Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 Programming Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 11-27-2011, 04:32 PM
SloppyGoat's Avatar
SloppyGoat SloppyGoat is offline
 
Join Date: Feb 2002
Posts: 339
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Which logs are you referring to? The files creation date was Jan 26, 2011.
Attached Images
File Type: jpg Trojan PHP Properties.jpg (32.9 KB, 0 views)
Reply With Quote
  #12  
Old 11-27-2011, 05:40 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Server access logs.
Reply With Quote
  #13  
Old 11-27-2011, 05:56 PM
SloppyGoat's Avatar
SloppyGoat SloppyGoat is offline
 
Join Date: Feb 2002
Posts: 339
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You mean the IIS log files? I don't run Apache, remember? I still have all the log files, but have no idea what to look for, or even where to start, since I really don't know when the problem even started...as I believe I mentioned above.
Reply With Quote
  #14  
Old 11-27-2011, 06:01 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by SloppyGoat View Post
Don't you think someone would have said something if an officially released hack here was actually a malicious code?
This is what you might not understand - Even though vB.org is the "Official Modifications Site" for vBulletin, they do not (that I know of) themselves officially release any modifications, and do not inspect the ones which are posted here.

The community sometimes catches malicious code in some of the Mods that get posted here. Some others no doubt, escape any scrutiny.
Reply With Quote
  #15  
Old 11-27-2011, 06:05 PM
SloppyGoat's Avatar
SloppyGoat SloppyGoat is offline
 
Join Date: Feb 2002
Posts: 339
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I know that. vBulletin refuses to support hacked boards at all. But as mentioned, I have not installed any hacks since 2010, and before that one, 2008. (Which is probably the last time I updated. It would've been whenever 3.8.0 was released.) What you're insinuating makes no sense, since the creation date of the file is Jan/2011. I appreciate any help or ideas, but please don't sidetrack the topic. All hacks were installed and running smoothly LOOOOOONG before this problem existed.
Reply With Quote
  #16  
Old 11-27-2011, 06:12 PM
Boofo's Avatar
Boofo Boofo is offline
 
Join Date: Mar 2002
Location: Des Moines, IA (USA)
Posts: 15,776
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Find out who has FTP access to your server and start from there.
Reply With Quote
Благодарность от:
Max Taxable
  #17  
Old 11-27-2011, 06:14 PM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by SloppyGoat View Post
I know that. vBulletin refuses to support hacked boards at all. But as mentioned, I have not installed any hacks since 2010, and before that one, 2008. (Which is probably the last time I updated. It would've been whenever 3.8.0 was released.) What you're insinuating makes no sense, since the creation date of the file is Jan/2011. I appreciate any help or ideas, but please don't sidetrack the topic. All hacks were installed and running smoothly LOOOOOONG before this problem existed.
I understand all of this.

I brought up styles because I do know of one that did have such a malicious file in it, that stayed dormant for months before going active. Wasn't saying definitely that such a malicious file existed in any of your mods or skins, or even insinuating it - was just, again, applying Occam's Razor. Spitballing.
Reply With Quote
  #18  
Old 11-27-2011, 06:38 PM
SloppyGoat's Avatar
SloppyGoat SloppyGoat is offline
 
Join Date: Feb 2002
Posts: 339
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Boofo View Post
Find out who has FTP access to your server and start from there.
I host my own server from my home. Nobody has any access to anything except the forum itself. There is no need for FTP when your server is right beside you. Direct access here only. All ports closed except 80, and I am behind two routers and a SW FW. That is about as secure as it gets, wouldn't you think?

[OT] Is that Jim Morrison in your avatar? Man, I love MR. MOJO RISIN!!![/OT]
--------------- Added 27 Nov 2011 at 13:40 ---------------

Quote:
Originally Posted by Max Taxable View Post
I understand all of this.

I brought up styles because I do know of one that did have such a malicious file in it, that stayed dormant for months before going active. Wasn't saying definitely that such a malicious file existed in any of your mods or skins, or even insinuating it - was just, again, applying Occam's Razor. Spitballing.
I see. I only have two styles (not counting vB default), and nobody uses the one that I don't have set to default. It's been that way since day 1. I created my own style and did install some, but never got them the way I wanted, so got rid of all of them. But that too was a very long time ago. At the time, there were not even updated styles for the version.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:47 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04089 seconds
  • Memory Usage 2,261KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (4)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (8)post_thanks_box
  • (1)post_thanks_box_bit
  • (8)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (8)post_thanks_postbit_info
  • (8)postbit
  • (1)postbit_attachment
  • (8)postbit_onlinestatus
  • (8)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_attachment
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete