The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
My website contiunes to get hacked
I have been continually getting hacked over the past month. I've rolled back my server followed
https://vborg.vbsupport.ru/showthrea...securing+forum by password protecting: admincp/ modcp/ includes/ install/ renaming modcp/ admincp/ making myself an undeletable user -reformatted my pc to prevent any viruses They either change my index files around and brag about their hacking abilities ot they delete the entire contents of my public_html ---------------- What should I do? I have no clue how they are getting into my system. I've changed the cpanel password a ton of times. Maybe attachments entry? About them? Some arabic group Tips? Help please. |
#2
|
||||
|
||||
Are you on a shared webserver? Have you talked to your host about this? Have you looked at your access_logs to see if anything is in there regarding the hacking?
|
#3
|
||||
|
||||
I have talked to my web hosting. I feel like I've been bothering them too much lately by asking them to continually roll it back. It is on a shared hosting which makes me a bit worried, maybe it's time to switch...although I did buy 3 years of hosting.
They actually went ahead and changed the cpanel password for me, and it got defaced the next day. This may be a coincidence but it started happening after I upgraded to vbulletin 4.0. I know its in beta, and I used to have this mod which now I think prevented this from happening: https://vborg.vbsupport.ru/showthrea...light=firewall |
#4
|
||||
|
||||
I doubt they are hacking through v4 but if you look at the access_logs, you could verify that. Shared hosting is not as secure as having your own server. But, I'm no server expert, so I really can't offer much advise here.
|
#5
|
||||
|
||||
Quote:
1- download a backup of your site 2- scan this backup by a powerful anti - virus (for me avira antivirus can do it) 3- your anti virus will detect the shell and will notify you with its path. 4- if you are sure that the file is not important delete it, otherwise open it and remove the shell (most propably coded text) , or just rewrite the file from a clean vbulletin version 5- make sure that there is no other files best wishes |
#6
|
||||
|
||||
Thanks for the quick feedback. I'll look into the virus scan method.
|
#7
|
|||
|
|||
you have checked out your end haven't you?
could have a keylogger, spyware etc. also what version of vbulletin are you on? |
#8
|
||||
|
||||
See post #3, he says vBulletin 4 Beta.
|
#9
|
|||
|
|||
on shared hosting ensure that config.php is NOT world readable.
In an ftp client you may see options for user, group and other permissions. Turn off all the permissions belonging to 'other' |
#10
|
||||
|
||||
There is little doubt you have some backdoor installed in your system, or that you have some modification that works as a back door.
Make also sure, in case you have it installed, that vBSEO is upgraded to the latest package. 3.3.2 release needs to be re-upgraded as there was a security patch a while ago which did not cause a version number change. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|