Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #21  
Old 09-12-2013, 06:47 PM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by teamemmenracing View Post
................... well I have tried everything and its still there.
worst of all, when I try to copy files back to my computer, they are all password protected and I cant access them.

Finally I went to my host and deleted everything from the server ........ except the database, then loaded new files that I just downloaded from the vbulletin members area ......

and from nowhere this file appears .....

zdberrb4476bf0aed19d1e05964d0757f51.dat

it doesn't look legit, I managed to open it up and the only contents were a number .....

13790115241146

Im thinking I now have a server problem .....

any ideas ?



Get back ups of both your files and the db PRIOR to the hack. Contact your provider to make sure they wipe everything off your hosted server and DB. Upload backups and see if that helps. Most host providers can get backups, either through their interface or requesting...

CHANGE all your passwords on your host, FTP, etc. DB pw etc, before uploading backup files, change config files to reflect. I would also force everyone on the site to put in a new pw, and I would change the admin pw...


I would also check your htaccess files for code, redirects, etc...
Reply With Quote
  #22  
Old 09-12-2013, 11:29 PM
xenite xenite is offline
 
Join Date: Oct 2005
Posts: 33
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by teamemmenracing View Post
I have a similar re-direct as of yesterday, only mine is to
http://www.cadiroig.cat/downalert.html

I have spent hours following instructions,, have re-installed files etc removed directories, I even deleted all files on the server and up loaded last months back up ...... which makes me wonder if it is the database that has been attacked.
Login to your ADMINCP and go to NOTICES. You should find it there. Just delete the notice. Then delete the admin account.
Reply With Quote
  #23  
Old 09-12-2013, 11:32 PM
Phat Phreddy Phat Phreddy is offline
 
Join Date: May 2013
Posts: 10
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

As above..

Deleted EVERYTHING but the DB multiple times..

Removed install of course
Changed all passwords
Removed admins
Removed the plugin.php
Scanned for strange files..

And still back in last night

--------------- Added [DATE]1379033803[/DATE] at [TIME]1379033803[/TIME] ---------------

Quote:
Originally Posted by pjkcards View Post
I hired someone in the paid forum to fix it. Took them quite awhile to fix it, and the styles are now messed up. Apparently it isn't an easy fix.
Who did you hire ??
Reply With Quote
  #24  
Old 09-13-2013, 05:23 AM
teamemmenracing teamemmenracing is offline
 
Join Date: Apr 2007
Posts: 13
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well I bit the bullet and had my Host wipe the server and data base.

Time to start all over again ..... and once I have a clean site running with an empty db, I will try and import an older db backup.
Reply With Quote
  #25  
Old 09-13-2013, 06:18 AM
Phat Phreddy Phat Phreddy is offline
 
Join Date: May 2013
Posts: 10
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have so much time in site config.. templates.. RSS feeds.. Spam control.. VBSEO..

I have my backups.. But working from them still somehow leaves me open..

I really dont want to revert to a earlier database.. There has to be someone or a way that this can be cleaned up.
Reply With Quote
  #26  
Old 09-13-2013, 03:51 PM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Phat Phreddy View Post
I have so much time in site config.. templates.. RSS feeds.. Spam control.. VBSEO..

I have my backups.. But working from them still somehow leaves me open..

I really dont want to revert to a earlier database.. There has to be someone or a way that this can be cleaned up.
Here is an idea. Take your CLEAN backup (with all your mods) and if you have a copy of the corrupted files (hacked) compare them in Meld http://meldmerge.org/ opensource software. See if it flags certain files and folder, and look into those...

--------------- Added [DATE]1379091231[/DATE] at [TIME]1379091231[/TIME] ---------------

I have not tried this, but you could also do the same for db comparison...

http://dbcomparer.com/
Reply With Quote
  #27  
Old 09-14-2013, 10:25 AM
sr20de_99 sr20de_99 is offline
 
Join Date: Mar 2012
Posts: 14
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zachery View Post
Please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked
...

How do I access the tool mentioned in "Step 5: Removing unknown files" from the AdminCP?

Never mind I think I found it.
Reply With Quote
  #28  
Old 09-14-2013, 02:02 PM
tnedator tnedator is offline
 
Join Date: Aug 2007
Posts: 43
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pityocamptes View Post
Here is an idea. Take your CLEAN backup (with all your mods) and if you have a copy of the corrupted files (hacked) compare them in Meld http://meldmerge.org/ opensource software. See if it flags certain files and folder, and look into those...

--------------- Added [DATE]1379091231[/DATE] at [TIME]1379091231[/TIME] ---------------

I have not tried this, but you could also do the same for db comparison...

http://dbcomparer.com/

Ok, meldmerge sounds interesting, but what if you don't have a graphical UI on your server?
Reply With Quote
  #29  
Old 09-14-2013, 03:23 PM
bremereric's Avatar
bremereric bremereric is offline
 
Join Date: Aug 2011
Location: Tomball Texas
Posts: 203
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have found two hackers hacked the admincp and added themselves as administrators, they only hacked my default style to link it to Syria. I have deleted the hackers, I bought Sitelock for one year and just need to find their crap in the default style.

--------------- Added [DATE]1379179783[/DATE] at [TIME]1379179783[/TIME] ---------------

I found their crap in the forumhome of my default style. I copied the code from another working style and pasted over their crap. My site is back to normal now. I did delete the install folder as suggested and also changed my password and deleted all other admins. I found their two ip addresses and added them to the banned list. Good luck to everyone. Run you admin log to see what they did.
Reply With Quote
  #30  
Old 09-15-2013, 02:39 AM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by tnedator View Post
Ok, meldmerge sounds interesting, but what if you don't have a graphical UI on your server?
I would get a hold of a clean version of you entire root download it to your desktop, along with the corrupted files (entire root files) and compare the corrupted version to the clean version you have before the hack...
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:40 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04712 seconds
  • Memory Usage 2,264KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (7)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (3)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete