Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 09-11-2013, 01:20 PM
Phat Phreddy Phat Phreddy is offline
 
Join Date: May 2013
Posts: 10
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Doing my head in.. Restored a full clean backup 3 times.. removed install.. Deleted admins.. Changed PWs..

Still it keeps coming back..

If the files are from a week ago, and hence clean.. what can there be to cleanup ??

What can forum logs show me ?? How can I look at how this is happening ??
Reply With Quote
  #12  
Old 09-11-2013, 06:51 PM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Would running your site through http://sitecheck.sucuri.net/scanner/ help? Might find the malware file. Also, have you checked your htaccess in root?
Reply With Quote
  #13  
Old 09-11-2013, 07:00 PM
pjkcards pjkcards is offline
 
Join Date: Jul 2007
Posts: 299
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I hired someone in the paid forum to fix it. Took them quite awhile to fix it, and the styles are now messed up. Apparently it isn't an easy fix.
Reply With Quote
  #14  
Old 09-12-2013, 01:40 AM
Phat Phreddy Phat Phreddy is offline
 
Join Date: May 2013
Posts: 10
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pjkcards View Post
I hired someone in the paid forum to fix it. Took them quite awhile to fix it, and the styles are now messed up. Apparently it isn't an easy fix.
I am assuming you mean fixing it when you didnt have a file system backup ??
Reply With Quote
  #15  
Old 09-12-2013, 11:14 AM
teamemmenracing teamemmenracing is offline
 
Join Date: Apr 2007
Posts: 13
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have a similar re-direct as of yesterday, only mine is to
http://www.cadiroig.cat/downalert.html

I have spent hours following instructions,, have re-installed files etc removed directories, I even deleted all files on the server and up loaded last months back up ...... which makes me wonder if it is the database that has been attacked.

I have found this unauthorised visit ......

20749 N/A 04:05, 10th Sep 2013 notice.php modify 91.144.37.46
20748 N/A 04:04, 10th Sep 2013 notice.php update 91.144.37.46
20747 N/A 04:04, 10th Sep 2013 notice.php add 91.144.37.46


........ but even replacing the notice.php with a newly downloaded version doesn't help.

Im kind of hoping that as hundreds of sites have been affected that someone might have found a common fix .....

anybody have any ideas ?
Reply With Quote
  #16  
Old 09-12-2013, 11:24 AM
Phat Phreddy Phat Phreddy is offline
 
Join Date: May 2013
Posts: 10
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You got the added admins ??

Also make sure you change admin PW, FTP and MySQL passwords ??
Reply With Quote
  #17  
Old 09-12-2013, 11:47 AM
TheLastSuperman's Avatar
TheLastSuperman TheLastSuperman is offline
Senior Member
 
Join Date: Sep 2008
Location: North Carolina
Posts: 5,844
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by teamemmenracing View Post
I have a similar re-direct as of yesterday, only mine is to
http://www.cadiroig.cat/downalert.html

I have spent hours following instructions,, have re-installed files etc removed directories, I even deleted all files on the server and up loaded last months back up ...... which makes me wonder if it is the database that has been attacked.

I have found this unauthorised visit ......

20749 N/A 04:05, 10th Sep 2013 notice.php modify 91.144.37.46
20748 N/A 04:04, 10th Sep 2013 notice.php update 91.144.37.46
20747 N/A 04:04, 10th Sep 2013 notice.php add 91.144.37.46


........ but even replacing the notice.php with a newly downloaded version doesn't help.

Im kind of hoping that as hundreds of sites have been affected that someone might have found a common fix .....

anybody have any ideas ?
Ladies and Gentlemen, there is no "added fix" let me clear up some misconceptions here:
  • Most of the sites hacked recently still had their /install/ folder present on the site, its the exploit mentioned here - http://www.vbulletin.com/forum/forum...-1-vbulletin-5
  • A security bulletin email was also sent out, you should have received one and followed instructions promptly. *Always ensure you're receiving vBulletin emails and eBulletins/any and all mail from vBulletin.com needs to bypass your spam filters and others and be in your inbox and able to be read each and every time and you need to read these emails as apparently they are important!
  • If you restore a backup of the database prior to being hacked, you must restore a backup of the files from that time as well otherwise a file may have been modified still allowing access. Is it just vBulletin files to overwrite? Well you certainly need to overwrite the vBulletin files with 100% fresh files AND any others you find that were modified, if you find a suspect file such as lol.php or sexy.php or even owned.html basically anything that does not belong should be deleted, run suspect file versions from the admincp maintenance area to check vBulletin related files.
  • Follow the links that myself and Zachery have been posting in countless threads, the links to his blog, mine and other links we post are to blogs and articles that provide detailed instructions including various ways to test and ways to fix.

Here are the links again:
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site
http://www.vbulletin.com/forum/blogs...vbulletin-site

So to be perfectly clear, there is no "automatic" fix, no upload this and run it then your done and site secure... it is this simple:

1) Restore a complete backup (database and filesystem, the backups need to be from before the hacker made changes and had access) then once restored promptly delete the /install/ folder and at this time check your version, patch to the most recent patch # of your version OR upgrade to a more secure version i.e. 4.1.5 --> 4.2.1

- OR -

2) If no backup is available, using the links provided above you must manually clean your site. Check the database and filesystem for modified files and be very thorough to ensure nothing slips past you and remains in place for example if a shell script is left on the server or a spare admin account then you're still vulnerable and the site can be exploited/defaced again.

If you're unsure about something and need a clarification do not hesitate to post and ask, if you feel its a stupid question well then its not, no question is stupid unless your specifically being silly when you ask it and even then it ends up being a silly question instead lol. Ask questions now and receive helpful replies that may assist you in cleaning your site and returning to business as usual .
Reply With Quote
2 благодарности(ей) от:
CAG CheechDogg, ozzy47
  #18  
Old 09-12-2013, 01:23 PM
joeychgo's Avatar
joeychgo joeychgo is offline
 
Join Date: Mar 2004
Location: Chicago, IL
Posts: 933
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I strongly recommend forum owners sign up with Securi.

They have done a great job for me and I use them on all my forums.




.
Reply With Quote
  #19  
Old 09-12-2013, 05:45 PM
lapiervb lapiervb is offline
 
Join Date: Mar 2010
Posts: 249
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by joeychgo View Post
I strongly recommend forum owners sign up with Securi.

They have done a great job for me and I use them on all my forums.




.
You need to stop pushing this as you are losing any credibilty the site may have had and it is against the rules here to have your affiliate link in a post.
Reply With Quote
  #20  
Old 09-12-2013, 06:33 PM
teamemmenracing teamemmenracing is offline
 
Join Date: Apr 2007
Posts: 13
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

................... well I have tried everything and its still there.
worst of all, when I try to copy files back to my computer, they are all password protected and I cant access them.

Finally I went to my host and deleted everything from the server ........ except the database, then loaded new files that I just downloaded from the vbulletin members area ......

and from nowhere this file appears .....

zdberrb4476bf0aed19d1e05964d0757f51.dat

it doesn't look legit, I managed to open it up and the only contents were a number .....

13790115241146

Im thinking I now have a server problem .....

any ideas ?
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:36 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04853 seconds
  • Memory Usage 2,267KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (10)post_thanks_box
  • (2)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete