Results 1 to 11 of 11
Like Tree1Likes
  • 1 Post By melbo

vBSEO valid plugins

This is a discussion on vBSEO valid plugins within the General Discussion forums, part of the vBSEO SEO Plugin category; Is this a valid plugin? I ask because of the typo (capitalized O) in the name: vBSEO FOrum Admin Save ...

  1. #1
    Senior Member
    Real Name
    Eric
    Join Date
    Jan 2010
    Posts
    137
    Liked
    3 times

    vBSEO valid plugins

    Is this a valid plugin? I ask because of the typo (capitalized O) in the name:

    vBSEO FOrum Admin Save
    Code:
    if(defined('VBSEO_ENABLED'))
    vbseo_complete_sec('forumadmin_update_save');
    I had the exploit and the errors but haven't been able to find the plugin which is malicious. Nothing found with either vbseo_checkplugins or version (2)

  2. #2
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,100
    Liked
    622 times
    Blog Entries
    4
    It is a valid plugin
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  3. #3
    Senior Member
    Real Name
    Eric
    Join Date
    Jan 2010
    Posts
    137
    Liked
    3 times
    Idid have the same symptoms of the exploit as others (red links, vB db errors) but can not find an instance of a plugin that shouldn't be there. Is it possible that I had some malicious code inserted without a new plugin showing up?

  4. #4
    vBSEO Staff Andrés Durán Hewitt's Avatar
    Real Name
    Andrés Durán
    Join Date
    Jul 2009
    Location
    Costa Rica
    Posts
    3,393
    Liked
    411 times
    Blog Entries
    1
    Hello Eric,

    Please see this post: *vBSEO Security Bulletin* All Supported Versions: Patch Release

    There's a tool (vbseo_checkplugins2.zip) which will allow you to check your database for malicious/suspicious code. Be sure to rebuild your datastore as well by clicking the "Click here to reset datastore" link.
    Andrés Durán / Crawlability Inc.
    ˇvBSEO 3.6.0 GOLD Liberado!
    Inaugurando el NUEVO vBSEO Sitemap Generator 3.0. - ˇAHORA disponible para Clientes de vBSEO!

    Síguenos en: Facebook | Síguenos en: Twitter


  5. #5
    Senior Member
    Real Name
    Eric
    Join Date
    Jan 2010
    Posts
    137
    Liked
    3 times
    I mentioned in my first post that I did run vbseo_checkplugins versions 1 and 2 with nothing reported.
    I did reimport the vbseo xml file as well as reset my datastore.

    My question is still this: Is it possible to have been affected by this exploit without any malicious plugins discovered?

  6. #6
    vBSEO Staff Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,742
    Liked
    168 times
    Possibly db errors in your case are related to something else. If you continue receiving many emails though, please open a support ticket with ftp/admincp details and we will check this further.

  7. #7
    Senior Member
    Real Name
    Eric
    Join Date
    Jan 2010
    Posts
    137
    Liked
    3 times
    Thanks. I had the exact same sympotms as the rest and it started around the same time. The Red links which seemed to be a symptom would be pretty coincidental.

    I have not had db errors for the past 12 hours but it concerns me that I never found a plugin and all I did was re-import the xml, flush the datastore and import the patched file.

    I never really found anything but it went away after performing these steps.

    Thanks

  8. #8
    Senior Member
    Real Name
    Eric
    Join Date
    Jan 2010
    Posts
    137
    Liked
    3 times
    This vBSEO plugin also has a typo in the plugin name: vBSEP Delete Thread which makes it suspect to me. Can you verify it is valid?
    Code:
    if(defined('VBSEO_ENABLED') && VBSEO_ENABLED && VBSEO_LIKE_POST && ($_POST['do'] != 'domergethreads'))
    {
        vbseo_extra_inc('ui');
        vBSEO_UI::delete_likes(0, $threadid, VBSEO_UI_THREAD);
    }

  9. #9
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    Yes, that is ok too. Typo and will be fixed in our next release

  10. #10
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    Quote Originally Posted by melbo View Post
    Thanks. I had the exact same sympotms as the rest and it started around the same time. The Red links which seemed to be a symptom would be pretty coincidental.

    I have not had db errors for the past 12 hours but it concerns me that I never found a plugin and all I did was re-import the xml, flush the datastore and import the patched file.

    I never really found anything but it went away after performing these steps.

    Thanks
    There were 3 hits that we have seen
    2 were plugins
    1 attached it self directly into the datestore table itself. Running the flush from version 2 of that script should clear it out and then you'll be ok.

  11. #11
    Senior Member
    Real Name
    Eric
    Join Date
    Jan 2010
    Posts
    137
    Liked
    3 times
    Thanks Brian, Might want to correct this one too:
    vBSEO FOrum Admin Save

Similar Threads

  1. When I enable vbseo under the plugins admin cp
    By MoneyMakerTalk in forum Troubleshooting
    Replies: 17
    Last Post: 10-03-2009, 07:07 PM
  2. Do I need both vbSEO and vbSEO-sitemaps plugins?
    By jeremym in forum Pre-Sales Questions
    Replies: 1
    Last Post: 08-22-2009, 09:24 AM
  3. vbseo done - welche Plugins noch?
    By taeb.de in forum Deutsch
    Replies: 3
    Last Post: 01-03-2008, 12:30 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •