Version: 1.0.2, by Onur
Developer Last Online: Apr 2015
Version: 3.5.4
Rating:
Released: 03-09-2006
Last Update: 05-15-2006
Installs: 84
Uses Plugins
Additional Files
No support by the author.
CrackerTracker
this is a port from the standalone system of the Cback.de CrackerTracker (was original made for phpBB) to an Product for vB
Description
this hack search in the requeststring for definied codeparts, is found any hit the skript was die and send a little massage
in addition of security this simply skript discharged the server by automatic attacks from botskripts if the definations have a hit in the requests
Instructions Install
upload the /elog/ directory and set the CHMOD of counter.txt and logfile_injects.txt to 666, this is only to log blocked requests
if you not want to have writeable files on youre server this hack works without logging too and you can leave this part
at last install the CrackerTracker100-product.xml
Update
uninstall product of v100
reinstall new product of v101
Uninstall
uninstall the CrackerTracker100-product.xml
upload thedelete /elog/ directory
Credits & Information
i have only port this hack to a Plugin
Authorof the Hack is Cback from www.cback.de
only restraint of Cback is the Copyright in the footer
(i hope my english was understandable )
History
10/03/06 Release 1.0.0
15/05/06 Release 1.0.1
new searchpattern and handfull old replaced
little codemodifications
15/05/06 Release 1.0.2
one typo in list (missing ",")
Show Your Support
This modification may not be copied, reproduced or published elsewhere without author's permission.
uninstall the product of the ct in the productmanager and the plugin is replaced with the copyright, if you have installed the plugincache(another hack here in the board) you have to regenerate the cache of the plugins too
to try if the product real uninstalled(only the 1 hook with code) open
youre-board.tld/index.php?fopen
if not come a message, the CT is uninstalled
I get this message..
Quote:
- th SECURITY ALERT -
The Board Security System has detected, that you wanted to bring bad
Code to this Forum or you have tried to exploit something here or maybe
another attack linke this.
This attempt was blocked and we logged all information about this.
If you see this message after including a new MOD to your Forum or if
you have reached this site over a normal Forum Link, please contact
the Board Administrator to fix this Problem.
@sensimilla
thats what i mean, it is not uninstalled
is it possible that you use this hack Plugin Accelerator
here the plugin was hardcoded in the boardfiles, after any change at the plugins you have to rebuild the whole plugincache (is an option near the pluginpart @acp)
vBulletin is pretty solid and I don't have much fear of my site being hacked. What I do fear is installing "third party" plugins that could leave my site wide open for attack.
For example, I've seen allot of people request a hack similar to vBulletin's bug tracker. The answer was vBug Tracker that has a known security hole since April of 2006 and it has yet to be updated by the author.
It is third party plugins that make vBulletin vulnerable and as a rule of thumb I always question the reputation of the developer.