The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#11
|
||||
|
||||
There is a thread about this over on vb.com - http://www.vbulletin.com/forum/showt...ghlight=base64 It's from a modification you have installed, but the thread never says which modification it was.
|
#12
|
|||
|
|||
Turn off "Allow HTML" in the forum manager as well as the bbcode and any other place you have it set to On.
|
#13
|
|||
|
|||
Recently they change the permission of the ftp, and others things. But a found de phpShell that they insert me. Iwas called confi2.php in MODULES it was... i delete ir.. Even the antivirus told me that was a malicius code.... but how the hell they insert that..
|
#14
|
|||
|
|||
With PHPShell, depending on the server configuration it can be very easy indeed to exploit your entire site. However for the hacker to have uploaded the PHPShell script in the first place requires a permission issue somewhere.
|
#15
|
|||
|
|||
The instert a "c99". I scan my site and they put 5 of them. Now is clen. But i need to know what to do, to dont let them do this. I change my admin pass, my ftp pas....
|
#16
|
|||
|
|||
You need to check the CHMOD permissions for all your directories and check for any vulnerable scripts. More than likely they didn't use your login details to do this.
|
#17
|
|||
|
|||
Thanks for the annswer. I delete the last mods, but i will have to check for vulnerabilitys of the rest. I have a Dude, when you reffer to CHMOD.... what they should be.... i mean, all reading, but the one that you upload things writing?
Thanks again |
#18
|
|||
|
|||
This very much depends on your setup. You should start by focusing on the directories which were exploited.
|
#19
|
|||
|
|||
Even tho a directory/file is set to 777, it does not mean its vulnerable to hacking, 755 is fine for all directories to function correctly, files can be set to 644, 644 can cause issues sometimes when running apache/php as a cgi though when the ownership is set incorrectly.
|
#20
|
||||
|
||||
Except!!!! The following directories need to be chmod 777:
/customprofilepics /customavatars /signaturepics /clientscript/vbulletin_css And the folder where your attachments are located if they are in the filesystem. (I think that list is correct.) |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|