Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 09-10-2013, 04:33 AM
Treeleaf Treeleaf is offline
 
Join Date: May 2012
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Site hacked by Myanmar Muslim Cyber Force

I believe it's time to enlist some help to get this resolved. Earlier this evening our forum.php was compromised and is now suffering from some kind of redirection.

So far I've removed the /install folder, deleted accounts created today, changed admin passwords and replaced the rest of the forum directories from backup and still don't have this thing removed.

Please PM me as soon as possible if you are interested in being paid to resolve this.

http://www.treeleaf.org/forums/forum.php
Reply With Quote
  #2  
Old 09-10-2013, 04:43 AM
Zachery's Avatar
Zachery Zachery is offline
 
Join Date: Jul 2002
Location: Ontario, Canada
Posts: 11,440
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site
Also please see these recent security announcements:
vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5
vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions
Reply With Quote
Благодарность от:
ForceHSS
  #3  
Old 09-10-2013, 05:02 AM
pjkcards pjkcards is offline
 
Join Date: Jul 2007
Posts: 299
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Same thing happened to us in the last 6 hours. When you click on our forum.php, it gets redirected to:
http://adf.ly/xxxxx

Reinstalling the forum removes any customizations we made. Is there any other way to handle this?

Thanks.
Reply With Quote
  #4  
Old 09-10-2013, 05:15 AM
Treeleaf Treeleaf is offline
 
Join Date: May 2012
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Okay, I tried the supplied cookbook. No resolution yet.

Help please!
Reply With Quote
  #5  
Old 09-10-2013, 05:31 AM
pjkcards pjkcards is offline
 
Join Date: Jul 2007
Posts: 299
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I've deleted the install directory, found several admin users and removed their admin permissions, disabled hooks in config.php, but still haven't resolved it yet. I haven't installed a fresh vB version yet since that will remove all my customizations.

I'll update here if I get it working.

Edit: I've also noticed it is the main theme that redirects, and all it child themes. Other themes work fine w/o redirect.

--------------- Added [DATE]1378795611[/DATE] at [TIME]1378795611[/TIME] ---------------

In the FORUMHOME template, it was modified by a hacker account, and was modified to be:
<META HTTP-EQUIV="Refresh" CONTENT="0;URL=http://adf.ly/xxx">

Check that file, and revert it.
Reply With Quote
  #6  
Old 09-10-2013, 05:51 AM
Treeleaf Treeleaf is offline
 
Join Date: May 2012
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I've also chased these fixes with no luck yet.

--------------- Added [DATE]1378824479[/DATE] at [TIME]1378824479[/TIME] ---------------

I'll eat my words, you had it right Pjkcards. Once you get the info out of the template, it's gone. Thanks so much for this.

Bows.
Reply With Quote
  #7  
Old 09-10-2013, 02:58 PM
xenite xenite is offline
 
Join Date: Oct 2005
Posts: 33
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

The redirects are being inserted into the database through the ADMINCP. Replacing the scripts won't accomplish anything.

Your best bet is to look at the Admin Log and see which functions the bogus admin accounts accessed. Then go to those tools and look at the most recently changed/added data. This could be notices, templates, plugins -- anything where you can embed HTML code that is executed.
Reply With Quote
  #8  
Old 09-10-2013, 03:39 PM
TheLastSuperman's Avatar
TheLastSuperman TheLastSuperman is offline
Senior Member
 
Join Date: Sep 2008
Location: North Carolina
Posts: 5,844
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pjkcards View Post
I've deleted the install directory, found several admin users and removed their admin permissions, disabled hooks in config.php, but still haven't resolved it yet. I haven't installed a fresh vB version yet since that will remove all my customizations.

I'll update here if I get it working.

Edit: I've also noticed it is the main theme that redirects, and all it child themes. Other themes work fine w/o redirect.

--------------- Added [DATE]1378795611[/DATE] at [TIME]1378795611[/TIME] ---------------

In the FORUMHOME template, it was modified by a hacker account, and was modified to be:
<META HTTP-EQUIV="Refresh" CONTENT="0;URL=http://adf.ly/VRAFS">

Check that file, and revert it.
Quote:
Originally Posted by Treeleaf View Post
I've also chased these fixes with no luck yet.

--------------- Added [DATE]1378824479[/DATE] at [TIME]1378824479[/TIME] ---------------

I'll eat my words, you had it right Pjkcards. Once you get the info out of the template, it's gone. Thanks so much for this.

Bows.
Quote:
Originally Posted by xenite View Post
The redirects are being inserted into the database through the ADMINCP. Replacing the scripts won't accomplish anything.

Your best bet is to look at the Admin Log and see which functions the bogus admin accounts accessed. Then go to those tools and look at the most recently changed/added data. This could be notices, templates, plugins -- anything where you can embed HTML code that is executed.
IF and I mean IF you have the redirect yet your FORUMHOME template is fine in your styles, then they have edited your master style see here - https://vborg.vbsupport.ru/showpost....1&postcount=52

The only way that is possible is by them uploading shell scripts that then allow them to modify files to place the site in debug mode, heck you can do that for one single user via a quick plugin. Check for files such as lol.php and others, also check above your forum root in public_html and others for files such as lol.php or similar names, check timestamps of files as one could be a shell script and yes do replace all your vBulletin files with 100% fresh files, download the same version (patched of course) and then overwrite all files - REMEMBER to delete the /install/ folder before uploading.
Reply With Quote
  #9  
Old 09-11-2013, 04:18 AM
pjkcards pjkcards is offline
 
Join Date: Jul 2007
Posts: 299
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Today the site was redirected again, then time the homepage.

As for the files they modified: the 4 users modified probably 100 files.
Reply With Quote
  #10  
Old 09-11-2013, 05:00 AM
monkeywarplane monkeywarplane is offline
 
Join Date: Sep 2005
Location: Bay Area
Posts: 30
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I just spent about a few hours cleaning up my forum

- changed passwords all over the place
- removing /install directory
- removing redirect from FORUMHOME
- removing admins
- changed passwords for all my admins
- reverted index.php in my /admincp
- they also placed some index.php files in each one of my folders (include, vb, archive,etc) that I had to manually delete. I organized by date modified.

Sigh. Hope that helps some of you guys.

Things look good now, but I am afraid to see what I find when I wake up tomorrow.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:56 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.06032 seconds
  • Memory Usage 2,263KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (1)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete