Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 03-15-2011, 05:37 PM
jefferis jefferis is offline
 
Join Date: Dec 2006
Location: Butler, PA
Posts: 43
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Security breach, unknown cause.. ?

Hi folks, I went onto our site and found a folder at our web root (1 level above our vB install) called "undeniable" which was 777 in permissions. When I looked in there, I found a lot of pages that put header spam advertizing content on the forum pages, but it used existing pages with renamed urls (So, IOW, the ad pages don't show up in our forum itself but only by accessing this rogue folder).
A sample page might be named zachary-walker-argus.html
And I cannot find any links in the pages that go outbound to any particular ad site, but there is content added to the page in the comment and post areas like:
Quote:
<title>"Argus cam lock || electronic ballast argus diagram"</title>
<div class="art-sheet-bl">One under-20 he had forced with frank, and after that she had to raise her impression then, argus cam lock.
Macarthur had the correspondent of eating over a preferred japan.
These unusual problems require have the claim including current.
Real samples are less strategic to hinge absence if they are organic the pinfall would be dragged and the club would be subjected.
Same accounts debating of the medicaid didn as mo healthnet was mastered as a communication.
North american spots is such a new life that the time has to engulf more than well a haven to drive estimates to crack up.
<li><p>argus firearms</p><p>brinkley argus online paper</p><p>brighton argus michigan</p><a href="http://www.OURWEBSITE/2011/01/sti-month-january-2011/" >STi of the Month – January 2011</a></li>

</div>
<div class='wpsc_categories wpsc_category_grid'><p>argus bean digital camera reviews</p><p>bayliner capri 1802 cuddy 1990 argus</p><p>argus observer classifieds</p>
I was wondering if anyone knows has seen something like this before, what kind of plugin breach might allow this, or how to tell where the hack came from, or how to protect against it.

Our webroot has a wordpress install but the pages in the undeniable folder had links to both WP and vB post pages....
Many thanks in advance.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:55 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03255 seconds
  • Memory Usage 2,155KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete