The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#21
|
||||
|
||||
Quote:
Get back ups of both your files and the db PRIOR to the hack. Contact your provider to make sure they wipe everything off your hosted server and DB. Upload backups and see if that helps. Most host providers can get backups, either through their interface or requesting... CHANGE all your passwords on your host, FTP, etc. DB pw etc, before uploading backup files, change config files to reflect. I would also force everyone on the site to put in a new pw, and I would change the admin pw... I would also check your htaccess files for code, redirects, etc... |
#22
|
|||
|
|||
Quote:
|
#23
|
|||
|
|||
As above..
Deleted EVERYTHING but the DB multiple times.. Removed install of course Changed all passwords Removed admins Removed the plugin.php Scanned for strange files.. And still back in last night --------------- Added [DATE]1379033803[/DATE] at [TIME]1379033803[/TIME] --------------- Who did you hire ?? |
#24
|
|||
|
|||
Well I bit the bullet and had my Host wipe the server and data base.
Time to start all over again ..... and once I have a clean site running with an empty db, I will try and import an older db backup. |
#25
|
|||
|
|||
I have so much time in site config.. templates.. RSS feeds.. Spam control.. VBSEO..
I have my backups.. But working from them still somehow leaves me open.. I really dont want to revert to a earlier database.. There has to be someone or a way that this can be cleaned up. |
#26
|
||||
|
||||
Quote:
--------------- Added [DATE]1379091231[/DATE] at [TIME]1379091231[/TIME] --------------- I have not tried this, but you could also do the same for db comparison... http://dbcomparer.com/ |
#27
|
|||
|
|||
Quote:
How do I access the tool mentioned in "Step 5: Removing unknown files" from the AdminCP? Never mind I think I found it. |
#28
|
|||
|
|||
Quote:
Ok, meldmerge sounds interesting, but what if you don't have a graphical UI on your server? |
#29
|
||||
|
||||
I have found two hackers hacked the admincp and added themselves as administrators, they only hacked my default style to link it to Syria. I have deleted the hackers, I bought Sitelock for one year and just need to find their crap in the default style.
--------------- Added [DATE]1379179783[/DATE] at [TIME]1379179783[/TIME] --------------- I found their crap in the forumhome of my default style. I copied the code from another working style and pasted over their crap. My site is back to normal now. I did delete the install folder as suggested and also changed my password and deleted all other admins. I found their two ip addresses and added them to the banned list. Good luck to everyone. Run you admin log to see what they did. |
#30
|
||||
|
||||
I would get a hold of a clean version of you entire root download it to your desktop, along with the corrupted files (entire root files) and compare the corrupted version to the clean version you have before the hack...
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|