Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 09-09-2013, 02:17 PM
jaxo jaxo is offline
 
Join Date: Dec 2011
Posts: 22
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Help - my forum has been hacked

Hi, sorry I`m not even sure if I should be posting here or on .com,. however my site has been hacked and I am unsure what to do.

I logged in today and just by concidence noticed an administrator by the name of h311-c0d3 was online,.. I checked admin permissions and logs and there where about 6-7 admin there who should not have been.

I check logs and deleted the admin. Most had no logs but a couple had been running scripts which seems to be to do with paid subscriptions. When I tried to access this section of the admin panel it asked for a password.. (something I have never set, as I have no paid subs)

I`m at a bit of a loss,.. what should I do? How did they get in etc?

I`d be greatful for any advice,.. The site is http://cccam-exchange.com and its running Version 4.2.0

Thanks invance

Jack
Reply With Quote
  #2  
Old 09-09-2013, 02:25 PM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

<a href="http://www.vbulletin.com/forum/blogs/michael-miller/3934768-recovering-a-hacked-vbulletin-site" target="_blank">http://www.vbulletin.com/forum/blogs...vbulletin-site</a>
Reply With Quote
  #3  
Old 09-09-2013, 02:46 PM
jaxo jaxo is offline
 
Join Date: Dec 2011
Posts: 22
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for that link. Will have a read and see what I can do.. Thanks

--------------- Added [DATE]1378752377[/DATE] at [TIME]1378752377[/TIME] ---------------

From what i can see, they have tried to run scripts and have did something with paid subscription section of the admin panel... every tab I try to access it asks for a password (which I do not know, as I have never set up any paid subscriptions).. where in the files is this password located so I can change or remove it,.. Or is there a quiery I could run to remove it?

What I have did so far is removed the rogue admin, checked config.php to see if any superadmin have been added (which they havent), upgraded my vbulletin to the latest version and renamed the admincp... As far as I am aware they got access through the vbulletin software and not through the server.

Is their anything else I can check for or do ?

--------------- Added [DATE]1378753861[/DATE] at [TIME]1378753861[/TIME] ---------------

Here is a copy of my admin log and what they have done..

25618 N/A 16:06, 8th Sep 2013 subscriptions.php modify 37.130.224.22
25617 N/A 16:06, 8th Sep 2013 subscriptions.php add 37.130.224.22
25616 N/A 16:06, 8th Sep 2013 plugin.php modify 37.130.224.22
25615 N/A 16:06, 8th Sep 2013 plugin.php add 37.130.224.22
25614 N/A 16:06, 8th Sep 2013 plugin.php 37.130.224.22
25613 N/A 16:06, 8th Sep 2013 plugin.php kill plugin id = 677 37.130.224.22
25612 N/A 16:06, 8th Sep 2013 plugin.php delete plugin id = 677 37.130.224.22
25611 N/A 16:06, 8th Sep 2013 plugin.php modify 37.130.224.22
25610 N/A 16:06, 8th Sep 2013 plugin.php kill plugin id = 678 37.130.224.22
25609 N/A 16:06, 8th Sep 2013 plugin.php delete plugin id = 678 37.130.224.22
25608 N/A 16:06, 8th Sep 2013 plugin.php modify 37.130.224.22
25607 N/A 16:06, 8th Sep 2013 plugin.php product 37.130.224.22
25606 N/A 16:05, 8th Sep 2013 diagnostic.php payments 37.130.224.22
25605 N/A 16:05, 8th Sep 2013 subscriptionpermission.php modify 37.130.224.22
25604 N/A 16:05, 8th Sep 2013 plugin.php 37.130.224.22
25603 N/A 16:05, 8th Sep 2013 plugin.php doimport 37.130.224.22
25602 N/A 16:05, 8th Sep 2013 plugin.php files 37.130.224.22
25601 N/A 16:05, 8th Sep 2013 plugin.php files 37.130.224.22
25600 N/A 16:02, 8th Sep 2013 plugin.php modify 37.130.224.22
25599 N/A 16:02, 8th Sep 2013 plugin.php product 37.130.224.22
25598 N/A 16:02, 8th Sep 2013 plugin.php modify 37.130.224.22
25597 N/A 16:02, 8th Sep 2013 plugin.php product 37.130.224.22
25596 N/A 16:02, 8th Sep 2013 plugin.php modify 37.130.224.22
25595 N/A 16:02, 8th Sep 2013 plugin.php add 37.130.224.22
25594 N/A 16:02, 8th Sep 2013 plugin.php files 37.130.224.22
25593 N/A 15:53, 8th Sep 2013 plugin.php 37.130.224.22
25592 N/A 15:53, 8th Sep 2013 plugin.php doimport 37.130.224.22
25591 N/A 15:52, 8th Sep 2013 plugin.php files 37.130.224.22
25590 N/A 15:52, 8th Sep 2013 plugin.php updateactive 37.130.224.22
25589 N/A 15:51, 8th Sep 2013 plugin.php 37.130.224.22
25588 N/A 15:51, 8th Sep 2013 plugin.php update 37.130.224.22
25587 N/A 15:51, 8th Sep 2013 plugin.php add 37.130.224.22
25586 N/A 15:51, 8th Sep 2013 plugin.php add 37.130.224.22
25585 N/A 15:50, 8th Sep 2013 plugin.php files 37.130.224.22
25584 N/A 15:50, 8th Sep 2013 plugin.php modify 37.130.224.22
25583 N/A 15:50, 8th Sep 2013 plugin.php product 37.130.224.22
25582 N/A 15:50, 8th Sep 2013 subscriptions.php add 37.130.224.22
25581 N/A 15:50, 8th Sep 2013 subscriptions.php modify 37.130.224.22
Reply With Quote
  #4  
Old 09-09-2013, 08:40 PM
TheLastSuperman's Avatar
TheLastSuperman TheLastSuperman is offline
Senior Member
 
Join Date: Sep 2008
Location: North Carolina
Posts: 5,844
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ForceHSS View Post
Ohh now I like that link... wonder why?

Moved thread from vB5 General Discussion to vB4 General Discussion.

Seems eerily familiar to this - https://vborg.vbsupport.ru/showthread.php?t=301904

The doimport is what includes their backdoor scripts.
Reply With Quote
Благодарность от:
ForceHSS
  #5  
Old 09-09-2013, 09:30 PM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site
Also please see these recent security announcements:
vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5
vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions
Reply With Quote
  #6  
Old 10-19-2013, 12:07 PM
XrayHead's Avatar
XrayHead XrayHead is offline
 
Join Date: Oct 2002
Posts: 138
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Subscribed, going to keep an eye on this thread! Let me know how you get on as my site got hacked yesterday as well!!

Just out of interest what was the username that did all the damage? The one on my site that run the scripts via the plugin.php and subscriptions.php was "optima"




Xray
Reply With Quote
  #7  
Old 10-19-2013, 12:32 PM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I guess you did not delete your install directory.
Reply With Quote
  #8  
Old 10-19-2013, 12:37 PM
borbole's Avatar
borbole borbole is offline
 
Join Date: Jan 2010
Posts: 2,559
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It looks like no matter what you do, all seems pointless. You close one door and many more are opened. vB should start to take security more seriously as it has more leaks than the Titanic for crying out loud.
Reply With Quote
Благодарность от:
dizzynation
  #9  
Old 10-19-2013, 12:46 PM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

All knows security issues have been addressed, only reason the last user was compromised, is because they did not delete their install directory, as they were instructed to do so many times.

No matter what you think you do with security with the software, hackers will always attempt to find holes, so best bet is to take measures to protect your site, rather than relying on the software to do it.
Reply With Quote
  #10  
Old 10-19-2013, 01:18 PM
XrayHead's Avatar
XrayHead XrayHead is offline
 
Join Date: Oct 2002
Posts: 138
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I think it would be more productive to help people fix this issue rather than fill the thread with useless post's! I personally never got any update from vBulletin as I've been changing email addresses for the past 2 months (that's another Yahoo mess in its self)..

Anyway this seems to be a very common hack that has hit hundreds of boards! Surely someone must have a fix for any database changes this attack applies??
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:34 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.12098 seconds
  • Memory Usage 2,269KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (2)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (2)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete