Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 10-11-2012, 12:53 PM
WEBDosser's Avatar
WEBDosser WEBDosser is offline
 
Join Date: Oct 2001
Location: @ MyPC
Posts: 824
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Like i said you have a compromised file somewhere..
I tried all this:

Upload all new vbulletin files & clean up the database - no effect
Ok so then i thought i will htaccess the forum dir (password protect it) nope still loads of emails bouncing back.

Right i will htaccess the whole website, still nope still emails

Ok then lets close the website from inside admincp right? .. wrong still loads of emails.

All righty then i will remove all hacks and plungins even delete their files.. Nope! still emails

OK disable plugins in the config.php file.. nope nothing worked.

So then i started to think maybe it was my server so checked all the setting and found nothing wrong with the server, maybe a few brute force attacks but that was all..

By this time his email account on his website was being filled that much that i got server admin emails warning me that that user has sent umteen thousand and was reaching their limit.

So because it was for a friend and he was not bothered about the few posts on there he said i could delete and he would start a fresh.. WOW no more emails..

Hope it helps..
Reply With Quote
  #12  
Old 10-11-2012, 10:33 PM
doob doob is offline
 
Join Date: Dec 2009
Posts: 127
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Unfortunately a re-install isn't an option.

I'm working my way through logs but off the top don't see anything related to sendmessage.php or other obvious vbulletin php.

I do see a fair number of errors that look like the following, but googling suggests are comment spam, not php mail spam.

forums/index.php+++++++++++++++++++++++++++++++++++++Resu lt:+\xed\xe5+\xed\xe0\xf8\xeb\xee\xf1\xfc+\xf4\xee \xf0\xec\xfb+\xe4\xeb\xff+\xee\xf2\xef\xf0\xe0\xe2 \xea\xe8;+Result:+\xed\xe5+\xed\xe0\xf8\xeb\xee\xf 1\xfc+\xf4\xee\xf0\xec\xfb+\xe4\xeb\xff+\xee\xf2\x ef\xf0\xe0\xe2\xea\xe8;, referer: http://URLRemovedByDoob.com/index.ph...0%E0%E2%EA%E8;
Reply With Quote
  #13  
Old 10-11-2012, 10:42 PM
kh99 kh99 is offline
 
Join Date: Aug 2009
Location: Maine
Posts: 13,185
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You could also try looking through your plugins to see if you notice any that you don't recognize.
Reply With Quote
  #14  
Old 10-11-2012, 10:55 PM
doob doob is offline
 
Join Date: Dec 2009
Posts: 127
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I'm pretty sure its not a plugin problem.

I just ticked off "Allow Users to Email Other Members" under AdminCP->VbulletinUptions->Email Options.

I'll have to wait and see if that has any effect. Next step probably to disable Email Functions on that same page and switch to SMTP and see if that has any effect.

May also be forced, belatedly, to upgrade to current patch, however in googling around this seems to affect folks running versions well into the 4.1.x strata.
Reply With Quote
  #15  
Old 10-11-2012, 11:18 PM
kh99 kh99 is offline
 
Join Date: Aug 2009
Location: Maine
Posts: 13,185
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by doob View Post
I'm pretty sure its not a plugin problem.
You may be right, I don't know. But I have seen plugins that somehow got added that allowed hackers to do anything from any page by including parameters (and posted parameters don't go in the logs so you wouldn't see it there).

Edit: I should add that I don't have a lot of experienced with hacked sites or anything, I've just seen a few posts about it on the forum.
Reply With Quote
  #16  
Old 10-11-2012, 11:29 PM
doob doob is offline
 
Join Date: Dec 2009
Posts: 127
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I just ticked off "Enable Email features?" under Email Options as the next step in testing. This really isn't how I saw my day going.
Reply With Quote
  #17  
Old 10-11-2012, 11:37 PM
Simon Lloyd's Avatar
Simon Lloyd Simon Lloyd is offline
 
Join Date: Aug 2008
Location: Manchester
Posts: 3,481
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Have you checked for suspect files under admincp>maintainance>diagnostics to make sure all your core files are correct?
Reply With Quote
  #18  
Old 10-11-2012, 11:45 PM
doob doob is offline
 
Join Date: Dec 2009
Posts: 127
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for that sugg. I already checked. The only discrepencies are core files I edited myself.
Reply With Quote
  #19  
Old 10-12-2012, 12:43 AM
Simon Lloyd's Avatar
Simon Lloyd Simon Lloyd is offline
 
Join Date: Aug 2008
Location: Manchester
Posts: 3,481
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

So no files that you don't recognise then? check files outside of your forum root, you may have a file or two you don't recognise. Your server logs should show which file has been sending mail or accessed a hell of a lot.
Reply With Quote
  #20  
Old 10-12-2012, 01:25 AM
kh99 kh99 is offline
 
Join Date: Aug 2009
Location: Maine
Posts: 13,185
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Do you have "Use Mailqueue System" set to on? Not that that's a problem of course, but if you had lots of emails queued then the logs showing what happened could be a long way back, and also disabling the options might not immediately stop mail from going out (I don't know if turning off email features clears the queue, but there's no check for that when mail from the queue is being sent out). Also I don't know of there's a way in vb3 to see what's in the queue from the adminCP, but you could look at the mailqueue table directly.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:53 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04149 seconds
  • Memory Usage 2,252KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete