The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Urgent Help Needed : Site HAcked How?
Hi
My site www.computerforums.org was hacked a few weeks back by using the search function to search a group which then enabled them to run SQL injection and get my password ( http://www.youtube.com/watch?v=ztCFJvzv3NM ) There was a patch available to stop this threat so I restored the site from a backup and installed this patch (Which did fix the issue as I tested it). But yesterday they hacked me again. So I restored the database from a week back, then I deleted all files and only uploaded the latest version of VB files and performed an upgrade to the latest version of VB. (So i have a fresh upgraded install of VB) But again today ive been hacked. I believe they have uploaded a shell program but I can not find it. I keek changing my passwords every few hours (Username + Hosting + SQL) but they keep getting back in. Any ideas what I can do?? The hacker has been sending me messages, this is what he has told me, I dont know if the below is true but this is what he is saying -He is using an SQL injection hack to get it -The vubrability is in the vbulletin files, all versions (But I uploaded fresh VB files and upgraded) could it be in the database somewhere? -he wants money to stop the attacks --------------- Added [DATE]1322388545[/DATE] at [TIME]1322388545[/TIME] --------------- i have just found out that I have been hacked using this http://itsecbiz.blogspot.com/2011/07...f-you-got.html and I have decoded the file and it reads this Quote:
|
#2
|
|||
|
|||
According to the blog the attacker has to have admin access to start with. The hack is installed either as a skin xml or as a mod plug in. Is it just you and David as admins?
Something, either the hosting or a mod, has punched a hole in your security. The fact they were already in the acp to install the plugin is disturbing. |
#3
|
|||
|
|||
Disabling the plugin may work. A Shell is a trojan, a back door into your system. If your site is just being hosted thru a register then that could work just by deleting it. However, if you are hosting your forum on a VPS or your own dedicated server then he could have uploaded a shell somewhere else which could give him easy access into your domain. Contact your hosting and tell them to disable shell's from running. I am and change all of your passwords.
Also, edit your .htacess to only allow YOUR IP to hit the admincp and your moderaters (if they & you use use dynamic ips). There are tutorials on how to secure your forum around. And also, rename your admin and modcp folder to something else, and also edit them in the config.php to match. This is another form of security for your forum so by default, its yourforum/admincp it is a good idea to change that to something else. Sure a hacker could also crawl your site to try to find it, but naming it something incognito like say youforum.com/lmages (with a lower case L ) may throw them off. Most of these SQL hackers do not know very much and just follow others tutorials. Without a deeper understanding of vbulletin itself they may be thrown off guard and move on. |
#4
|
|||
|
|||
Woah! Last night I checked the site as I am a long time member there. Got the database errors screen. This morning just a blank page.
Good advice preemz. Hope he gets it back up pretty quick. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|