The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#11
|
|||
|
|||
![]()
Okay, just making sure.
Check your templates, or even download a new template. He might have accessed that somehow, it happens. |
#12
|
||||
|
||||
![]()
You the vBulletin police?
![]() As mentioned I can't access the ACP. |
#13
|
||||
|
||||
![]() Quote:
Quote:
![]() Fleabag: Are you comfortable working directly with the MySQL tables using a tool like myPHPAdmin or similar? |
#14
|
||||
|
||||
![]()
Sure Kevin, I've done a bit of modifying in the past. I'd considered altering the password field directly but I don't know how to encrypt the value adequately.
But to answer the question, yes I can do that. ![]() Thanks again by the way, you've come to my rescue in the past on a few occasions, and it's appreciated. EDIT: OK as an update I managed to use tools.php to reset the style settings and it seems it was indeed altered at the template level. That's fixed at least, but I guess I wiped out any trace of how it was done. There are a lot of weird registrations too... EDIT 2: I've managed to log in using my old/current admin password. I was greeted by a screen telling me my password is 219 days old and needs to be updated. The screen seemed to refresh when it first loaded. EDIT 3: Upgraded to latest version... Trying to make sure everything is locked down now. Thanks for the input guys. I just need to work out what happened now. |
#15
|
||||
|
||||
![]()
Sorry for the delay... I was on the road home from work. If you're still interested in the SQL item, I'll follow up via PM.
The site I got hit with was done via an older version of a certain gallery software application that did not properly check file extensions and a malicious PHP script ended up on the server. It sounds like you got hit with either the same script or something similar. - Check all of your modified templates. Some of the big ones, like forumhome were easy enough to tell that it got hit but I found out a day later that some others were hit as well. No fast way of doing this other than going into Style Manager, expanding the views, and checking all of the templates that were modified (the ones listed in red). - Check your languages; when I got hit there was a second language installed that had to be deleted. - Weird, but also check your "vBulletin is turned off" message. Not only did our templates get changed, but they turned off the site and replaced the 'turned off' message with a copy of the same HTML junk. The result was that even after restoring the templates and restoring access to the admin account, the site was still showing the HTML. - If you're running a particular gallery app', upgrade it to the latest version. The issue was that files were able to be uploaded with a faked file extension resulting in a PHP file getting uploaded to the server. The vendor's support site also has a script to find suspect files that may have been uploaded. - If you're not running a particular gallery app', check for other methods where a user may have uploaded a file to your server using some other add-on. The big thing is really what non-Jelsoft add-ons you might be running to see if any of them may have been the culprit. |
#16
|
|||
|
|||
![]()
What was the gallery app that caused the problem. I might have the same problem.
|
#17
|
||||
|
||||
![]()
Hey KW802, sorry for so long checking back. I forgot about this thread. Until now, when I got hacked all over again x 2. Seriously, why me?
Thanks for the advice last time around, I do have a gallery app on one of the sites but not both. Not sure which one you mean but I don't think it is the problem. I have few modified templates, but I found nothing suspicious within. I can't remember now, but I think there may have been a modified language last time. I'll have to check it out again now. I have a few mods installed, most of which are considered secure I guess, but I will have to review that again. I think the only thing I didn't have up to date this time around was the latest PL1 of the blog. I hope that isn't the culprit. Silly me. For anyone who wants to see the damage check the links in my sig. But again seriously, why me? I have nothing to do with this war they speak of. Give me a break. Now to try and fix this all over again. And at least it's in english this time - now I know who to hate. |
#18
|
||||
|
||||
![]()
Is there anything that makes you so sure?
|
#19
|
||||
|
||||
![]()
I guess because I've had them for years and never heard of any real problems. They only ones installed on both boards (and the only ones on board number 2 full stop) are GAB, Stop the Registration Bots, vBadvanced CMPS, vBSEO, vBSEO Sitemap Generator, vBStopForumSpam and vBulletin Blog.
I'm back in control again now, it seems I was exploited in exactly the same way as last time. I have a feeling they have compromised my WHM, so it's password changes all round. Anyone know of any good apps to detect keyloggers? I don't wanna download malware by accident. ![]() Any idea how I can view logs from WHM or from my server? I've never done logs before. |
#20
|
||||
|
||||
![]()
Make sure you have an effective virus scanner and scan your whole system (which do you have currently?).
|
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|