The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Security concerns
Hi All,
I'm running a 3.8.1 forum and recently we've had a couple of intrusions where .js files were modified in the clientscript folder. I was able to remove those but some users have reported that they still getting virus warnings occasionally. Can anyone help me understand how someone may be able to modify the files in the clientscript folder? I don't believe they've gain access to the server directly. Could there be malicious code in our database? if so, which tables/fields should I know? Is there a query I can use to find them? Thanks. |
#2
|
||||
|
||||
Ask your host to check the access/ftp logs for around the time of the hack to see what exactly went down. You are running a very old version which has several known security issue. I think it would help to upgrade your forum to the latest version of the 3.8x series.
|
#3
|
||||
|
||||
I agree with this. There have been a lot of security patches since 3.8.1. Not having them will leave your forum vulnerable.
|
#4
|
||||
|
||||
Ineed, if you are able to, upgrade to vB 3.8.7 - other than that, check the permissions on your clientscript folder - do you allow files to be written in /clientscript/vbulletin_css/ ?
|
#5
|
||||
|
||||
I know on one occasion, a client of mine was hacked... come to find out a plugin was created w/o them knowing so check your files for any changes via timestamps and also check your plugins, ensure that there are no spare "iffy" plugins active .
|
Благодарность от: | ||
borbole |
#6
|
|||
|
|||
Quote:
--------------- Added [DATE]1314984001[/DATE] at [TIME]1314984001[/TIME] --------------- Quote:
--------------- Added [DATE]1314984225[/DATE] at [TIME]1314984225[/TIME] --------------- The other admin handles the plugins and we may have a few that may be suspect... I'll have to check them out. Thanks |
Благодарность от: | ||
TheLastSuperman |
#7
|
||||
|
||||
755
|
#8
|
|||
|
|||
Thank you! I've changed it to 755 now. Do you guys think this could of allowed access into the clientscript folder for modification? I thought permissions can not go up the tree.
|
#9
|
|||
|
|||
Umm.. this might be a dumb question but..
If you've changed the CSS to be stored on disk, doesn't that folder need to be 777? I think 755 will give a write access error. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|