The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Problems with vbulletin 3.7.4 PL 2
Hi guys, I resort to you because my site has been hacked. The hacker inserted an exploit that creates a new php file in the "uploads folder" of vBulletin allowing remote filesystem control. By the way, it modifies the pages being served (every .php file) to include a script tag redirecting visitors to some sites.
I could fixed temporarily running a script that I took from here: https://github.com/walkeralencar/rrn...rnuVaccine.php It really worked, but I would like a permanent solution. According to my limit knowledge, I inferred that this vulnerability comes from a stored-xss vulnerability but I carried out different researches and all the vulnerabilities connected with this vbulletin version are "sql injection" ones. Anyway, the aim of this thread is to ask if you know how can I fix all the vulnerabilities that this version has. Is upgrading to a new version the only solution? I look forward to hearing your opinions!!! Thanks in advance. koko |
#2
|
||||
|
||||
Since security patches are no longer provided for that version, then you really should upgrade.
Also, you uploads folder (I assume you are talking about your attachments directory?) should not be accessible - it should NOT be in the site root folder. It should be 'above' there so no one may access any files in there directly. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|