Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 01-25-2009, 12:49 PM
BlitzSports BlitzSports is offline
 
Join Date: Jan 2008
Posts: 40
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Site keep getting hacked

My site keeps getting hacked. This bozo keeps replacing ALL of my index.php files with his hacked files.

I am running 3.6.8 and have about 60 mods installed. MY host said its vbulletin that is allowing my site to be compromised due to security issues with 3.6.8.

What files do I need to update that will allow me NOT to overwrite any templates. Also, how do i do it? Please do not tell me that I need to start from scratch because I do not know how as I paid somebody to create my site and I do not want to pay them again as it was costly.

I do have some knowledge to computers and know a lot about HTML. That's my extent.
Reply With Quote
  #2  
Old 01-25-2009, 12:53 PM
SEOvB's Avatar
SEOvB SEOvB is offline
 
Join Date: May 2007
Location: Indianapolis
Posts: 2,451
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You need to update 3.6.8 to at least 3.6.12 or whatever the latest version for 3.6 is.

There should only be minimal style changes between the two, and the upgrade won't automatically overwrite your styles.

60 mods is a lot, hopefully you need all of them, as thats 60 additional chances of a modification being the source of the hacking as well. I'd remove any not used along with their files.
Reply With Quote
  #3  
Old 01-25-2009, 01:15 PM
BlitzSports BlitzSports is offline
 
Join Date: Jan 2008
Posts: 40
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I just spent a long time at the vbulletin.com site looking for the update to the latest 3.6 version and all I can find is 3.8.

Where do I do to get the latest 3.6.x update patch?

And thanks for your help
Reply With Quote
  #4  
Old 01-25-2009, 01:59 PM
SEOvB's Avatar
SEOvB SEOvB is offline
 
Join Date: May 2007
Location: Indianapolis
Posts: 2,451
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Click the "More Download Options" while going thru the download process at vbulletin.com/members
Reply With Quote
  #5  
Old 01-25-2009, 02:43 PM
Alfa1's Avatar
Alfa1 Alfa1 is offline
 
Join Date: Dec 2005
Location: Netherlands
Posts: 3,537
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Your image gallery is getting hacked. He was able to upload files to your server. What software do you use for your image gallery?

I see your hacker asks you to remove safe_mode and mentions your permission settings.

You need someone who knows what he/she is doing to review your server security. Ranging from permissions to the services that are allowed on your server. Your logs need to be reviewed, so that you can see what happened and what security issues you need to resolve. As I see it you have two options: get someone in charge of your server security or you will have to learn it yourself(either by free will or by force, as hacks will likely keep on coming)

Although I do not know the situation, my bet is that the hosting co has no clue.
Reply With Quote
  #6  
Old 01-25-2009, 03:08 PM
Brandon Sheley's Avatar
Brandon Sheley Brandon Sheley is offline
 
Join Date: Mar 2005
Location: Google Kansas
Posts: 4,678
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

talk to your host, check the logs
google this, it's been asked 100's of times
Reply With Quote
  #7  
Old 01-25-2009, 07:20 PM
BiZiMDiYaR BiZiMDiYaR is offline
 
Join Date: Aug 2006
Posts: 100
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hi,

Ok, let'say this has been asked 100's or even 1000's times.. and I think will be asked more also :-). Can anybody explain where to look for in the logs ? How to analyse what has been done and how to see what is happening on the server.. ? Where to see these logs for hacking, for DDOS's or any other things what happens.. ?

Just the basic info on where to look woulf be great.. or maybe some google links which you think has got some good informations... as there are like you mentioned a lot of links, but how do we know which one is good ? :-)

Best regards.
Reply With Quote
  #8  
Old 01-25-2009, 08:15 PM
BlitzSports BlitzSports is offline
 
Join Date: Jan 2008
Posts: 40
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Alfa1 View Post
Your image gallery is getting hacked. He was able to upload files to your server. What software do you use for your image gallery?

I see your hacker asks you to remove safe_mode and mentions your permission settings.

You need someone who knows what he/she is doing to review your server security. Ranging from permissions to the services that are allowed on your server. Your logs need to be reviewed, so that you can see what happened and what security issues you need to resolve. As I see it you have two options: get someone in charge of your server security or you will have to learn it yourself(either by free will or by force, as hacks will likely keep on coming)

Although I do not know the situation, my bet is that the hosting co has no clue.
I am running photoplog, or something like that. If I uninstall it will this stop the attacks?
Reply With Quote
  #9  
Old 01-25-2009, 10:36 PM
Alfa1's Avatar
Alfa1 Alfa1 is offline
 
Join Date: Dec 2005
Location: Netherlands
Posts: 3,537
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by BiZiMDiYaR View Post
Can anybody explain where to look for in the logs ? How to analyse what has been done and how to see what is happening on the server.. ? Where to see these logs for hacking, for DDOS's or any other things what happens.. ?
You need to review the logs line for line. See if anything odd happens. Keep an eye on strange requests, especially by the same IP(s), especially in the photoplog directory. If you find a suspect IP run it trough vbulletin and see what comes up. You need to find out what services where exploited and if you can block these services, or at least make them more secure.

You should be able to access your logs trough your servers admin panel. Where in the admin panel depends upon which admin panel you have.

Quote:
Originally Posted by BlitzSports View Post
I am running photoplog, or something like that. If I uninstall it will this stop the attacks?
This is hard to answer without knowing what exactly has happened. It is likely that the hacker gained access by finding an vulnerability in your photoplog directory. But this is far from certain. One thing you almost surely need to address is CMOD permissions of your directories. You will need to find out what is on your server that does not belong there. After you have found out what happened you could consider using a back up of your database and files and using that as your basis. It is possible that you have files and scripts on your forum, that will allow the hacker regain control.
Reply With Quote
  #10  
Old 01-28-2009, 08:38 AM
Jon Tolzien Jon Tolzien is offline
 
Join Date: Nov 2008
Location: Grand Forks, ND
Posts: 87
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have read alot of these forums, so i am not sure I can help you right now, but i can recommend you to read this post. https://vborg.vbsupport.ru/showthread.php?t=197510 Regardless it is a good read.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 07:23 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04419 seconds
  • Memory Usage 2,256KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete