Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 12-22-2011, 05:56 AM
sdfontanini sdfontanini is offline
 
Join Date: Oct 2008
Posts: 13
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Site Hacked

<a href="http://www.coloradoevo.com" target="_blank">www.coloradoevo.com</a>

Site was hacked about a week ago, no backup copies available from the server hosts as they just updated their software and the only copy is the hacked version.

I went and upgraded my site to 4.1.9 from 4.1.5 and installed everything but the site still won't return to its original state.

I can't even log into the Admin Panel

Every folder I visit takes me to the same main page.... like a redirect

Please visit my site above and see if you can help me out

thanks

Steve
Reply With Quote
  #2  
Old 12-22-2011, 10:14 AM
Skivey Skivey is offline
 
Join Date: Jan 2008
Posts: 162
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

For starters we need someone here to determine what the simple security flaws were here so that I can make sure I dont get the same probem with my site!!

I was able to get to your cpanel, so you should be able to get into your ftp.

It says nothing was deleted, so within ftp id guess that they moved everything up one folder or just renamed your index.php and probably your .htaccess file.

Contact your host, I also had a problem where I had accidently deleted my site (I was ment to delete a different one and didnt realise i was in the wrong folder!) and although there were no backps in my backups folder, the host had backups.. and were able to fix it for me for $50.

Im no expert, so appologies if what I put are wrong..... but this is what id be doing right now!

--------------- Added [DATE]1324552839[/DATE] at [TIME]1324552839[/TIME] ---------------

oh and take your site down
Reply With Quote
  #3  
Old 12-22-2011, 03:09 PM
borbole's Avatar
borbole borbole is offline
 
Join Date: Jan 2010
Posts: 2,559
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Can you check the db, is it still intact?

Try to overwrite your forum files with a fresh set from the vb package of your forum version. Then contact your host to check their logs and see what ecactly went down.
Reply With Quote
  #4  
Old 12-22-2011, 11:56 PM
sdfontanini sdfontanini is offline
 
Join Date: Oct 2008
Posts: 13
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I have accessed the server, and it appears everything is still there, and I have tried to override the files with backups, but still no success... checked both the .htacess and the index.php files and both seem to be okay. not sure how this hack is working...
Reply With Quote
  #5  
Old 12-23-2011, 12:01 AM
Max Taxable's Avatar
Max Taxable Max Taxable is offline
 
Join Date: Feb 2011
Posts: 3,134
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Looking at the page source, there is nothing at all of vBulletin in it. So you're looking in the wrong spot if you're looking in vBulletin files. This appears to be on your root.
Reply With Quote
  #6  
Old 12-23-2011, 12:17 AM
sdfontanini sdfontanini is offline
 
Join Date: Oct 2008
Posts: 13
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

yeah I also read the page source, I've been looking in my root folder and there is nothing like this in there, not even an html file, this is why I'm so confused... you can also try to navigate to other pages on my site and before it would redirect to that main Hacker Page, but now since I tried replacing these files with a backup copy I'm getting a 404 page...

--------------- Added [DATE]1324604431[/DATE] at [TIME]1324604431[/TIME] ---------------

Updated again to 4.1.9 and it looks like I now have access to the AdminCP

But where to go from here???
Reply With Quote
  #7  
Old 12-23-2011, 12:45 AM
Lee Roberts's Avatar
Lee Roberts Lee Roberts is offline
 
Join Date: Jun 2008
Location: UK
Posts: 117
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It could be a Symlink on your index file('s) take a look at this then see if you can find anything out, you may need SSH to view those links or in cpanel. http://en.wikipedia.org/wiki/Symbolic_link
Reply With Quote
  #8  
Old 12-23-2011, 03:09 AM
hivitro hivitro is offline
 
Join Date: Jun 2011
Posts: 20
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

1- If your DB exist, make a backup from phpmyadmin or the host backups tools

2- rename your Forum path to forumhacked and copy the original files of vb4.1.9 to your forum path

3- Upgrade vb /install.php -> upgrade to have and funtional forum

4- Check for /images or avatars to restore the profieles in /forumhacked -> /forum

5- Re install Plugins, but.. check the source of this external files....
Reply With Quote
  #9  
Old 12-23-2011, 03:39 AM
sdfontanini sdfontanini is offline
 
Join Date: Oct 2008
Posts: 13
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I've got other sites on my server space and none of them are affected just the vbulletin pages.

Can't find anything in my root folder that would cause this...

--------------- Added [DATE]1324617182[/DATE] at [TIME]1324617182[/TIME] ---------------

Every page gets redirected back to this Hacker Main Page

--------------- Added [DATE]1324617824[/DATE] at [TIME]1324617824[/TIME] ---------------

can someone post their .htaccess code, not sure what it's suppose to look like
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:54 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04043 seconds
  • Memory Usage 2,234KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (9)post_thanks_box
  • (9)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (9)post_thanks_postbit_info
  • (9)postbit
  • (9)postbit_onlinestatus
  • (9)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete