script already planted somewhere on the BlueHost shared server.
Amazingly and rare, the hacker actually communicated in the forum for some time.
http://thebestforumever.com/archives...c-ur-site.html
Reply With Quote
  #39  
Old 09-25-2008, 07:06 PM
RS25com RS25com is offline
 
Join Date: Dec 2001
Posts: 87
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Bilderback View Post
In our case, there was a php shell script already planted somewhere on the BlueHost shared server.
Amazingly and rare, the hacker actually communicated in the forum for some time.
http://thebestforumever.com/archives...c-ur-site.html
I'd be interested in seeing what he said, but without registering. Care to post his comments?
Reply With Quote
  #40  
Old 09-25-2008, 08:07 PM
fattony69 fattony69 is offline
 
Join Date: Jun 2007
Location: Philly
Posts: 353
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by RS25com View Post
I'd be interested in seeing what he said, but without registering. Care to post his comments?
I have some quotes if you want them:

Quote:
hi tbfe admins and users . .

i think u know me ?

any way i ViRuS_HiMa , the person who hacked ur site 3 times be4

fisrt sorry me about my english cuz i 17 y old from egypt

when i read the topic , its talk about this site hacked more than 4 or 5 times i think !!

how did i hack u ?

i was have phpshell script on the server that ur site has hosted on . .

but i was user and it mean that i can only read files from other sites on the server

so i look for forums to read the config thin use an script to change all forum home pages . .

and i think some one tlak about me and about the scrept in the vBulletin site :

vbulletin hacked - vBulletin.org Forum

but u know they was wrong in more of things cuz they talk about 777 permissions

but i dont need to 777 permissions to hack the vb forums cuz i can hack it with the only config data . . .

how to protect ur selfs from the next attacks ?

u have to change the include directory place

if u dont know what include dirctory

its folder in the vBulletin script . . .

and u have also to crypt the config by zend program . . .

last advic to u that u have to change ur passwords cum my some one have it now

and u have to see wich users are administrator and can log to the vb cpanel

cus the hacker can creat new user have the administrators access to the vb cpanel

now i tell u some of the forums security ways and u should know more

but any way if u dont know more about forums and sites security

u can contact me and i gonna help u as i can

A.e@hotmail.com


that was my advvices and i w8 for u . . .

and for the second time sorry me about my english . .

ViRuS_HiMa
Quote:
look when i deface ur forum i wasnt have phpshell on the "tbfe" i was have the shell on another site of the server

so when my id on the sell is user , and i wanna hack another site on the server ,

i have to use the script that i talkin about . .

i have use 2 scripts , one to read the config of the forum and the other is to deface all forum home pages .

about the milw0rm script , there is big defranse between my scriptes and the milw0rm script . .

the job of milw0rm script is to send the new exploits by the useres to stroky the milw0rm admin

then he add it to the script , so any 1 can see it . use it , and hack by it . . .

ViRuS_HiMa . .
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:06 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05719 seconds
  • Memory Usage 2,279KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (8)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete