Results 1 to 10 of 10
Like Tree6Likes
  • 1 Post By benFF
  • 2 Post By Juan Muriente
  • 1 Post By fishguy
  • 1 Post By Andrés Durán Hewitt
  • 1 Post By Andrés Durán Hewitt

Hacking Updates?

This is a discussion on Hacking Updates? within the General Discussion forums, part of the vBSEO SEO Plugin category; So are we going to get an update on this? Now the infected file has been taken off the vBSEO ...

  1. #1
    Senior Member
    Real Name
    Ben Griffiths
    Join Date
    Apr 2006
    Location
    Taipei
    Posts
    154
    Liked
    6 times

    Hacking Updates?

    So are we going to get an update on this?

    Now the infected file has been taken off the vBSEO site, there is no way for us members to analyse what could have happened - thus we are totally reliant on you guys.

    It's been 2 days now and we still don't know what danger could be lurking... we know how the exploit was implemented, but not what damage could be done - and how..

    Could we please get updated?
    Lee G likes this.

  2. #2
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2

  3. #3
    vBSEO Staff Juan Muriente's Avatar
    Real Name
    Juan Carlos Muriente
    Join Date
    Jun 2005
    Location
    Puerto Rico
    Posts
    14,266
    Liked
    586 times
    Quote Originally Posted by benFF View Post
    So are we going to get an update on this?
    I'll be adding a third (and final) post to the FAQ's and then add all three as a new thread within the announcements forum. At the moment we are compiling a list of all the rogue plugins identified so far.

  4. #4
    Junior Member
    Real Name
    fishguy
    Join Date
    May 2010
    Posts
    8
    Liked
    1 times
    He is probably wondering the same thing I am?

    I am guessing they did not do this to simply add some arbitrary plug-in via an IFrame.

    What was the intent of the hack?

    Gather passwords from members?

    Create a mailing list for spamming / marketing by niche.

    etc.

    Is there any danger to the end users of all the communities affected?

    Thanks...
    Lee G likes this.

  5. #5
    Junior Member
    Real Name
    Alan
    Join Date
    May 2011
    Posts
    27
    Liked
    2 times
    Actually, this is the most important thing, what they did with these plugins and what we now have to do if we are hit (and many of us probably are)? I removed plugin manually, but what now? Is this enough?

  6. #6
    vBSEO Staff Andrés Durán Hewitt's Avatar
    Real Name
    Andrés Durán
    Join Date
    Jul 2009
    Location
    Costa Rica
    Posts
    3,393
    Liked
    411 times
    Blog Entries
    1
    @fishguy, all of those questions are going to be answered in the upcoming FAQ thread.

    @Alan, if you've already removed the rogue plugins, be sure to run this tool as well (vbseo_checkpluings2.zip): *vBSEO Security Bulletin* All Supported Versions: Patch Release

    You need to unzip it, upload the *.php file to your forum root directory, and run it from your web browser to clean up your datastore.
    Andrés Durán / Crawlability Inc.
    ˇvBSEO 3.6.0 GOLD Liberado!
    Inaugurando el NUEVO vBSEO Sitemap Generator 3.0. - ˇAHORA disponible para Clientes de vBSEO!

    Síguenos en: Facebook | Síguenos en: Twitter


  7. #7
    Junior Member
    Real Name
    Alan
    Join Date
    May 2011
    Posts
    27
    Liked
    2 times
    Yes, I ran both check plugins, everything was ok.

  8. #8
    vBSEO Staff Andrés Durán Hewitt's Avatar
    Real Name
    Andrés Durán
    Join Date
    Jul 2009
    Location
    Costa Rica
    Posts
    3,393
    Liked
    411 times
    Blog Entries
    1
    Then you should be all set now

    If you still go through further issues on this, please do let us know. We'll be happy to assist
    Alan_SP likes this.
    Andrés Durán / Crawlability Inc.
    ˇvBSEO 3.6.0 GOLD Liberado!
    Inaugurando el NUEVO vBSEO Sitemap Generator 3.0. - ˇAHORA disponible para Clientes de vBSEO!

    Síguenos en: Facebook | Síguenos en: Twitter


  9. #9
    Member
    Real Name
    Pepe
    Join Date
    May 2006
    Posts
    36
    Liked
    0 times
    Hello1. Runing VBSEO 3.62. Patched the abstract file as mentioned on the Announcement3. Ran the checkplugins2 file (nothing has shown up)4. Repaired datastore templateresult:I am still getting 61 emails per minute with the invalid SQL warningatabase error in vBulletin 3.8.2:Invalid SQL:SELECT * FROM datastore WHERE title='pluginlist';MySQL Error :Error Number :Request Date : Thursday, January 26th 2012 @ 02:38:14 AMError Date : Thursday, January 26th 2012 @ 02:38:14 AM

  10. #10
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    replied to your other post. please don't double post.

Similar Threads

  1. Hacking attempt today
    By Lee G in forum Off-Topic & Chit Chat
    Replies: 2
    Last Post: 04-15-2011, 07:20 PM
  2. vBulletin 3.x Hacking Attempt Crippled vBSEO
    By Sajuuk in forum Troubleshooting
    Replies: 4
    Last Post: 11-14-2010, 03:02 PM
  3. Strange hacking attempt
    By Lee G in forum Off-Topic & Chit Chat
    Replies: 3
    Last Post: 08-05-2010, 03:37 PM
  4. Google hacking, did anyone experience this?
    By Arjan in forum General Discussion
    Replies: 2
    Last Post: 08-31-2007, 09:21 AM
  5. General Hacking and Debugging of vB
    By LarryEitel in forum General Discussion
    Replies: 1
    Last Post: 06-28-2006, 09:08 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •