Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 Programming Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 10-10-2007, 07:57 PM
shahin531 shahin531 is offline
 
Join Date: Nov 2005
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Our site has been hacked -please help us urgently

Hi all.
Please advise me about this problem.
Our website has been hacked.
Our site has two admin account, and the hacker reset one of account and hack our site . then we restore the site by another admin account .
Any way I don’t know what happening when I go to the cpanel for editing the forums, I saw all of the forums name is the same as hacker name!!!
Also in the forums description this code is exist “<script>location.href="http://kamy4r.persiangig.com/xmors.htm";</script>”
So when all of the topics and forums redirect to the above link.
Pls note that I totally change (new) the following files and I sure that these files don’t have any problem:
config.php
index.php
.htaccess

Please help us , what should we do .

Thank you in advance.
Reply With Quote
  #2  
Old 10-10-2007, 08:30 PM
EnIgMa1234 EnIgMa1234 is offline
 
Join Date: Mar 2006
Location: .:: Ireland ::.
Posts: 1,306
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Change all passwords e.g all admin accounts, cpanel, ftp

Also .htaccess the admincp
There should be an option in cpanel (password protect directories)
Reply With Quote
  #3  
Old 10-11-2007, 12:41 AM
DivisionByZero's Avatar
DivisionByZero DivisionByZero is offline
 
Join Date: Dec 2002
Location: South Bend, Indiana
Posts: 485
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

also, if you're personally prone to these attacks, it may not be a bad idea to do an hourly backup of your database!!!
Reply With Quote
  #4  
Old 10-11-2007, 04:36 AM
shahin531 shahin531 is offline
 
Join Date: Nov 2005
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

thanks.i have been changed all the password.but how about the forums , the name and description of all forums changed to:
“<script>location.href="http://kamy4r.persiangig.com/xmors.htm";</script>”
and we redirected to this link . what should we do and how we can modify the forums name and description as before ? we strongly beleive that the hacker put above link into one of the main file(or settings) of our site.
waiting for your advise.
thanks.
Reply With Quote
  #5  
Old 10-11-2007, 04:46 AM
SCRIPT3R SCRIPT3R is offline
 
Join Date: Jan 2005
Posts: 1,303
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

what version of vB are you using?
Reply With Quote
  #6  
Old 10-11-2007, 05:31 AM
Freesteyelz's Avatar
Freesteyelz Freesteyelz is offline
 
Join Date: Jan 2006
Posts: 1,552
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Check your headerinclude and header templates. Unless you know for sure that the person did not access via server check for any additional files/scripts that you did not upload/edit yourself. 1) Can you not re-edit the forum names and descriptions via Admin CP? 2) Also, did you say that when clicking topics the links will take you to the person's site?

Go To:
In Admin CP, at the left-hand navigation, go to Statistics & Logs --> Control Panel Logs --> Control Panel Log Viewer --> View

*Check any entries made other than you. Snag the IP(s) if any and look at the files that were edited. More likely if the person gained access via Admin CP he/she did not consider pruning those entries.
Reply With Quote
  #7  
Old 10-11-2007, 09:37 PM
shahin531 shahin531 is offline
 
Join Date: Nov 2005
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Freesteyelz View Post
Check your headerinclude and header templates. Unless you know for sure that the person did not access via server check for any additional files/scripts that you did not upload/edit yourself. 1) Can you not re-edit the forum names and descriptions via Admin CP? 2) Also, did you say that when clicking topics the links will take you to the person's site?

Go To:
In Admin CP, at the left-hand navigation, go to Statistics & Logs --> Control Panel Logs --> Control Panel Log Viewer --> View

*Check any entries made other than you. Snag the IP(s) if any and look at the files that were edited. More likely if the person gained access via Admin CP he/she did not consider pruning those entries.
thank you.
i checked the address. but contol panel log viewer in restricted access in our site . ("Control Panel log viewing restricted.") do you have any other solution?

--------------- Added at 22:41 ---------------

Quote:
Originally Posted by GearTripper View Post
what version of vB are you using?
3.6.7
Reply With Quote
  #8  
Old 10-11-2007, 09:59 PM
EnIgMa1234 EnIgMa1234 is offline
 
Join Date: Mar 2006
Location: .:: Ireland ::.
Posts: 1,306
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Add your userid to config.php

Can view admincp log.
Reply With Quote
  #9  
Old 10-11-2007, 10:39 PM
vertigo jones vertigo jones is offline
 
Join Date: May 2007
Posts: 70
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Make sure to search your templates for "persiangig", "kamy4r", ".com" or anything else that might lead you to them and remove it. You never know what kind of javascript they've included without you knowing.

But yea, most importantly change your password, .htaccess protect your admincp, and change the name of the admincp directory.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 09:49 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05489 seconds
  • Memory Usage 2,240KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (9)post_thanks_box
  • (9)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (9)post_thanks_postbit_info
  • (9)postbit
  • (9)postbit_onlinestatus
  • (9)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete