The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Help, being hacked!
All, running a modified version of vb2.3.0
Starting yesterday we keep getting hacked, someone keeps getting control of userid 1 which happens to be my account with full admin rights, they first defaced it with a bunch of arab anti-american garbage, now they are logging in and deleting forums. I changed the password for my account, and now I just banned it. Anyone know how they are doing this so I can fix it? Upgrading is not really an option at this point. Any help is appreciated, thanks. |
#2
|
|||
|
|||
It's tough to tell how they are doing it.
If you changed your password, then they probably aren't guessing it. They could just be getting access to your database. Do you have an insecure version of phpmyadmin installed, one with out a password? (if it has a password, change it) List off what hacks you have installed, one may be vulnerable. Last case would be to look through your Apache access logs, it's a pain, but it'll let you know what IP has been accessing certain admin only files. -Modin |
#3
|
|||
|
|||
They are using the admin control panel, all the hacks were done by me personally. They dont have access to my database because if they did, they wouldn't be deleting forums and changing users from the admin control panel I dont think.
I saw some mention of a hole in the "I forgot my password" function? The admin logs show the IP of "217.23.37.85" under my account. |
#4
|
||||
|
||||
See this thread: http://www.vbulletin.com/forum/showthread.php?t=108741
|
#5
|
|||
|
|||
Well, I already had the calander disabled, I went ahead and removed the calander.php file altogether since we dont use it.
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|