Go Back   vb.org Archive > vBulletin 4 Discussion > vB4 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 02-08-2016, 04:05 AM
anupam_luv anupam_luv is offline
 
Join Date: Feb 2007
Posts: 31
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Hostgator Blocked My Outbound Port 80/443 because of ckeditor.js

My Outbound Port 80/443 is Blocked hostgator because of virus in ckeditor.js ... because it all my sites are down (until I remove these files from the server)

I think the files which it is asking me to delete are very crucial for my Vbulletin forums to work ...
I am very sure that antivirus is falsely showing it as virus bec I have replaced it with original/new files but it is still showing them as Virus ...

Im using these Vbulletin forums for many years I cannot delete these files ...

The files are :

public_html/fitnessmatter.com/forum/clientscript/ckeditor/ckeditor.js

public_html/dstreetdirect.com/clientscript/ckeditor/ckeditor.js

Now hostgator is asking me to remove this file from the server .... is it safe to remove them ...
Reply With Quote
  #2  
Old 02-08-2016, 05:58 AM
RichieBoy67's Avatar
RichieBoy67 RichieBoy67 is offline
 
Join Date: Apr 2004
Location: CT - Down in a hole..
Posts: 3,057
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

No, your site needs them but they are probably altered. Download them and look to see what as added.

if your site is hacked just removing those files is not going to fix things.
Reply With Quote
  #3  
Old 02-08-2016, 12:20 PM
Dave Dave is offline
 
Join Date: May 2010
Posts: 2,583
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

forum/clientscript/ckeditor/ckeditor.js is not a virus.
This is your moment to move to a host that isn't a sellout.
Reply With Quote
  #4  
Old 02-08-2016, 12:23 PM
RichieBoy67's Avatar
RichieBoy67 RichieBoy67 is offline
 
Join Date: Apr 2004
Location: CT - Down in a hole..
Posts: 3,057
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It could be hacked though. I agree though that hostgator of no so good for vbulletin.
Reply With Quote
  #5  
Old 02-09-2016, 09:31 AM
anupam_luv anupam_luv is offline
 
Join Date: Feb 2007
Posts: 31
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I did remove the file and replaced it with a new file download ... and re-scanned ... it again reported it as virus....

I raised a ticket regarding the issue and hostgator replied with the following response. ...

-----------------------------------------
From server logs, I could see that port 80/443 is blocked for the user xxxxxxx. This could be a reason for the issue you have reported earlier.

We have an automated scanning cron which disables port 80/443 of a user, when the user account has malicious file(s). Also, it disables all such file(s) with immutable attribute and null permission to avoid further infection. Check the scan results given below:
=======
Infected files: 2

/home/xxxxxxx/public_html/dstreetdirect.com/clientscript/ckeditor/ckeditor.js
/home/xxxxxxx/public_html/fitnessmatter.com/forum/clientscript/ckeditor/ckeditor.js
=======

As of now, I have reverted immutable attributes and null permission set on above file(s) so that you can modify those files(s).

Please note that, simply deleting/replacing infected file(s) will not be a permanent solution. If any of those file is used by your website theme/plugin/CMS then removing those file(s) may cause downtime to your websites.

Hence, I suggest you to double check your website contents like CMS, themes, plugins and make sure that they are up-to-date. Further, scan and re-upload above mentioned file(s) and get back to us.

Once your account is cleaned, we will activate port 80/443 for the user xxxxxxxxxx.

This will help you to avoid similar issues in future.

------------------------------------------

After that I repeated same steps .... Scanned > Quarantined > Re-uploaded new file > Scanned Again .... and again found same files as virus... Deadlock!!!
Reply With Quote
  #6  
Old 02-09-2016, 10:47 AM
ForceHSS ForceHSS is offline
 
Join Date: Apr 2008
Posts: 6,357
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

With Hostgator I don't have a problem with them as a host. You need to ask your host to check logs to see how the virus was uploaded, but I am sure he got into your admin panel and changed a few things so you need to check the logs in there and revert any templates he changed also check Plugins & Products/Plugin Manager see if he has added any plugins
Reply With Quote
  #7  
Old 02-09-2016, 10:13 PM
RichieBoy67's Avatar
RichieBoy67 RichieBoy67 is offline
 
Join Date: Apr 2004
Location: CT - Down in a hole..
Posts: 3,057
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

As they said in the email removing and replacing the file will not fix the issue if the site is indeed hacked.

--------------- Added [DATE]1455063275[/DATE] at [TIME]1455063275[/TIME] ---------------

Also, is Google reporting your site had malware? Check webmaster tools.
Reply With Quote
  #8  
Old 02-11-2016, 10:16 AM
anupam_luv anupam_luv is offline
 
Join Date: Feb 2007
Posts: 31
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

On 9th Feb evening I got the following message (they almost admitted tht it could be a false +ve)

-------------------------
We apologies fro the delay in our response.

We could understand your concern and we are checking this issue widely with our abuse and security wing.

We need to check whether this is a False positive signature then we will remove the signature.

Please be patient we will get back to you once the issue is fixed.
Thank You
--------------------------------

But even after many reminders/updates they are still saying that we are working on it....
Now I cant take it anymore, I removed/quarantined the file ckeditor.js ... so that at least Port is unlocked ... at least other sites shouldn't suffer because of it......

--------------- Added [DATE]1455201780[/DATE] at [TIME]1455201780[/TIME] ---------------

The problem is rectified now by Hostgator....

------------------------------
The Outgoing Port 80 for your account has been unblocked and you should not face any issues accessing your websites.

The False Positive issue has also been rectified and genuine files should not be blocked now in the virus scan.

Kindly check and verify the same.

Let us know in case you have any further queries.

Regards,
Joyson L

-----------------------------------------------------

Reuploaded the files .... having no issues for now....

ckeditor.js file is for Quick Edit or Quick Reply ... without it we have to use "Advanced" method to post the replies.....
Reply With Quote
  #9  
Old 02-12-2016, 09:02 AM
Skyrider Skyrider is offline
 
Join Date: Feb 2006
Location: Netherlands
Posts: 1,392
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

https://www.virustotal.com/en/url/bc...is/1455274700/
https://www.virustotal.com/en/url/42...is/1455274737/

You can ignore the Yandex Safebrowsing report on the second URL. I've checked both .js files with a text difference and it's exactly a duplicate. The file is clean.. I have no idea what hostgator is talkin about.. it's false positive whatever they are using.

But seeing the website is accessible, I can assume they already opened up the ports again for you.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 09:02 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04840 seconds
  • Memory Usage 2,240KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (9)post_thanks_box
  • (9)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (9)post_thanks_postbit_info
  • (9)postbit
  • (9)postbit_onlinestatus
  • (9)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete