Go Back   vb.org Archive > Community Central > Community Lounge
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 04-10-2014, 02:47 PM
blind-eddie's Avatar
blind-eddie blind-eddie is offline
 
Join Date: Apr 2006
Location: Michigan
Posts: 2,310
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Please discuss this error

I know what File does not exist means....

I have a ton of these in my error logs.
What are they searching for, a way in?
Have any of you ever seen this before and should I be concerned?

Thank you...

Quote:
[Thu Apr 10 07:02:48 2014] [error] [client 183.207.228.2] File does not exist: /home1/blablabla/public_html/blindeddie/forum/index.php+++++++++++++++++++++++++++++++++++++++++ ++Result:+\xe8\xf1\xef\xee\xeb\xfc\xe7\xee\xe2\xe0 \xed\xfb+\xe4\xe0\xed\xed\xfb\xe5+\xf1\xe8\xf1\xf2 \xe5\xec\xfb+\xf1\xe0\xec\xee\xee\xe1\xf3\xf7\xe5\ xed\xe8\xff;+\xed\xe5+\xed\xe0\xf8\xeb\xee\xf1\xfc +\xf4\xee\xf0\xec\xfb+\xe4\xeb\xff+\xee\xf2\xef\xf 0\xe0\xe2\xea\xe8;, referer: http://blind-eddie.com/forum/index.p...0%E0%E2%EA%E8;
Reply With Quote
  #2  
Old 04-11-2014, 03:33 PM
vbresults vbresults is offline
 
Join Date: Apr 2009
Posts: 687
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yeah, it means someone is trying to hack your board.
Reply With Quote
Благодарность от:
blind-eddie
  #3  
Old 04-11-2014, 08:28 PM
socialteenz's Avatar
socialteenz socialteenz is offline
 
Join Date: May 2011
Posts: 465
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

As vbresults said, yes seems to be a injection to me.

Check your index.php and plugin manger for this code.
Reply With Quote
Благодарность от:
blind-eddie
  #4  
Old 04-12-2014, 05:09 AM
blind-eddie's Avatar
blind-eddie blind-eddie is offline
 
Join Date: Apr 2006
Location: Michigan
Posts: 2,310
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

After looking for dates of last edit on all files via FTP, nothing has been altered.

I have checked all sites and many other scripts installed within my domain and nothing has been altered.

After researching the gibberish I posted in my op, someone is in fact looking for a way in.
I can't believe with all that is installed on my site that no way in was found.....

Only time will tell...

Thank you.
Reply With Quote
  #5  
Old 04-23-2014, 03:46 PM
blind-eddie's Avatar
blind-eddie blind-eddie is offline
 
Join Date: Apr 2006
Location: Michigan
Posts: 2,310
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

New errors.....

America/Denver] PHP Notice:Undefined property: Install::$setting in /home1/blablabla/public_html/blablabla/ssv3_installer_payloaduXjL9hv2.php on line 437

This does not exist anywhere on my server nor have I heard of it....

==============================

America/Denver] PHP Notice: Undefined index: electricsheep in /home1/blablabla/public_html/blablabla/guestbook/includes/guestbook.php on line 278

What is electricsheep?..
Reply With Quote
  #6  
Old 04-23-2014, 04:13 PM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I would get your host onto this and get rid of this hacker and whatever damage they have done
Reply With Quote
  #7  
Old 04-23-2014, 04:28 PM
tbworld tbworld is offline
 
Join Date: Oct 2008
Posts: 2,126
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by blind-eddie View Post
New errors.....

America/Denver] PHP Notice:Undefined property: Install::$setting in /home1/blablabla/public_html/blablabla/ssv3_installer_payloaduXjL9hv2.php on line 437

This does not exist anywhere on my server nor have I heard of it....

==============================

America/Denver] PHP Notice: Undefined index: electricsheep in /home1/blablabla/public_html/blablabla/guestbook/includes/guestbook.php on line 278

What is electricsheep?..
electricsheep is a hack tool, it is older code that has been recently modified.
Reply With Quote
  #8  
Old 04-23-2014, 11:48 PM
blind-eddie's Avatar
blind-eddie blind-eddie is offline
 
Join Date: Apr 2006
Location: Michigan
Posts: 2,310
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thank you for your replies.

They did not get in but, they did try but failed.
None of my files were edited, all domain wide sites folders were scanned, all clean.

All I can do now is wait and see... stay tuned...
Reply With Quote
Благодарность от:
tbworld
  #9  
Old 04-25-2014, 05:11 PM
socialteenz's Avatar
socialteenz socialteenz is offline
 
Join Date: May 2011
Posts: 465
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by blind-eddie View Post
Thank you for your replies.

They did not get in but, they did try but failed.
None of my files were edited, all domain wide sites folders were scanned, all clean.

All I can do now is wait and see... stay tuned...

yeah, also it would be nice to change all your passwords.
Reply With Quote
Благодарность от:
blind-eddie
  #10  
Old 04-25-2014, 05:44 PM
blind-eddie's Avatar
blind-eddie blind-eddie is offline
 
Join Date: Apr 2006
Location: Michigan
Posts: 2,310
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

All passwords were changed as soon as I saw the error messages. :up:
Reply With Quote
Благодарность от:
socialteenz
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:52 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04262 seconds
  • Memory Usage 2,267KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (5)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (5)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete