Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 12-11-2009, 02:12 PM
daveaite's Avatar
daveaite daveaite is offline
 
Join Date: Jul 2009
Location: Florida
Posts: 1,890
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default My website contiunes to get hacked

I have been continually getting hacked over the past month. I've rolled back my server followed

https://vborg.vbsupport.ru/showthrea...securing+forum

by password protecting:
admincp/
modcp/
includes/
install/

renaming modcp/
admincp/

making myself an undeletable user

-reformatted my pc to prevent any viruses

They either change my index files around and brag about their hacking abilities ot they delete the entire contents of my public_html
----------------
What should I do? I have no clue how they are getting into my system. I've changed the cpanel password a ton of times. Maybe attachments entry?

About them?
Some arabic group

Tips? Help please.
Reply With Quote
  #2  
Old 12-11-2009, 02:20 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Are you on a shared webserver? Have you talked to your host about this? Have you looked at your access_logs to see if anything is in there regarding the hacking?
Reply With Quote
  #3  
Old 12-11-2009, 02:27 PM
daveaite's Avatar
daveaite daveaite is offline
 
Join Date: Jul 2009
Location: Florida
Posts: 1,890
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have talked to my web hosting. I feel like I've been bothering them too much lately by asking them to continually roll it back. It is on a shared hosting which makes me a bit worried, maybe it's time to switch...although I did buy 3 years of hosting.

They actually went ahead and changed the cpanel password for me, and it got defaced the next day.

This may be a coincidence but it started happening after I upgraded to vbulletin 4.0. I know its in beta, and I used to have this mod which now I think prevented this from happening: https://vborg.vbsupport.ru/showthrea...light=firewall
Reply With Quote
  #4  
Old 12-11-2009, 02:40 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I doubt they are hacking through v4 but if you look at the access_logs, you could verify that. Shared hosting is not as secure as having your own server. But, I'm no server expert, so I really can't offer much advise here.
Reply With Quote
  #5  
Old 12-11-2009, 03:48 PM
abdobasha2004's Avatar
abdobasha2004 abdobasha2004 is offline
 
Join Date: Aug 2008
Posts: 541
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
What should I do? I have no clue how they are getting into my system
it is a possibly a root shell on one of your vbulletin or website files

1- download a backup of your site
2- scan this backup by a powerful anti - virus (for me avira antivirus can do it)
3- your anti virus will detect the shell and will notify you with its path.
4- if you are sure that the file is not important delete it, otherwise open it and remove the shell (most propably coded text) , or just rewrite the file from a clean vbulletin version
5- make sure that there is no other files

best wishes
Reply With Quote
  #6  
Old 12-11-2009, 07:03 PM
daveaite's Avatar
daveaite daveaite is offline
 
Join Date: Jul 2009
Location: Florida
Posts: 1,890
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for the quick feedback. I'll look into the virus scan method.
Reply With Quote
  #7  
Old 12-11-2009, 07:29 PM
Matais Matais is offline
 
Join Date: Jan 2008
Posts: 47
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

you have checked out your end haven't you?

could have a keylogger, spyware etc.

also what version of vbulletin are you on?
Reply With Quote
  #8  
Old 12-13-2009, 10:36 AM
Speysider's Avatar
Speysider Speysider is offline
 
Join Date: Apr 2009
Posts: 1,029
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Matais View Post
also what version of vbulletin are you on?
See post #3, he says vBulletin 4 Beta.
Reply With Quote
  #9  
Old 12-13-2009, 11:13 AM
Carnage Carnage is offline
 
Join Date: Jan 2005
Location: uk
Posts: 760
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

on shared hosting ensure that config.php is NOT world readable.

In an ftp client you may see options for user, group and other permissions. Turn off all the permissions belonging to 'other'
Reply With Quote
  #10  
Old 12-14-2009, 07:22 PM
CarlitoBrigante's Avatar
CarlitoBrigante CarlitoBrigante is offline
 
Join Date: Nov 2002
Location: Iceland
Posts: 182
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

There is little doubt you have some backdoor installed in your system, or that you have some modification that works as a back door.

Make also sure, in case you have it installed, that vBSEO is upgraded to the latest package. 3.3.2 release needs to be re-upgraded as there was a security patch a while ago which did not cause a version number change.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 05:52 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04551 seconds
  • Memory Usage 2,251KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete