Looking for commonalities in vBulletin forums with the file2store.info redirect

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • djbaxter
    Senior Member
    • Aug 2006
    • 1418
    • 4.2.5

    Looking for commonalities in vBulletin forums with the file2store.info redirect

    I'm trying to identify common factors in vBullein forums affected by the file2store.info redirection exploit. In part, this is to avoid all the red herrings and blind alleys many of us have been running up and down since it first surfaced (or resurfaced).

    Can you please post here:

    1. vBulletin version number

    2. vBSEO installed? if yes, version?

    3. vBSEO sitemap add-on installed? if so, version?

    4. other add-ons installed
    Psychlinks Web Services Affordable Web Design & Site Management
    Specializing in Small Businesses and vBulletin/Xenforo Forums
  • djbaxter
    Senior Member
    • Aug 2006
    • 1418
    • 4.2.5

    #2
    See https://www.vbulletin.com/forum/show...=1#post2185385

    With the help of the security people at RealWebHost.net, we have now positively identified the method for injecting this exploit as well as specific vulnerabilities that permitted it on a 3.83, since updated to 3.87 PL2: As it turns out, it was a server configuration and security issue combined with some specific attributes of vBulletin installations which gave the intruder direct access to the MySQL database.

    The key is first to check your settings in cPanel for Remote MySQL: Unless you are using a database on a remote server, i.e., NOT on localhost, this setting should say "There are no additional mysql access hosts configured". If you have a specific database intentionally enabled, that too is okay. What should NEVER be there is the character % - this is a wildcard which allows ALL other servers to connect to the database. If you see the wildcard enabled, DELETE IT.

    Then, make sure you change your passwords to strong passwords for both cPanel and MySQL to ensure that no one can change this setting back without your knowledge.

    Then, pick any add-on, disable it, then re-enable it to clear the datastore.

    Finally, download the file tool_reparse.php from http://www.vbulletin.org/forum/showthread.php?t=220967 and let it find any discrpancies in your compiled templates and rebuild them.
    Psychlinks Web Services Affordable Web Design & Site Management
    Specializing in Small Businesses and vBulletin/Xenforo Forums

    Comment

    widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
    Working...