Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 03-01-2010, 10:15 PM
cammot cammot is offline
 
Join Date: Jul 2009
Posts: 18
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Site Attacked

I need some urgent help. It seems that my vB4 suite site has been attacked by a hacker. What has happened is that a new section has been added to the list of sections on my home page. The new section is an advertisement with some profanity on it. Clearly, who ever did this may have had access to my CP, and add the new sections.

Aside from trying to determine how this might have happened, I am unable to delete the section becasue there is no 'delete icon' next to it. I am however, able to block the viewing on the front end of this specific section, by removing all the permissions except to the administrator.

I recently updated the latest patch 4.0.2 so not sure how this has occured, and how to prevent it from continuing - and also removing the section.

Any help would be greatly appreciated.

cammot
Reply With Quote
  #2  
Old 03-01-2010, 11:47 PM
ChopSuey ChopSuey is offline
 
Join Date: Jun 2009
Location: Alaska
Posts: 2,140
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

One big tip about running a forum "Always use strong passwords"

Thats how he got to your AdminCP
Reply With Quote
  #3  
Old 03-02-2010, 01:28 AM
cammot cammot is offline
 
Join Date: Jul 2009
Posts: 18
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I agree with the need for strong passwords, which I have. But it's an assumption on your part to suggest that's the only way a hacker can infiltrate a site. That's why they discover security holes from time to time, and releases security patches.

cammot
Reply With Quote
  #4  
Old 03-02-2010, 03:13 AM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You cannot delete the section until you have removed all the articles from it.

Check your access_logs and see if you can determine how they got in.
Reply With Quote
  #5  
Old 03-03-2010, 08:00 PM
mrt12345's Avatar
mrt12345 mrt12345 is offline
 
Join Date: Feb 2009
Posts: 93
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I had problems also but it is just spammers and there dam software they use i just added a security question for registration and so far it has help quit a bit. :up:
Reply With Quote
  #6  
Old 03-03-2010, 11:52 PM
RandyO RandyO is offline
 
Join Date: Jan 2006
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Your server needs proper security.. brute force attacks are all too common (my servers ban dozens of IP's daily for these) If your web host does not run some type of protection from brute force attacks, you need a new host..

ALSO Make sure your mysql db password in the config file is uber complex as well.. good hackers really do not use the GUI in most cases.. they inject code through an insecure script and it may not even be related to your forum...

Good luck... for me? a server gets hacked and it is full system dump and reload of the OS...
Reply With Quote
  #7  
Old 03-05-2010, 05:41 PM
cammot cammot is offline
 
Join Date: Jul 2009
Posts: 18
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for all the comments. I think I finally think I found the method used, if this helps anyone. Apparently one of my forum's was accessible for non registered, and an article that was created on the forum also had comments (replies) enabled. So the spammer took advantage of making a comment, that somehow even changed the forum title. HTML was allowed on the comment box. So it could be that these contributing factors led to how my site was infiltrated without a password being necessary.

Thanks
cammot
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:06 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04393 seconds
  • Memory Usage 2,210KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (7)post_thanks_box
  • (7)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (7)post_thanks_postbit_info
  • (7)postbit
  • (7)postbit_onlinestatus
  • (7)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete