Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 01-16-2015, 08:11 PM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Hacked through provider - files added.

Ok, looks like some a$$hole somehow got into my providers site and purchased a $hit ton of server stuff, ie, new server, hosting, etc. Got all that taken care of, etc.

My site has been obviously compromised, and will address that later tonight. In the mean time going through the cpanel screen on my providers site, it looks like, according to the time stamps, that the culprite only ADDED files, they did not modify previously existing files. Very strange because if someone was going f... you over would they not just $hit tank your site? I have an output.txt and .php files added that have somehow overroad my entire site. They did not have DB access thank god.

I assume that when you look at an FTP manager, the dates next to the files/folders (especially folders) will change even if ONE thing in a multi tier folder changes, correct? Any input appreciated. Thanks.

I still have no idea how they knew my ID and PW for my provider... they didn't even change account info, contact, etc...
Reply With Quote
  #2  
Old 01-16-2015, 08:16 PM
Dave Dave is offline
 
Join Date: May 2010
Posts: 2,583
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Try this: login into the admin cp > Maintenance > Diagnostics > Suspect File Versions. That will display any files which do not belong to vBulletin or are modified. Also check your plugins at Plugins & Products > Plugin Manager. There might be some fishy plugins with backdoor code.

In case you use shared hosting, they probably "rooted" the server and ran a script to replace all index files of all websites with their deface page. If that's the case, you better find a completely different host.
Reply With Quote
2 благодарности(ей) от:
CarpCharacin, RichieBoy67
  #3  
Old 01-16-2015, 08:28 PM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Dave View Post
Try this: login into the admin cp > Maintenance > Diagnostics > Suspect File Versions. That will display any files which do not belong to vBulletin or are modified. Also check your plugins at Plugins & Products > Plugin Manager. There might be some fishy plugins with backdoor code.

In case you use shared hosting, they probably "rooted" the server and ran a script to replace all index files of all websites with their deface page. If that's the case, you better find a completely different host.


Thanks. I don't think they did that, as they charged close to a grand of $hit from my account, like new server space, domain names, etc.

I have not checked the suspect file version. It seems that I have only a few added files. In fact this whole thing is weird, how did someone get a multi digit ID and long PW???? The only two people that know are God and me and God isn't saying $hit.

In fact what is so weird is they could have totally have destroyed the site, etc. but everything is there with the exception of the few newly added files. Strange...

Ok, here are the files with new dates of 01/15/2015:

Index.php
MS.php
output.txt
wso.php
Reply With Quote
  #4  
Old 01-16-2015, 08:38 PM
Dave Dave is offline
 
Join Date: May 2010
Posts: 2,583
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

They didn't alter anything else because those scriptkiddies usually only do it to deface your site so they can brag about it to their other scripkiddy friends.

What I would do is change the passwords of all your stuff, just to be sure.
- Delete those suspicious files and re-upload the index.php file of vBulletin. (wso.php is a web-shell by the way, a backdoor. Delete that file asap)
- Be sure all of your plugins are up to date.
- Change the admincp folder to something else.

I can help you out in private if you need help, but of course understandable if you have some trust issues now.
Reply With Quote
  #5  
Old 01-16-2015, 08:43 PM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thanks. The admin CP folder was changed to something else originally... do I need to change it again? Also, I assume they got the FTP connection info for the DB... should I change the DB pw as well? If so, do I just do that in config, or do I need to do something on the back end of VB?

Still pretty ballsy to charge $1000.00 in server, and domain names...

Are any of thise files, with the exception of INDEX, vbulletin files to begin with? Not sure if these are fresh uploads or altered existing files.
Reply With Quote
  #6  
Old 01-16-2015, 08:44 PM
Dave Dave is offline
 
Join Date: May 2010
Posts: 2,583
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by pityocamptes View Post
Thanks. The admin CP folder was changed to something else originally... do I need to change it again? Also, I assume they got the FTP connection info for the DB... should I change the DB pw as well? If so, do I just do that in config, or do I need to do something on the back end of VB?


Still pretty ballsy to charge $1000.00 in server, and domain names...
You usually change the passwords of your FTP/MySQL in the CPanel of your host. If you change the password of MySQL, you also have to change it in the config file at includes/config.php of vBulletin.
Reply With Quote
  #7  
Old 01-16-2015, 08:47 PM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Dave View Post
You usually change the passwords of your FTP/MySQL in the CPanel of your host. If you change the password of MySQL, you also have to change it in the config file at includes/config.php of vBulletin.
Thanks. How about those file names? Are any of those vbulletin files by origin?


Oh, and also, should I change the admin folder name to something else?

--------------- Added [DATE]1421452963[/DATE] at [TIME]1421452963[/TIME] ---------------

I can"t delete output.text is that a vbulletin file??? It keeps showing up. Thanks.
Reply With Quote
  #8  
Old 01-16-2015, 10:38 PM
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Location: USA
Posts: 10,929
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

output text could be from the https://vborg.vbsupport.ru/showthread.php?t=268208 mod.

Please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site
Reply With Quote
  #9  
Old 01-16-2015, 10:39 PM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by ozzy47 View Post
Thanks! I believe that is it. It shows spiders, etc. in the output. No need to go to those threads, seems like everything is ok. I still would like to know how they got my host account info... everything seems ok now.. thanks.

--------------- Added [DATE]1421513152[/DATE] at [TIME]1421513152[/TIME] ---------------

How long does it take for google to pick up the changes back to my site? It still is saying in google search "hacked by..." ? I resubmitted my sitemap via seo, and have checked on the page source code and the "hacked by..." is gone (removed when I changed the site back).
Reply With Quote
  #10  
Old 01-20-2015, 03:43 PM
pityocamptes's Avatar
pityocamptes pityocamptes is offline
 
Join Date: Apr 2010
Posts: 595
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Cleaned up everything, changed FTP and database passwords, removed all recent files, scanned for foreign non vbulletin software, used secondary confirmation for host access (texts pin), changed admin folder name, pw protected, changed mod folder name, pw protected... I do have the admin firewall on, and I still got hacked again this morning. I have the admin firewall mod and never received notice that someone accessed the admincp, so I wonder if this was a direct FTP?

Can the host provider tell how someone is getting in? I updated my vbulletin software this past weekend. I don't know how these people are getting in!!! I'm not sure if it originally started off as a problem on the providers end (as originally the hackers had access to my account info and proceeded to charge a bunch of stuff - ie server space, etc. on the providers site) - because I think if it was a direct ftp hack they would not have had access to my actual provider account info.

I've scanned my computer at home, and have no rootkits, or viruses. Any ideas how to combat this? Thanks.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 03:41 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04321 seconds
  • Memory Usage 2,270KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (4)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (2)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete