Just been hacked with new version

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • readjono
    New Member
    • Aug 2006
    • 28

    Just been hacked with new version

    How disappointing that the new version (3.6.9) has meant that my website has been hacked. They've managed to edit all of the PHP to include some coding at the bottom linking to "cdpuvbhfzz.com" or something similar. Anyone else experienced similar problems?
  • Reeve of Shinra
    Senior Member
    • Sep 2001
    • 4325
    • 4.0.0

    #2
    Are you running any modifications? Any third party plugins or programs? Are you sure they didn't exploit some hole in your web server program?
    Plan, Do, Check, Act!

    Comment

    • Jobe1986
      Senior Member
      • Jan 2007
      • 629
      • 4.2.x

      #3
      Also a point to mention, if they managed to edit the actual PHP code, then chances are they got access to the host and not just vBulletin. Which can mean the host is insecure.
      http://data.collectiveirc.net/status/user/Jobe.png

      Comment

      • Jerz
        Senior Member
        • Apr 2007
        • 398
        • 3.8.x

        #4
        Originally posted by readjono
        How disappointing that the new version (3.6.9) has meant that my website has been hacked. They've managed to edit all of the PHP to include some coding at the bottom linking to "cdpuvbhfzz.com" or something similar. Anyone else experienced similar problems?
        As the others said this was probably caused by either a modification, or something at the server level, and not vB.

        Comment

        • readjono
          New Member
          • Aug 2006
          • 28

          #5
          The log would show they would have got in through vBulletin, but I will consider the third party applications.

          Comment

          • Steve Machol
            Former Customer Support Manager
            • Jul 2000
            • 154488

            #6
            Please see this thread on how to make your vBulletin more secure:



            If you are still being hacked after doing all of this, then they are most likely doing this by accessing your server. You need to contact your host about this.
            Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
            Change CKEditor Colors to Match Style (for 4.1.4 and above)

            Steve Machol Photography


            Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


            Comment

            • _nik_
              Member
              • Feb 2006
              • 96

              #7
              Yesterday night the same thing for me (with the previous version).
              Same link cdpu.... for me!

              Comment

              • pauli
                Member
                • Dec 2004
                • 59
                • 3.0.3

                #8
                I have been hacked 2 times today.. after getting it back up and running, changing all passwords.. they got back in again

                Comment

                • Steve Machol
                  Former Customer Support Manager
                  • Jul 2000
                  • 154488

                  #9
                  Originally posted by pauli
                  I have been hacked 2 times today.. after getting it back up and running, changing all passwords.. they got back in again
                  I checked your license and site. You need to upgrade to 3.6.9 and follow the instructions in my previous post.
                  Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
                  Change CKEditor Colors to Match Style (for 4.1.4 and above)

                  Steve Machol Photography


                  Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


                  Comment

                  widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                  Working...