Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 11-05-2008, 08:49 PM
FleaBag's Avatar
FleaBag FleaBag is offline
 
Join Date: Dec 2001
Posts: 1,674
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default OK, so my site got hacked... I think? Advice?!

I have a second vB board which I mostly use for testing stuff out... I logged onto it yesterday and found that in some shape or form I've been hacked. The second time in my 12 years or so online... The last time was an old vB2 v3 Articles vulnerability... This test board however, had few hacks installed.

I've Googled for the names on the page but it doesn't yield many results, it seems my page is the only one online hacked in this way.

All vB URL's redirect to the page you can see in the above link, there is an embedded image - which is not actually a file on the server. I thought the FTP had been hacked but I logged in and all files are unchanged since my last upgrade. I then thought .htaccess had been changed in some way, but this is also unchanged...

ACP stuff works fine... So what's going on here? Where has my site gone?

I don't know if this is a vB issue (by issue I mean I left a door open somewhere, rather than an exploit) or server issue... The page does mention Safe Mode being off.

So if anyone could shed any light on what happened, how I stop it happening again and how I get rid of this trash it would be greatly appreciated!?

Oh and can anyone translate what the text on the page says?

The board is/was running 3.7.3 PL1. Thanks guys!
Reply With Quote
  #2  
Old 11-05-2008, 08:57 PM
KW802's Avatar
KW802 KW802 is offline
 
Join Date: Jul 2003
Location: A galaxy far, far away...
Posts: 1,450
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Check your templates to see if any of them have been modified (replaced with the HTML you're seeing instead of the usual vB templates). I came across a site that was hacked where several templates were replaced; everything behind the scenes worked but the templates were replaced. Also be sure, after you've recovered to a point where you can go from, to check your phrases & translations to make sure nothing was added. The site I mentioned with the template changes also had a second language added and some phrases altered.
Reply With Quote
  #3  
Old 11-05-2008, 09:23 PM
FleaBag's Avatar
FleaBag FleaBag is offline
 
Join Date: Dec 2001
Posts: 1,674
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hi Kevin, thanks for the suggestions...

I must have been tripping last night, as I just tried to log into the ACP and I get the same defaced page on login.php?do=login. So no cookie can be set.
Reply With Quote
  #4  
Old 11-05-2008, 09:34 PM
KW802's Avatar
KW802 KW802 is offline
 
Join Date: Jul 2003
Location: A galaxy far, far away...
Posts: 1,450
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by FleaBag View Post
Hi Kevin, thanks for the suggestions...

I must have been tripping last night, as I just tried to log into the ACP and I get the same defaced page on login.php?do=login. So no cookie can be set.
If you're sure that none of the actual files on the server have been comprimised, then perhaps your admin password has been reset and you're seeing the 'invalid password' error page that has been defaced.

Try resetting your admin password.
Reply With Quote
  #5  
Old 11-05-2008, 09:34 PM
Winterworks Winterworks is offline
 
Join Date: Feb 2008
Location: Canada
Posts: 640
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Do you have two licenses or just one? It all depends on this.
Reply With Quote
  #6  
Old 11-05-2008, 09:44 PM
FleaBag's Avatar
FleaBag FleaBag is offline
 
Join Date: Dec 2001
Posts: 1,674
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by KW802 View Post
If you're sure that none of the actual files on the server have been comprimised, then perhaps your admin password has been reset and you're seeing the 'invalid password' error page that has been defaced.

Try resetting your admin password.
Thanks once more. I'll give that a shot now.

EDIT: Kevin I just realised, I need to set up a new account to do this... Which I don't have the ability to do.

Quote:
Originally Posted by Winterworks View Post
Do you have two licenses or just one? It all depends on this.
What all depends on this?
Reply With Quote
  #7  
Old 11-05-2008, 09:45 PM
Winterworks Winterworks is offline
 
Join Date: Feb 2008
Location: Canada
Posts: 640
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Just answer the question and I can help you?
Reply With Quote
  #8  
Old 11-05-2008, 09:53 PM
FleaBag's Avatar
FleaBag FleaBag is offline
 
Join Date: Dec 2001
Posts: 1,674
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Oh right, I thought you meant there was an issue that only affected licensed boards lol.

Yes it is my friend, and I'm sure I'd be shut down here pretty fast if I didn't.
Reply With Quote
  #9  
Old 11-05-2008, 09:56 PM
Winterworks Winterworks is offline
 
Join Date: Feb 2008
Location: Canada
Posts: 640
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

That's not my question It was how many licenses do you have?
Reply With Quote
  #10  
Old 11-05-2008, 09:59 PM
FleaBag's Avatar
FleaBag FleaBag is offline
 
Join Date: Dec 2001
Posts: 1,674
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Oh, right... Sorry I misread the question. I have two at present.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:12 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06177 seconds
  • Memory Usage 2,261KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete