Got hacked

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • sungerr
    Member
    • Jan 2009
    • 59

    Got hacked

    Hello

    My vbulletin 3.8.5 got hacked. all pages i open like index.php showthread.php register.php ...... and all other pages give the same hacking page

    i reupload all the vb files also same issue

    then i realized that it is database issue. i start searching on keywords . finally i found it

    in the template table (spacer_open) i found largeeeeee code starting bye (eval(decote.......)
    i remove it and everything works fine. then i updated to 4.2.0

    any way . what i need to know how this happen. and how can i check that their is no other change in my database and what actions i should do?

    regards
  • Wayne Luke
    vBulletin Technical Support Lead
    • Aug 2000
    • 74161

    #2
    Check out this blog entry here for more information on recovering your site and what to look for.

    Symptoms Having your site hacked is something no owner wants to experience due to the fact it takes quite a bit of effort to fix, often times requiring payment to a experienced third-party when a owner feels
    Translations provided by Google.

    Wayne Luke
    The Rabid Badger - a vBulletin Cloud demonstration site.
    vBulletin 5 API

    Comment

    • sungerr
      Member
      • Jan 2009
      • 59

      #3
      Thanks Mr Wayne i saw it before

      i was reading in some forms. to create a new template same as spacer_open and then go to global.php and change the name of spacer_open to the new template name
      this is available in 3.8

      but in 4.2 the global.php is completly different! is their a way to secure the spacer_open? since all arab hackers use this bug to hack the forum

      regards

      Comment

      • Wayne Luke
        vBulletin Technical Support Lead
        • Aug 2000
        • 74161

        #4
        You'd be better off securing your systems. Make sure all your files can run under 644 permissions, lock down the admincp and other directories where direct access isn't needed. Delete the install folder.
        Translations provided by Google.

        Wayne Luke
        The Rabid Badger - a vBulletin Cloud demonstration site.
        vBulletin 5 API

        Comment

        widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
        Working...