Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 09-08-2013, 04:49 AM
stryker2012 stryker2012 is offline
 
Join Date: Aug 2011
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Please help site hacked

I notice today when two members made posts about their donations.

I checked my paypal account and there's was $0 , so I told them double check and they
send me a transaction confirmation ID, I was using vBDonate plugin for donations,
so I checked the setting and the paypal email was changed to a different email.

I started to check everything and find when I click on ranks in the admin cp
I get this:

http://postimg.org/image/7cfz7pie3/

It has been almost 6 hours I've trying to figure this out reading and doing some other stuff
and I still can't get rid of it.

I was using vb 4.1.10, I upgraded to 4.1.12 thinking that will fix the problem and still there.

Any help will be greatly appreciated.
Reply With Quote
  #2  
Old 09-08-2013, 09:22 AM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

This may be a good start.

http://www.vbulletin.com/vbcms/conte...vBulletin-Site
Reply With Quote
  #3  
Old 09-08-2013, 02:55 PM
stryker2012 stryker2012 is offline
 
Join Date: Aug 2011
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for your reply.
Yes, I did that and also a few other things, followed all steps.
I also change ftp, db, passwords.

I've also checked .htaccess file and config.php file as well and I don't see any modifications.

I've also use this template tool if the malicious code was int he template but still doing the same.
https://vborg.vbsupport.ru/showthread.php?t=281080
and that tool "teamps" is still there.
Reply With Quote
  #4  
Old 09-08-2013, 03:01 PM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I would:
  • Download the same exact version of vBulletin your currently running from the members area and have it ready for upload.
  • Delete the /install/install.php file and the config.php.new.
Then upload all the new files, change your admincp and modcp folder to a different name, then change your config.php to reflect the new names, and see if the issue still persists.
Reply With Quote
  #5  
Old 09-08-2013, 03:16 PM
stryker2012 stryker2012 is offline
 
Join Date: Aug 2011
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thank you for your reply.
I did it and still the ranks link showing up "TEAMPS" tool.

I see in that tool when trying to click in something it shows the link as this:

I don't really know where to look.
Reply With Quote
  #6  
Old 09-08-2013, 04:32 PM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Disable all your plugins.

Open your config.php and below<?php add this line:

PHP Code:
 define('DISABLE_HOOKS'true); 
So it looks like this:
PHP Code:
<?php
define
('DISABLE_HOOKS'true);
/*=================================================  =====================*\
|| ##################################################  ################## ||
|| # vBulletin 4.1.4
And see if that fixes it.
Reply With Quote
  #7  
Old 09-09-2013, 04:33 AM
stryker2012 stryker2012 is offline
 
Join Date: Aug 2011
Posts: 17
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks for your response.
adding that code was working fine.

after disabling, and enabling one by one, I find out that the plugin called:
GlowHost - Spam-O-Matic, was the one with the TEAMPS tool, I removed and then it was fine.
Now I'm adding more security ".htacces , htpw, etc."
Thank you.
Reply With Quote
  #8  
Old 09-09-2013, 09:04 AM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Not a problem, glad it's sorted.
Reply With Quote
  #9  
Old 09-09-2013, 09:56 AM
tim.liton tim.liton is offline
 
Join Date: Dec 2012
Posts: 35
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

delete the install folder!
Reply With Quote
  #10  
Old 09-09-2013, 11:45 AM
BirdOPrey5's Avatar
BirdOPrey5 BirdOPrey5 is offline
Senior Member
 
Join Date: Jun 2008
Location: New York
Posts: 10,610
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ozzy47 View Post
I would:
  • Download the same exact version of vBulletin your currently running from the members area and have it ready for upload.
  • Delete the /install/install.php file and the config.php.new.
Then upload all the new files, change your admincp and modcp folder to a different name, then change your config.php to reflect the new names, and see if the issue still persists.
At this point the entire /install/ directory should now be deleted, not just install.php.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:00 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04788 seconds
  • Memory Usage 2,249KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (2)bbcode_php
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete