Go Back   vb.org Archive > Community Discussions > Forum and Server Management
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 08-04-2013, 06:49 PM
Wir3tap Wir3tap is offline
 
Join Date: Jul 2013
Posts: 19
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Recovering from a Hack

So a few weeks ago some great help got me in with Fix It to fix our forums. There are still problems we are running into.

1.) When going to update plugs and enable them. It acts like its going to but gives this in the box.
Updating style information for each style

World at War ... (Templates) (StyleVars) (Replacement Variables) (CSS) ~ HaCkEd By EjRaM HaCkEr ~ isecurity7@gmail.com

That hacked by ejram is the hack that kept spamming our main page before we used fix it.

2.) If I try to run the vbulletin upgrade script. It says this.

On Processing Blog 17 of 18 It errors out with this message.

Unexpected Text:
<?xml version="1.0" encoding="windows-1252"?>
~ HaCkEd By EjRaM HaCkEr ~
isecurity7@gmail.com


Does anyone know where this hack could be?

Otherwise the forums are working just seems like updates can't be done.

--------------- Added [DATE]1375646712[/DATE] at [TIME]1375646712[/TIME] ---------------

Also, The only way we can view the forums, is if all of our plugins are disabled.

--------------- Added [DATE]1375647598[/DATE] at [TIME]1375647598[/TIME] ---------------

Ok I disabled every plugin, and removed the define('DISABLE_HOOKS', 1); from my config file. Now each time I go to enable a plugin it gives me this:

Updating style information for each style

World at War ... (Templates) (StyleVars) (Replacement Variables) (CSS) ~ HaCkEd By EjRaM HaCkEr ~ isecurity7@gmail.com

--------------- Added [DATE]1375648135[/DATE] at [TIME]1375648135[/TIME] ---------------

Ok Plugin - Everywhere Sidebar - Posted teh big white screen of the hacked message on main index.php or any of the site links. I have uninstalled this plugin, but still getting the Hacked messages for the Updating Styles
Reply With Quote
  #2  
Old 08-04-2013, 07:42 PM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Have you tried posting a support ticket yet. A link to your site might help someone here to locate the problem. Check server logs see how they got in. Using custom plugins sometimes allow hackers access to your site
Reply With Quote
  #3  
Old 08-04-2013, 08:01 PM
Wir3tap Wir3tap is offline
 
Join Date: Jul 2013
Posts: 19
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

<a href="http://www.bfewaw.com" target="_blank">http://www.bfewaw.com</a> is the site, but the hacked message is only in admin stuff now.
Reply With Quote
  #4  
Old 08-04-2013, 09:29 PM
Big Al Big Al is offline
 
Join Date: Nov 2011
Posts: 54
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The site shows as blacklisted.
Quote:
Analyzed On 2013-08-04 22:23 GMT
Website Address bfewaw.com
Blacklist Status BLACKLISTED
Detection Ratio 1 / 26 (4 %)
Domain 1st Registered 2005-10-24 (8 years ago)
Google Page Rank Google Page Rank
Alexa Rank 10,610,734
Website Blacklist Report
Engine Status Info
Favicon SCUMWARE Alert DETECTED

Some information about the hacker? http://www.google.com.au/?gws_rd=cr#...w=1280&bih=792

This may help with sorting it out.? Good luck with getting rid of the hacker.

Hackers and those who support them are the scum of the earth IMHO.
Reply With Quote
  #5  
Old 08-04-2013, 10:16 PM
Wir3tap Wir3tap is offline
 
Join Date: Jul 2013
Posts: 19
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

What does that exactly mean?
Reply With Quote
  #6  
Old 08-04-2013, 10:38 PM
Big Al Big Al is offline
 
Join Date: Nov 2011
Posts: 54
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It means that as of a few seconds ago a scan of your site shows it is blacklisted by http://www.scumware.org/search.scumware

This information may assist if you contact your host, so they can see there is a problem.

You may wish to contact scumware.org to re-evaluate your site to see if it is now clean.
Reply With Quote
  #7  
Old 08-05-2013, 12:47 AM
Lynne's Avatar
Lynne Lynne is offline
 
Join Date: Sep 2004
Location: California/Idaho
Posts: 41,180
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Did you make sure to use a database backup from before you were hacked? I'm guessing they either changed, or added, a plugin and that is causing the issue.
Reply With Quote
  #8  
Old 08-05-2013, 10:45 AM
Wir3tap Wir3tap is offline
 
Join Date: Jul 2013
Posts: 19
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yeah unfortunately Lynne we didn't have a backup. So we are trying to find out where the hack is at.
Reply With Quote
  #9  
Old 08-05-2013, 11:07 AM
borbole's Avatar
borbole borbole is offline
 
Join Date: Jan 2010
Posts: 2,559
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Wir3tap View Post
Yeah unfortunately Lynne we didn't have a backup. So we are trying to find out where the hack is at.
Where do you get the hack message? You should do a thorough checkup of your server space and database as well. Also contact your host so they can check their access logs around the time that your forum got hacked to see how they got in.

Quote:
Originally Posted by Wir3tap View Post
http://www.bfewaw.com is the site, but the hacked message is only in admin stuff now.
I loaded your admin page and I did not see any hack message. Is it solved now?
Reply With Quote
  #10  
Old 08-05-2013, 12:51 PM
Wir3tap Wir3tap is offline
 
Join Date: Jul 2013
Posts: 19
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Here are screenshots.

The first is the message that pops up when you try to Enable a plugin. (It does not update the styles when you click enable.)



The 2nd is what pops up in error of stage 17 of updating VBulletin. When you scroll the bar to the side, it says the hacked Message




When we first got hacked, we couldn't get into anything. It didn't even show us the forums. It was just one white screen that said "Hacked By Ejram" and that email address, the same thing its saying in the screenshots.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:26 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04457 seconds
  • Memory Usage 2,256KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete