Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 07-01-2011, 11:53 PM
keress keress is offline
 
Join Date: Jan 2003
Location: Virginia
Posts: 15
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Site hacked

Our site's been hacked. When trying to open the forum, a forum.php opened with an email address, 'meowholio@gmail.com for security.' I deleted that, then when the index.php kicked, it had the same email address. I uploaded the real index.php and then got these error messages:

Quote:
Warning: fetch_template() calls should be replaced by the vB_Template class. Template name: forumhome_birthdaybit in [path]/includes/functions.php on line 3932

Parse error: syntax error, unexpected T_CONSTANT_ENCAPSED_STRING in /home/saponorg/public_html/forum/index.php(147) : eval()'d code on line 1

Warning: fetch_template() calls should be replaced by the vB_Template class. Template name: forumhome_birthdaybit in [path]/includes/functions.php on line 3932

Parse error: syntax error, unexpected T_CONSTANT_ENCAPSED_STRING in /home/saponorg/public_html/forum/index.php(147) : eval()'d code on line 1

Warning: fetch_template() calls should be replaced by the vB_Template class. Template name: forumhome_markread_script in [path]/includes/functions.php on line 3932

Parse error: syntax error, unexpected T_STRING in /home/saponorg/public_html/forum/index.php(532) : eval()'d code on line 1

Warning: fetch_template() calls should be replaced by the vB_Template class. Template name: ad_forumhome_afterforums in [path]/includes/functions.php on line 3932

Warning: fetch_template() calls should be replaced by the vB_Template class. Template name: navbar in [path]/includes/functions.php on line 3932

Parse error: syntax error, unexpected T_STRING in /home/saponorg/public_html/forum/index.php(562) : eval()'d code on line 1

Warning: fetch_template() calls should be replaced by the vB_Template class. Template name: FORUMHOME in [path]/includes/functions.php on line 3932

Parse error: syntax error, unexpected T_STRING in /home/saponorg/public_html/forum/index.php(563) : eval()'d code on line 1
Should I start by re-uploading the site? I know I'm downlevel, though I'm not sure what level I'm on. What file will tell me this? Would it 'cure' the problem to upgrade?
Reply With Quote
  #2  
Old 07-02-2011, 12:32 AM
snakes1100 snakes1100 is offline
 
Join Date: Dec 2001
Location: Michigan
Posts: 3,733
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

That would be a start.

I would rename the current folder to name-dont-use or whatever you like.

Upload the current version php files for vb to the new rightly named folder.

If there is a required upgrade to close a vb security hole, that would be wise to complete.

Upload & upgrade your installed hacks/addons 1 by 1.

Revert / update any out dated templates.

If you was previously storing any files for attachments/avatars etc, move them back int othe new folder that vb resides in.

You may also want to do a scan of the current db for injected code that may be in a template.
Reply With Quote
  #3  
Old 07-02-2011, 02:54 AM
keress keress is offline
 
Join Date: Jan 2003
Location: Virginia
Posts: 15
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks so much for the good advice.

Isn't there a file (online) that would tell me what version I'm using? I want to confirm that before I start uploading.

--------------- Added [DATE]1309582233[/DATE] at [TIME]1309582233[/TIME] ---------------

So far, so good. I went ahead and uploaded my best guess version and the site's reappeared.

http://www.saponitown.com/forum/forum.php

Where would the banner image and avatars be stored?
Reply With Quote
  #4  
Old 07-02-2011, 08:06 PM
BirdOPrey5's Avatar
BirdOPrey5 BirdOPrey5 is offline
Senior Member
 
Join Date: Jun 2008
Location: New York
Posts: 10,610
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You are using vBulletin 4.0.2 according to your link- but from the errors posted in your first post it appears you have uploaded vBulletin 3.x files.

You are also posting in the vBullerin 3.x section- I suggest verifying what version you are supposed to be running and download the original files for that version.
Reply With Quote
Благодарность от:
borbole
  #5  
Old 07-03-2011, 11:54 PM
Danny702 Danny702 is offline
 
Join Date: Jul 2011
Posts: 4
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

My site has been hacked 2 .. and idk how to stop them i patched all the exploits anybody wanna help me 2 ........
Reply With Quote
  #6  
Old 07-04-2011, 12:57 AM
BirdOPrey5's Avatar
BirdOPrey5 BirdOPrey5 is offline
Senior Member
 
Join Date: Jun 2008
Location: New York
Posts: 10,610
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Danny702 View Post
My site has been hacked 2 .. and idk how to stop them i patched all the exploits anybody wanna help me 2 ........
You should file a support ticket on vBulletin.com. Put in all the info you have gathered about the hack.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:20 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04406 seconds
  • Memory Usage 2,217KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (6)post_thanks_box
  • (1)post_thanks_box_bit
  • (6)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (6)post_thanks_postbit_info
  • (6)postbit
  • (6)postbit_onlinestatus
  • (6)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete