vBulletin Modifications

my forum was hacked , need help!!

Welcome to vBHackers.com! - vBHackers Updates:

Go Back   vBulletin Modifications > General vBulletin Section > General vBulletin Support

Reply
 
LinkBack Thread Tools
Old 09-04-2006, 02:48 PM   #1
vB Newbie
Join Date: Aug 2006
bongwater is on a distinguished road

Exclamation my forum was hacked , need help!!

My forum was hacked, I get the following message

Defaced By CiberPunk


sh-2.05b$ ls
error to connect the server . . . . . . . . .
Community Punk Unidos!
We Are Punk Unidos..... CiberPunk Rules!

sh-2.05b$ id
uid=(root) gid=(root) groups=(root)
CiberPunk HackeD Your system

Process this completing. . . . . . . . . . . . . . . . . . . . . .
Process went completed

.:Members:.
CiberPunk, punknomas
Punk Unidos




What do I do???? running 3.6 gold. thanks




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Old 09-04-2006, 02:52 PM   #2
vB Newbie
Join Date: Aug 2006
bongwater is on a distinguished road

Default

okay, I found a fix, I reuploaded the index.php file. Looks like somebody hacked into it and overwrote that file. Any ideas on how to protect that file or any other files vulnerable to a hack?

Last edited by bongwater; 09-04-2006 at 03:22 PM..




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-04-2006, 02:56 PM   #3
Coder
Idan's Avatar
Join Date: Feb 2005
Real Name: Idan
Location: Israel
Idan is on a distinguished road

Default

most likely some product code/plugin installed on your forum might have some xss vuln that were exploited successfully... (or maybe vbulletin itself with unpatched security "hole" found ???)
the best you could do is try to gather all logs you can on find your hosting, hoping to understand what was exploited & how in order to prevent this from ever repeating again.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-04-2006, 03:05 PM   #4
vBulletin Guru
Nick R's Avatar
Join Date: May 2006
Real Name: Nick
Location: Cyberspace, UK
Nick R is on a distinguished road

Default

And make a weekly db backups at least. Make sure the chmod permissions are ok and you don't have a file upload center uploading to root that supports php files.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-04-2006, 04:43 PM   #5
Coder
Join Date: May 2005
ntfu2 is on a distinguished road

Default

Not only should you make a weekly DB backup, but dont forget to download that from the server, or back it up to another server. Nothing like doing it, then leaving it on the server and it getting deleted :shock:

Do you have Top X Stats installed?




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-04-2006, 04:48 PM   #6
vBulletin Guru
Nick R's Avatar
Join Date: May 2006
Real Name: Nick
Location: Cyberspace, UK
Nick R is on a distinguished road

Default

The top x stats was just the forum home redirect it doesn't overide files. Which you can't do anyway unless you have ftp access or the chmod perms are wrong.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-04-2006, 05:06 PM   #7
vB Newbie
Join Date: Aug 2006
bongwater is on a distinguished road

Default

can changing chmod permissions on the index file prevent an intruder from overwriting the file? if so, what would the permission setting be?




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-04-2006, 05:11 PM   #8
vB Newbie
Join Date: Jul 2006
stutefc is on a distinguished road

Default

Got hacked twice this year already, both from Romania believe it not. I do daily back ups. You normally think it is ok to upload the index file again, but they normally leave another few pressies, your best to get your host provider to have a look at the server for you as well.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-04-2006, 05:18 PM   #9
vBulletin Guru
Nick R's Avatar
Join Date: May 2006
Real Name: Nick
Location: Cyberspace, UK
Nick R is on a distinguished road

Default

Best to do the root folder seeing as you don't need that chmod, dhouls be 644 i think.




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 09-04-2006, 05:42 PM   #10
vB Newbie
Join Date: Aug 2006
bongwater is on a distinguished road

Default

Quote:
Originally Posted by rogersnm
Best to do the root folder seeing as you don't need that chmod, dhouls be 644 i think.

My chmod settings for my forum root is set at 775. So if I change the permissions to my root folder (http://www.mysite.com/forums) to chmod 644 (my ftp client is SmartFTP), that should prevent an intruder from overwriting the index file again?




Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Forum Display Ordering (User Control) xyz vBulletin 3.5 / 3.6 Hack Releases 14 07-20-2007 09:35 PM
Automatic send forum password after accept rules JollyJack vBulletin Modification Requests 3 08-17-2006 09:24 PM
Archive HDRebel88 vBulletin Modification Requests 2 07-29-2006 10:38 AM


All times are GMT -3. The time now is 06:43 PM.

Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc. (Patent Pending)