Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 11-05-2008, 10:01 PM
Winterworks Winterworks is offline
 
Join Date: Feb 2008
Location: Canada
Posts: 640
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Okay, just making sure.

Check your templates, or even download a new template. He might have accessed that somehow, it happens.
Reply With Quote
  #12  
Old 11-05-2008, 10:09 PM
FleaBag's Avatar
FleaBag FleaBag is offline
 
Join Date: Dec 2001
Posts: 1,674
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You the vBulletin police?

As mentioned I can't access the ACP.
Reply With Quote
  #13  
Old 11-05-2008, 10:11 PM
KW802's Avatar
KW802 KW802 is offline
 
Join Date: Jul 2003
Location: A galaxy far, far away...
Posts: 1,450
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by KW802 View Post
Check your templates to see if any of them have been modified. ...
Quote:
Originally Posted by Winterworks View Post
Check your templates, or even download a new template. He might have accessed that somehow, it happens.
After playing "20 Questions" you offer the same advice as the first response?


Fleabag: Are you comfortable working directly with the MySQL tables using a tool like myPHPAdmin or similar?
Reply With Quote
  #14  
Old 11-05-2008, 10:24 PM
FleaBag's Avatar
FleaBag FleaBag is offline
 
Join Date: Dec 2001
Posts: 1,674
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Sure Kevin, I've done a bit of modifying in the past. I'd considered altering the password field directly but I don't know how to encrypt the value adequately.

But to answer the question, yes I can do that.

Thanks again by the way, you've come to my rescue in the past on a few occasions, and it's appreciated.

EDIT: OK as an update I managed to use tools.php to reset the style settings and it seems it was indeed altered at the template level. That's fixed at least, but I guess I wiped out any trace of how it was done. There are a lot of weird registrations too...

EDIT 2: I've managed to log in using my old/current admin password. I was greeted by a screen telling me my password is 219 days old and needs to be updated. The screen seemed to refresh when it first loaded.

EDIT 3: Upgraded to latest version... Trying to make sure everything is locked down now. Thanks for the input guys. I just need to work out what happened now.
Reply With Quote
  #15  
Old 11-06-2008, 01:14 AM
KW802's Avatar
KW802 KW802 is offline
 
Join Date: Jul 2003
Location: A galaxy far, far away...
Posts: 1,450
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Sorry for the delay... I was on the road home from work. If you're still interested in the SQL item, I'll follow up via PM.

The site I got hit with was done via an older version of a certain gallery software application that did not properly check file extensions and a malicious PHP script ended up on the server. It sounds like you got hit with either the same script or something similar.

- Check all of your modified templates. Some of the big ones, like forumhome were easy enough to tell that it got hit but I found out a day later that some others were hit as well. No fast way of doing this other than going into Style Manager, expanding the views, and checking all of the templates that were modified (the ones listed in red).

- Check your languages; when I got hit there was a second language installed that had to be deleted.

- Weird, but also check your "vBulletin is turned off" message. Not only did our templates get changed, but they turned off the site and replaced the 'turned off' message with a copy of the same HTML junk. The result was that even after restoring the templates and restoring access to the admin account, the site was still showing the HTML.

- If you're running a particular gallery app', upgrade it to the latest version. The issue was that files were able to be uploaded with a faked file extension resulting in a PHP file getting uploaded to the server. The vendor's support site also has a script to find suspect files that may have been uploaded.

- If you're not running a particular gallery app', check for other methods where a user may have uploaded a file to your server using some other add-on.

The big thing is really what non-Jelsoft add-ons you might be running to see if any of them may have been the culprit.
Reply With Quote
  #16  
Old 11-07-2008, 02:42 AM
terracore terracore is offline
 
Join Date: Dec 2007
Posts: 35
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

What was the gallery app that caused the problem. I might have the same problem.
Reply With Quote
  #17  
Old 02-10-2009, 08:11 PM
FleaBag's Avatar
FleaBag FleaBag is offline
 
Join Date: Dec 2001
Posts: 1,674
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hey KW802, sorry for so long checking back. I forgot about this thread. Until now, when I got hacked all over again x 2. Seriously, why me?

Thanks for the advice last time around, I do have a gallery app on one of the sites but not both. Not sure which one you mean but I don't think it is the problem.

I have few modified templates, but I found nothing suspicious within.

I can't remember now, but I think there may have been a modified language last time. I'll have to check it out again now.

I have a few mods installed, most of which are considered secure I guess, but I will have to review that again.

I think the only thing I didn't have up to date this time around was the latest PL1 of the blog. I hope that isn't the culprit. Silly me.

For anyone who wants to see the damage check the links in my sig. But again seriously, why me? I have nothing to do with this war they speak of. Give me a break.

Now to try and fix this all over again. And at least it's in english this time - now I know who to hate.
Reply With Quote
  #18  
Old 02-11-2009, 08:28 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by FleaBag View Post
I have a few mods installed, most of which are considered secure I guess, but I will have to review that again.
Is there anything that makes you so sure?
Reply With Quote
  #19  
Old 02-11-2009, 06:39 PM
FleaBag's Avatar
FleaBag FleaBag is offline
 
Join Date: Dec 2001
Posts: 1,674
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I guess because I've had them for years and never heard of any real problems. They only ones installed on both boards (and the only ones on board number 2 full stop) are GAB, Stop the Registration Bots, vBadvanced CMPS, vBSEO, vBSEO Sitemap Generator, vBStopForumSpam and vBulletin Blog.

I'm back in control again now, it seems I was exploited in exactly the same way as last time. I have a feeling they have compromised my WHM, so it's password changes all round.

Anyone know of any good apps to detect keyloggers? I don't wanna download malware by accident.

Any idea how I can view logs from WHM or from my server? I've never done logs before.
Reply With Quote
  #20  
Old 02-12-2009, 05:16 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by FleaBag View Post
Anyone know of any good apps to detect keyloggers? I don't wanna download malware by accident.
Make sure you have an effective virus scanner and scan your whole system (which do you have currently?).
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:29 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.11317 seconds
  • Memory Usage 2,259KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (4)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete