The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
Hacker only accessed plugin.php?
Hi guys, I just got some messages from forum members telling me a user has been added to the "Founder" group in my forum, I am the only one with powers to edit a persons group so it is obvious they used something malicious to do it.
I checked what he had done and this is what it shows: http://i.imgur.com/C7DNTZc.png It seems he only wanted to add a plugin but I'm not sure what plugin it is that he has added. Does anyone have any idea what to look for specifically? |
#2
|
||||
|
||||
Please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked http://www.vbulletin.com/forum/blogs...vbulletin-site Also please see these recent security announcements: vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5 vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions |
Благодарность от: | ||
tbworld |
#3
|
|||
|
|||
I would echo what Zachery says, but you also need to check your public_html file for any files they may have added, I got hacked yesterday and thy tried to hide a couple of files, one was called "mail.php", the other was "passwords.txt"
I have also been notified by Hawkhost that there is a known exploit in Forum runner, so if you are using that it would probably be best to uninstall and delete any files belonging to it as well. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|