Page 4 of 11 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 LastLast
Results 46 to 60 of 152
Like Tree16Likes

hacked by url123.info

This is a discussion on hacked by url123.info within the Security Topics forums, part of the vBSEO SEO Plugin category; Originally Posted by eliteguias prevenir de nada sirve si el problema ya está dentro Probably this is my problem. I'm ...

  1. #46
    Member Array
    Real Name
    Davide
    Join Date
    Jan 2009
    Posts
    35
    Liked
    2 times
    Quote Originally Posted by eliteguias View Post
    prevenir de nada sirve si el problema ya está dentro
    Probably this is my problem. I'm not able to find the malevolous code.

  2. #47
    Member Array
    Real Name
    Diego
    Join Date
    Oct 2009
    Posts
    54
    Liked
    7 times
    bmastro I couldn't find the problem, but... I download a new copy of vbulletin from vbulletin.com and re-upload all archives (the same with vbseo) and.... problem solved (I hope so...).

    The same as with your computer "do you have a virus?" don't try to delete it, just.... reinstall windows.

  3. #48
    Junior Member Array
    Real Name
    Martin
    Join Date
    Apr 2007
    Posts
    16
    Liked
    0 times
    Another hack, here's again the log entry from the same time i got the warning mail:

    unassigned-87.236.194.191.coolhousing.net - - [09/Jul/2012:18:34:43 +0200] "GET /forum/search.php HTTP/1.1" 200 782 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0"
    Again the search.php is accessed. The only difference is that they didn't use TOR to hide the tracks.

  4. #49
    Member Array
    Real Name
    Bill Belcamino
    Join Date
    Nov 2008
    Posts
    58
    Liked
    3 times
    How do you clean forum cache?

  5. #50
    Member Array
    Real Name
    Davide
    Join Date
    Jan 2009
    Posts
    35
    Liked
    2 times
    Quote Originally Posted by Sparkiller View Post
    TOR to hide the tracks.
    ???
    I never received the warning mail! Maybe because of this TOR?

  6. #51
    Junior Member Array
    Real Name
    Martin
    Join Date
    Apr 2007
    Posts
    16
    Liked
    0 times
    Quote Originally Posted by Bmastro View Post
    ???
    I never received the warning mail! Maybe because of this TOR?
    I'm using the "Suspicious Activity Tracker" from the vbseo team, which sends a mail everytime the datastore table is changed:

    http://www.vbseo.com/f5/faqs-rogue-p...62/#post326304

    (You need to enter your email adress at the vb options after installation to receive the mail.)

    And i also installed the "Check 4 hack" pluging from vbulletin.org which resets the datastore table automatically:

    http://www.vbulletin.org/forum/showthread.php?t=265866

    But that's all just a bandaid which doesn't solve the problem.

  7. #52
    Member Array
    Real Name
    Davide
    Join Date
    Jan 2009
    Posts
    35
    Liked
    2 times
    Quote Originally Posted by Sparkiller View Post
    I'm using the "Suspicious Activity Tracker" from the vbseo team, which sends a mail everytime the datastore table is changed:

    http://www.vbseo.com/f5/faqs-rogue-p...62/#post326304

    (You need to enter your email adress at the vb options after installation to receive the mail.)
    Yes, I have it, but no response from it.

    Quote Originally Posted by Sparkiller View Post
    And i also installed the "Check 4 hack" pluging from vbulletin.org which resets the datastore table automatically:

    Check 4 Hack - Finds infected Datastore Entries - vBulletin.org Forum

    But that's all just a bandaid which doesn't solve the problem.
    This is new for me, thanks.

    BTW, is it possible that now the hacker enters the forum using the file install/upgrade.php?
    Probably he previously discovered the license number and now he can do what he wants.

    P.S. And surely the hacker is a VBulletin and VBSeo user, and he has the latest versions of the programs. Maybe he is also reading this thread.

  8. #53
    Junior Member Array
    Real Name
    Martin
    Join Date
    Apr 2007
    Posts
    16
    Liked
    0 times
    Quote Originally Posted by Bmastro View Post
    Yes, I have it, but no response from it.
    Did you enter a mail adress in the corresponding vb options menu? (top entry)

    BTW, is it possible that now the hacker enters the forum using the file install/upgrade.php?
    Probably he previously discovered the license number and now he can do what he wants.
    I checked the time of the email with my server log and the only fitting entries tried to access search.php in the root:

    http://www.vbseo.com/f3/hacked-url12...tml#post332574

    But i'm no expert, so i'm not sure if that means anything. And i don't think knowing the license no. gives the hacker automatically access to anything?

  9. #54
    Member Array
    Real Name
    Davide
    Join Date
    Jan 2009
    Posts
    35
    Liked
    2 times
    Quote Originally Posted by Sparkiller View Post
    Did you enter a mail adress in the corresponding vb options menu? (top entry)
    Yes I did, but no answer till now.

  10. #55
    Junior Member Array
    Real Name
    Martin
    Join Date
    Apr 2007
    Posts
    16
    Liked
    0 times
    Quote Originally Posted by Bmastro View Post
    Yes I did, but no answer till now.
    Did you get hacked again since entering the email adress? It's only send out at the same moment the datastore table is changed by the culprit.

    Or perhaps the mail was automatically moved into your spam folder.

  11. #56
    Member Array
    Real Name
    Davide
    Join Date
    Jan 2009
    Posts
    35
    Liked
    2 times
    Quote Originally Posted by Sparkiller View Post
    Did you get hacked again since entering the email adress?
    Yes, 2 times.

    Quote Originally Posted by Sparkiller View Post
    Or perhaps the mail was automatically moved into your spam folder.
    WTF! Maybe you're right.

    Edit: No, I checked. No messages from VBSEO Suspicious Activity Tracker

  12. #57
    Junior Member Array
    Real Name
    Benjamin
    Join Date
    Jul 2010
    Posts
    8
    Liked
    0 times
    And here we go again.

    Can anyone tell me how I can delete this code from the faq.php?


  13. #58
    Member Array
    Real Name
    Davide
    Join Date
    Jan 2009
    Posts
    35
    Liked
    2 times
    Yes, your forum has the redirection.
    I've seen that you run VB Version 4.1.11, would you consider to install the last one (4.2.0 patch level 2)?

    BTW is it possible to delist from the web that website? or the other (myfilestore.com)?

  14. #59
    Junior Member Array
    Real Name
    Benjamin
    Join Date
    Jul 2010
    Posts
    8
    Liked
    0 times
    I know that it does have the redirect issues
    I just wanted to know how to remove the malicious code from the two displayed files.

    I have another forum running 4.2 and the users hated the activity stream to be honest...

  15. #60
    Member Array
    Real Name
    Davide
    Join Date
    Jan 2009
    Posts
    35
    Liked
    2 times
    Quote Originally Posted by Ducati1 View Post
    I know that it does have the redirect issues
    I know that you know.
    I wrote in such a way because when I went to your forum I did not notice any redirection... because my browser already had the cookie of url123.info! Then, when I cleaned the browser, I saw the problem.

    Have you tried upgrading VBulletin to clean the forum?

Page 4 of 11 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 LastLast

Similar Threads

  1. vBulletin 3.x Hacked
    By jimjam in forum Troubleshooting
    Replies: 27
    Last Post: 01-27-2012, 12:53 PM
  2. hacked??
    By genusis in forum Off-Topic & Chit Chat
    Replies: 2
    Last Post: 09-13-2007, 05:11 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •