Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 03-31-2011, 11:01 AM
gregory_clayton gregory_clayton is offline
 
Join Date: Jul 2010
Location: England
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Website hacked :/

i was hoping this shit wouldnt happen again :/..happend a few years back on my old forum and on my new one which has been opended 2 months which has finally started tog row jut got hacked this morning.

www.wwehq.com

It doesnt look like any files/tables were deleted. But it is displaying his websites on each page.

If I try to go onto the arcade.php its just the same.

Any idea anyone :/
Reply With Quote
  #2  
Old 03-31-2011, 11:04 AM
lazydesis lazydesis is offline
 
Join Date: Sep 2006
Posts: 234
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I am sure the database has been modified. It happened to me in the past. Open phpmyadmin and search for the text that's being displayed on your website, or search for the URL to which it is being redirected and you will see that.

Luckily I had a database backup which I restored, and then changed all my passwords. Also I would delete all the files in the public_html dir and reupload the vb files.

There is also a possibility that he might have just modified your config.php file. So take a look at that as well.
Reply With Quote
  #3  
Old 03-31-2011, 11:08 AM
gregory_clayton gregory_clayton is offline
 
Join Date: Jul 2010
Location: England
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

tried searching in phpmyadmin the text isnt found. Makes me wonder if he is using some sort of script to link to that site

--------------- Added [DATE]1301575085[/DATE] at [TIME]1301575085[/TIME] ---------------

bump
Reply With Quote
  #4  
Old 03-31-2011, 12:45 PM
borbole's Avatar
borbole borbole is offline
 
Join Date: Jan 2010
Posts: 2,559
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

What was the text displayed? I get a forum closed message when I loaded your forum?

it would be best to ask your host to check their access logs for around the time that the hack occurred to see how they got access.

What version of vb were you having btw?
Reply With Quote
  #5  
Old 03-31-2011, 01:47 PM
gregory_clayton gregory_clayton is offline
 
Join Date: Jul 2010
Location: England
Posts: 16
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The host has now uploaded a backup of the forum back online. I am awaiting the logs, they are going to transfer them to me later. When it happens I will be sure to paste the bas!£$ds ip for you guys here to ban him too.

I am using Powered by vBulletin™ Version 4.1.2
Reply With Quote
  #6  
Old 04-01-2011, 12:06 AM
DNN DNN is offline
 
Join Date: Mar 2011
Posts: 125
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

wow. Let me hurry up and update my stuff too.
Reply With Quote
  #7  
Old 04-01-2011, 10:13 PM
conradk conradk is offline
 
Join Date: Aug 2007
Posts: 37
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Several years ago when the hacking attempts got bad on my site I renamed the admincp directory and created a bogus admincp directory with bogus/broken php files.

and regular backups are a good thing - thanks for the reminder
Reply With Quote
  #8  
Old 04-03-2011, 02:59 PM
Phaedrus Phaedrus is offline
 
Join Date: Jul 2006
Location: Colorado
Posts: 617
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

check your PHP files, if he has access he can add just a couple lines to them that redirect everything to his pages. If such is the case, reload your clean files w/overwrite, then change your password you use to get into your server control panel to something indecipherable.
Reply With Quote
  #9  
Old 04-03-2011, 05:39 PM
Chase Chase is offline
 
Join Date: May 2002
Location: Northern Ohio
Posts: 237
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I highly recommend renaming your admincp and modcp folders and putting a password protection on them as well.

If you change your admincp folder name to something else, make sure you update it in your config.php file as well.
Reply With Quote
  #10  
Old 04-03-2011, 05:54 PM
TheLastSuperman's Avatar
TheLastSuperman TheLastSuperman is offline
Senior Member
 
Join Date: Sep 2008
Location: North Carolina
Posts: 5,844
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

  • Change cPanel Password (Or Hosting Account Manager password etc)
  • Change FTP Passwords
  • Change Forum Passwords
  • Changes ALL Database Usernames & Passwords then reset in config, remove old user from all DB's etc.
  • Check for modified files, compare timestamps etc.
  • IF you can access admincp check your template system for edits, revert all modified templates.
  • Check for shell files, .php, any new very large image files, anything with a odd name as sometimes it's apparent and sometimes it's not, depends on the hacker per say.
  • Check for oddly names modifications or plugins, recently a plugin was the culprit for me on a clients site.

The most important this is restoring from a backup, unless you know what to look for you could miss something so restoring then figuring out how you were compromised should be your number one priority otherwise they'll simply repeat the process .
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:05 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.10528 seconds
  • Memory Usage 2,252KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete