Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 07-12-2010, 04:59 PM
mexicanpizza mexicanpizza is offline
 
Join Date: Oct 2007
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Site hacked via page navigation? (vB 3.8.5)

Hi all...just wanted to report here while waiting for my support ticket.

My site just started showing a very subtle hack...whenever one views a forum, then tries to move to another page of threads...upon the second click on any navigation control (page #, etc)...i get redirected to some pharmacy site. There is no diff between forumdisplay on my site and a known good copy, I'm still running further diffs to see if this is a file hack or some injection.

Nothing has changed in the last few weeks.

Not sure how it's even happening, the URLs are not compromised, and the problem happens in every forum (and can be reproduced on any page depending on what order you click the nav controls).

:/
Reply With Quote
  #2  
Old 07-12-2010, 05:05 PM
snakes1100 snakes1100 is offline
 
Join Date: Dec 2001
Location: Michigan
Posts: 3,733
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Its doubtful this is a vb issue code wise, no need to alarm the masses.

Sounds like a simple issue, possibly left html on in a forum and someone made a html post, could be a code injection using spacer open or close etc in a template, did you check either?
Reply With Quote
  #3  
Old 07-12-2010, 05:15 PM
mexicanpizza mexicanpizza is offline
 
Join Date: Oct 2007
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for the response...no alarm needed...I'm just in that panicked state.

I haven't changed any templates in a while...but don't know how to check for bad fields in the database.
Reply With Quote
  #4  
Old 07-12-2010, 05:35 PM
snakes1100 snakes1100 is offline
 
Join Date: Dec 2001
Location: Michigan
Posts: 3,733
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well, i didnt mean you changed a template, the injection may have been injected into a template.

Did you verify html is off in all forums?
Should work as long as your running 3.7.x/3.8.x
Code:
UPDATE forum SET options=options - 256 WHERE (options & 256);
Confirm "affected rows" is 0
Reply With Quote
  #5  
Old 07-13-2010, 01:32 AM
mexicanpizza mexicanpizza is offline
 
Join Date: Oct 2007
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

So...just as an update...somehow my host was accessed and an additional file was included in the global.php (what looked like randomly buried in a directory of my wiki). But....changed all my passwords, reverted that file to the original, and the hack was back in a different manner in 30 minutes (new filenames and locations, same content...).

Still working with my host on this one...but any suggestions (along with pointing and laughing) are welcome.

--------------- Added [DATE]1278999435[/DATE] at [TIME]1278999435[/TIME] ---------------

Another update...everything I can figure out on my own (no help from host :/ ) is that my ad server (OpenX) was compromised with some sort of exploit that allows uploading of files (??), both times it happened there were many large POST requests to a known problem .php file in OpenX. I should've upgraded sooner.

This was a pretty insidious hack that attempted to hide itself from human users and display pharmacy pages to web search bots...but was clearly targetted at vBulletin. So anyone running OpenX I would encourage you to upgrade ASAP.

Thanks for letting me vent here.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:24 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04484 seconds
  • Memory Usage 2,201KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_code
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (5)post_thanks_box
  • (5)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (5)post_thanks_postbit_info
  • (5)postbit
  • (5)postbit_onlinestatus
  • (5)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete