Forum Hacked (4.2.3 Patch Level 2)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • pcs1
    New Member
    • Aug 2010
    • 5

    Forum Hacked (4.2.3 Patch Level 2)

    Good afternoon

    On Tuesday our forum was hacked (we were on the latest version of 4.2.3, the day before you released patch level 2) and unfortunately some of the database files have been amended.

    Due to an error with our server hosts we were not able to restore our database which has been very frustrating. All our data is still there and the forums are functioning more or less as they should be, apart from the image.php and admincp/image.php files are not loading Avatars anymore - instead they are loading a password box (see attached image) which is very obviously an attempt to obtain our forum password and/or hijack our sessions.

    We have installed a complete fresh forums with fresh database and this functions just fine, but we do not wish to start over again! We have also replaced all the forum files with a new set that were downloaded from vbulletin without any luck - so I'm pretty confident that the malicious data is stored in our forum database somewhere.

    We have full access to the database and have searched the forum database without any success for the past few days now and I'm at a loss now on how to fix the issue.

    Can anybody shed any light on what we need to do to resolve this?

    It appears that the hacker has gone for now, perhaps the new patch installed on Wednesday morning fixed the issue, or the hacker has discovered that there is nothing of value for him/her to steal and has moved on.

    Thanks in advance.
  • pcs1
    New Member
    • Aug 2010
    • 5

    #2
    Just to add - the password box as per the image appears when we click on "Avatar Manager", "Add new Avatars" or "Upload Avatar".

    Comment

    • Paul M
      Former Lead Developer
      vB.Com & vB.Org
      • Sep 2004
      • 9886

      #3
      You need to log a support ticket and provide them with access to the server so they can take a look, without direct access anyone would just be blindly guessing whats going on.
      Baby, I was born this way

      Comment

      • pcs1
        New Member
        • Aug 2010
        • 5

        #4
        Thanks - I have logged a support ticket.

        Comment

        widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
        Working...