Go Back   vb.org Archive > Community Discussions > Forum and Server Management
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 12-13-2009, 11:37 AM
Jeff G Jeff G is offline
 
Join Date: Mar 2008
Posts: 6
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default HELP!! Hacker keeps hacking site

Don't know how he is doing this & would like help if possible.

Hacker is from Hanoi, Vietnam got me twice so far, used different IP's

He creates a screen name & then he is able to log onto my admincp? How? All permissions are set for new users & the have no admincp access, but he does & give himself admin privileges! & then tosses code for streaming ads into my main forum page.

I have change name of admincp directory to a completely obscure name, is there anything else I can do besides that & ban his IP & email addresses?

Any help would be greatly appreciated.

I have checked all files via FTP & none have been changed, so he is doing this straight thru Vbulletin!!
Reply With Quote
  #2  
Old 12-13-2009, 01:09 PM
snakes1100 snakes1100 is offline
 
Join Date: Dec 2001
Location: Michigan
Posts: 3,733
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well, if you aren't running the latest version of vb then it's not vb's fault, i would suggest you upgrade it and any installed hacks on your site.

Then you need to upgrade your server's backend programs, sql, apache, php etc...

Next on the list would be to remove any other custom scripts mainly php based that you have added to your site, even if they arent vb related.

You should also check your server logs and see if there is any indication that he is doing a db injection.

Install some security while your at it, suhosin/apf etc.
Reply With Quote
  #3  
Old 12-13-2009, 02:16 PM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Along with making sure vBulletin is up-to-date, make sure all your modifications are up-to-date and don't run any modifications that have been graveyarded (they could have a security flaw in them).
Reply With Quote
  #4  
Old 12-14-2009, 05:41 PM
iHatton iHatton is offline
 
Join Date: Oct 2008
Posts: 57
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Read this, https://vborg.vbsupport.ru/showthread.php?t=220914
Reply With Quote
  #5  
Old 12-15-2009, 01:01 AM
motowebmaster motowebmaster is offline
 
Join Date: Feb 2006
Posts: 62
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

If the respective server has been compromised, it would be easy to "cover your tracks". An FTP program is not going to give you conclusive info.

Share you site's URL with some folks you trust, without that info it's anyone's guess as to what the issue is.
Reply With Quote
  #6  
Old 12-15-2009, 01:43 AM
Medtech's Avatar
Medtech Medtech is offline
 
Join Date: Oct 2007
Posts: 310
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

There are many ways to secure your forum, renaming the admincp is the first and easiest, i like to have a dummy admincp folder with an index.html file in it with a redirect to a really nasty site or the 404 page.
Reply With Quote
  #7  
Old 12-15-2009, 09:40 AM
Carnage Carnage is offline
 
Join Date: Jan 2005
Location: uk
Posts: 760
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

put a .htaccess file into the admin cp directory and setup password protected access.

See this: http://davidwalsh.name/password-prot...using-htaccess
Reply With Quote
  #8  
Old 12-16-2009, 02:17 PM
Black Tiger's Avatar
Black Tiger Black Tiger is offline
 
Join Date: Apr 2004
Location: Netherlands
Posts: 957
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

And be sure to use a good host. Not some kid or man who started a hosting company without any experience.
If the hacker keeps coming back, even when you change the admincp directoryname, they can read your config file. Some hosts have not provided decent protection on their servers, and if you know the location of the config file (which is always in /forums/includes with vBulletin) you can read it out via ssh or via a self made php file.
All the hacker needs is an account on the same server.
Reply With Quote
  #9  
Old 01-03-2010, 12:52 AM
daveaite's Avatar
daveaite daveaite is offline
 
Join Date: Jul 2009
Location: Florida
Posts: 1,890
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Medtech View Post
There are many ways to secure your forum, renaming the admincp is the first and easiest, i like to have a dummy admincp folder with an index.html file in it with a redirect to a really nasty site or the 404 page.

Haha, this is good stuff
Reply With Quote
  #10  
Old 01-04-2010, 12:39 PM
Princeton's Avatar
Princeton Princeton is offline
 
Join Date: Nov 2001
Location: Vineland, NJ
Posts: 6,693
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

if this continues, I suggest hiring someone with a good reputation to check your site
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:18 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04489 seconds
  • Memory Usage 2,249KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete