New user made himself an admin

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • deadandy
    New Member
    • May 2010
    • 8
    • 4.2.X

    New user made himself an admin

    A new user account appeared in my database and somehow made himself an admin through the control panel. I'm assuming he used some exploit but I can't figure out what or how. The only clue I have is a handful of actions that appear in the Control Panel Log (image attached). Is there any way of telling what he did or what plugin he exploited? I deleted the user account, BTW, which is why it appears as N/A.
    Attached Files
  • In Omnibus
    Senior Member
    • Apr 2010
    • 2310

    #2
    Did you delete the "install" folder from your server? If not, that's likely your answer.

    Comment

    • Teascu Dorin
      Senior Member
      • Aug 2010
      • 257

      #3
      Originally posted by ProSportsForums
      Did you delete the "install" folder from your server? If not, that's likely your answer.
      Also if he did created an admin account you most surely have some hackers plugins installed.
      Best Regards

      roStyles Design LLC
      CEO & Founder (Design and Support)
      Romanian Translator
      Teascu Dorin

      Comment

      • Zachery
        Former vBulletin Support
        • Jul 2002
        • 59097

        #4
        First you need to follow our advisory about deleting the install folder off your forums.
        Then please read the following two blog posts:
        This guide is for what to do, after youÂ’ve been hacked, exploited, and or defaced. Step 1, Change everything: If you believe, or think your site has

        Getting Started This guide is intended to be a starting point for helping to keep your site safe and secure in the long run. It is not a be-all, end-all guide

        Also please see these recent security announcements:
        vBulletin 4.1.x-4.2.x & All versions of vBulletin 5: http://www.vbulletin.com/forum/forum...-1-vbulletin-5
        vBulletin 5.0.x patch released, for a different security issue: http://www.vbulletin.com/forum/forum...d-all-versions

        Comment

        • Nauti Rogue
          Member
          • Jan 2011
          • 40
          • 4.2.X

          #5
          Ironically, I have just noticed 3 users who have done the same on my forum within the last week or two. The issue was the fact that I had failed to delete the install folder. I've corrected this now, and I've deleted the other Admin accounts, but is it too late? Have I shut the barn door after the cows got out? What could they have done? What should I look for?
          http://www.lmbp.us/n.bmp


          Maximum martinis,minimum bikinis!

          Comment

          • DemOnstar
            Senior Member
            • Nov 2012
            • 1912

            #6
            Check your plug ins for something you didn't install and remove it..


            Comment

            • Nauti Rogue
              Member
              • Jan 2011
              • 40
              • 4.2.X

              #7
              Thanks. I uninstalled Skimlinks and Postrelease. I now notice that I'm getting the following warning: "Warning: Plugins are currently globally disabled via config.php." in the Plugins page. Is this normal, or should I go check that out? It seems like that's a good thing, except that I had previously had Forum Runner working correctly for the forum. I assume for Forum Runner to be working correctly in the past, I plugins must not have been globally disabled. Why would a hacker install plugins and then disable plugins?
              http://www.lmbp.us/n.bmp


              Maximum martinis,minimum bikinis!

              Comment

              • Mark.B
                vBulletin Support
                • Feb 2004
                • 24287
                • 6.0.X

                #8
                No real need to remove Skimlinks and Forum Runner...your rogue plugins are probably under the "vBulletin" product.

                The message you are receiving is because plugins are ALL disabled, which is normal.

                In this instance I would suggest raising a support ticket so we can get your login credentials and take a quick look around.



                Please include AdminCP login and FTP credentials in the "Sensitive Data" field.
                MARK.B
                vBulletin Support
                ------------
                My Unofficial vBulletin 6.0.0 Demo: https://www.talknewsuk.com
                My Unofficial vBulletin Cloud Demo: https://www.adminammo.com

                Comment

                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                Working...