The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
I am running vB 3.5.2 on Linux (with a patch from 3.5.3 I believe). Yes, I need to upgrade.
Was hacked: -removed- Can you make suggestions to start? Thanks. No new users listed in the administrator with admin rights, but there is a suspicious high-ID entry in table VBADMINISTRATOR. blakespot Look at source for page now - last line: Code:
<table cellpadding="0" cellspacing="0" border="0"> <tr valign="bottom"> <td><a href="#" onclick="history.back(1); return false;"><img src="iSkin/misc/navbits_start.gif" alt="Go Back" border="0" /></a></td> <td> </td> <td width="100%"><span class="navbar"><a href="index.php?" accesskey="1">iPod Hacks Forums</a></span> <span class="navbar">> <a href="forumdisplay.php?f=1"><meta http-equiv='refresh' content='0; url=http://www.enyenimix.com/hacked.html'></a></span> blakespot |
#2
|
|||
|
|||
![]()
someone edited your forum title and replaced the text with a redirect...
that's the one thing you have to edit.. the forumid #10.. change its title. |
#3
|
|||
|
|||
![]() Quote:
Thoughts? Thanks. blakespot |
#4
|
|||
|
|||
![]()
this is what we call an exploit...
![]() |
#5
|
|||
|
|||
![]()
Also, I changed them back in the VBFORUM table, but the page still renders with the redirrects as the forum titles?! Is there some cache mechanism I must flush? Thanks.
blakespot |
#6
|
|||
|
|||
![]()
you have to edit it from the admincp, not the database... and to be sure, post a new thread in that forum so the cache is updated there too..
![]() |
#7
|
|||
|
|||
![]()
I can't edit it from the adminCP - the frame redirects to the hack site, as it renders the title as HTML, forcing a redirect... Can I not flush the cache another way? I've changed the names in the DB. Thanks.
Will but and upgrade to latest tonight... If I can get this clean first. blakespot |
#8
|
||||
|
||||
![]()
I would be more worried about how they edited the forum title in the first place...
Go into your database and remove the redirect, and then go into ACP > Maintenance > Update Counters > Rebuild Forum Information. |
#9
|
|||
|
|||
![]()
Thanks - I'll update tonight.
blakespot |
#10
|
|||
|
|||
![]()
Upgraded to 3.6.5. Hopefully that exploit was addressed. I see reports of a Calendar vulnerability of that sort, but can't find reference to a forum-title vulnerability...
blakespot |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|