Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 06-23-2009, 07:01 AM
musado1961 musado1961 is offline
 
Join Date: Apr 2009
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default vBulletin 3.8.3 exploit?

Hi

Yesterday my hosting company [servage.net] suspended my account due to the forum/misc.php taking over 2.5 million hits and putting undue load on the shared server.

It's a small forum [under 70 members], and pretty quiet, and ONY visible to the to Registered Members. Registration is closed, so all anyone will see is the login page.

I have the CYB Advanced Statistics installed which refreshes every 30 secs, but surely that wouldn't generate over 2.5 million hits?

From talking to some other vBulletin users I've been informed that this may be some form of attack called "teardropping"?

Now, the hosting company are being a real PITA & refuse to re-instate my account till I take the necessary action [according to them change the problem with the misc.php script!]

However, I cant do anything because they've locked out my ftp access as well!

Anyone got any ideas/suggestions as to what may have caused the HUGE amount of hits on the misc.php & how to solve it?

TIA
Reply With Quote
  #2  
Old 06-23-2009, 07:13 AM
Oblivion Knight's Avatar
Oblivion Knight Oblivion Knight is offline
 
Join Date: May 2002
Location: Sheffield, UK
Posts: 1,757
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You'd probably be better asking at vbulletin.com, sounds like some kind of attack..

Do you have any other modifications installed that use misc.php?
Reply With Quote
  #3  
Old 06-23-2009, 08:06 AM
musado1961 musado1961 is offline
 
Join Date: Apr 2009
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Just CYB - Advanced Forum Rules and CYB - Chatbox..but I've never had a problem like this in the 2 months I've been using the CYB mods
Reply With Quote
  #4  
Old 06-23-2009, 12:07 PM
BlueNinjaGo's Avatar
BlueNinjaGo BlueNinjaGo is offline
 
Join Date: Mar 2009
Posts: 668
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

My suggestion: change hosts.
Reply With Quote
  #5  
Old 06-23-2009, 12:11 PM
Oblivion Knight's Avatar
Oblivion Knight Oblivion Knight is offline
 
Join Date: May 2002
Location: Sheffield, UK
Posts: 1,757
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Any form of shoutbox / chatbox is notoriously bad for server resources..

A few hosts that I know of have effectively banned their use.
Reply With Quote
  #6  
Old 06-23-2009, 12:32 PM
Carnage Carnage is offline
 
Join Date: Jan 2005
Location: uk
Posts: 760
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Can you get the apache logs from the host?

Might be helpful to see what was being requested -> ips could be matched to forum users in your db; see if it was regular usage or some form of attack.
Reply With Quote
  #7  
Old 06-23-2009, 12:35 PM
musado1961 musado1961 is offline
 
Join Date: Apr 2009
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Oblivion Knight View Post
Any form of shoutbox / chatbox is notoriously bad for server resources..

A few hosts that I know of have effectively banned their use.
Till yesterday I'd never had any issues with the CYB mods & dont believe they are at fault. The chatbox in particular has never caused any issues whatsoever before.

The sudden jump to over 2.5 million hits seems like some form of exploit against my forum

Thanks for the replies so far guys

--------------- Added [DATE]1245764474[/DATE] at [TIME]1245764474[/TIME] ---------------

Quote:
Originally Posted by Carnage- View Post
Can you get the apache logs from the host?

Might be helpful to see what was being requested -> ips could be matched to forum users in your db; see if it was regular usage or some form of attack.
I wish!

That's the 1st thing I requested from Servage & got fobbed off with allsorts of ridiculous excuses
Reply With Quote
  #8  
Old 06-23-2009, 12:50 PM
TNCclubman's Avatar
TNCclubman TNCclubman is offline
 
Join Date: Sep 2008
Posts: 690
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

r u on a dedicated server? If you're on a shared server, thats probably why they dont want to give you the logs.

Unfortunately, unless you're on a dedicated box, you're not considered a priority and you're going to get treated like caca. Change hosts or go dedicated.
Reply With Quote
  #9  
Old 06-23-2009, 12:57 PM
musado1961 musado1961 is offline
 
Join Date: Apr 2009
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It's a shared server & I fully intend to change hosts if I can find a decent [if there is such a thing] european host.

I've had nothing but problems with Servage from day 1
Reply With Quote
  #10  
Old 06-23-2009, 01:02 PM
TNCclubman's Avatar
TNCclubman TNCclubman is offline
 
Join Date: Sep 2008
Posts: 690
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

There are no known exploits for vB 3.8.3... post your problems re: hacing on cyb's mods post. See if anyone can figure it out...
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 08:40 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04208 seconds
  • Memory Usage 2,252KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete