Page 1 of 11 1 2 3 4 5 6 7 8 9 10 11 LastLast
Results 1 to 15 of 152
Like Tree31Likes

Url123 Redirect. Tried everything, I am at wits end.

This is a discussion on Url123 Redirect. Tried everything, I am at wits end. within the Security Topics forums, part of the vBSEO SEO Plugin category; I have changed all pws, checked for ftp accounts, made sure I had no external mysql connections, rebuilt the parsed ...

  1. #1
    Member Array
    Real Name
    Bill Belcamino
    Join Date
    Nov 2008
    Posts
    58
    Liked
    3 times

    Question Url123 Redirect. Tried everything, I am at wits end.

    I have changed all pws, checked for ftp accounts, made sure I had no external mysql connections, rebuilt the parsed templates to make sure they had no malicious code. Checked for base64 in both templates and plugins.

    CHMOD all folders to 644 unless needed for users (like avatars), those that are 777 write-able have .htaccess files protecting them from executing php.

    Checked all plugins (all are known to me). Deleted ones that I didn't use or didn't trust.

    Had my host scan for viruses.

    VBSEO is 3.5.2, not current version.

    And yet... every few hours it comes back.

    I am not blaming VBSEO, but their staff has helped in the past, so I am posting here.

    Can anyone help?

    Bill

  2. #2
    Member Array
    Real Name
    Bill Belcamino
    Join Date
    Nov 2008
    Posts
    58
    Liked
    3 times
    Update:

    Just updated to vbulletin 3.8.7 patch lvl3

    But I am mistaken, I am running VBSEO 3.5.2, will upgrading to 3.6 help?

  3. #3
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    721 times
    Blog Entries
    4
    Hello ,

    Url redirect issue is a server security issue. It is not related to vBSEO , however you should always run latest released stable vBSEO versions.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  4. #4
    Member Array
    Real Name
    Bill Belcamino
    Join Date
    Nov 2008
    Posts
    58
    Liked
    3 times
    I've heard. Where do you suggest I go to get some support for the server security issue?

    Bill

  5. #5
    Member Array
    Real Name
    Bill Belcamino
    Join Date
    Nov 2008
    Posts
    58
    Liked
    3 times
    Lastly, the Check cB instance for suspicious plugins (v4) shows this when I am being redirected:

    vBSEO - Check vB instance for suspicious plugins (v4)
    Checking datastore pluginslist: DETECTED: eval(CHR [Click here to reset datastore]
    ---------------------
    Checking plugins code
    ---------------------
    Done.

    Does that help in any way?

  6. #6
    Member Array
    Real Name
    Bill Belcamino
    Join Date
    Nov 2008
    Posts
    58
    Liked
    3 times
    Also installed the plugin monitoring tool and verified it is working.

    I will send the report it gives me.

    (Thanks for your help).

  7. #7
    Member Array
    Real Name
    Bill Belcamino
    Join Date
    Nov 2008
    Posts
    58
    Liked
    3 times
    Moved my discussion here to a larger thread (feel free to close this one):

    http://www.vbseo.com/f3/hacked-url12...45/index5.html

  8. #8
    Senior Member Array I, Brian's Avatar
    Join Date
    Sep 2005
    Location
    Scotland
    Posts
    132
    Liked
    1 times
    That thread got locked.

    The vbseo developers say there's no correlation between the 123url.info hacking and vbseo.

    And yet the vbseo board is flooded with reports of being hacked, but there are only a couple on vbulletin.com - from vbseo owners.

    Hard not to conclude there's an exploit somewhere related to vbseo.

  9. #9
    Member Array
    Real Name
    Bill Belcamino
    Join Date
    Nov 2008
    Posts
    58
    Liked
    3 times
    Well, still no proof it was VBSEO and frankly I am just glad it is fixed so I can resume normal operations.

  10. #10
    Member Array
    Real Name
    Diego
    Join Date
    Oct 2009
    Posts
    54
    Liked
    7 times
    belcamino fixed temporary (like before) or malware is gone forever? and how did you fixed? removing "register_globals"?

  11. #11
    Member Array
    Real Name
    Davide
    Join Date
    Jan 2009
    Posts
    35
    Liked
    2 times
    Disabling register_globals is enough? Without reinstalling all?

  12. #12
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    721 times
    Blog Entries
    4
    Hello Brian ,

    The thread is locked as many people are posting wrong information. I can quickly find 20-30 link on vBulletin with the exact same issue. Attackers are targetting vBSEO because they know vBSEO users are having good traffic so they will make money with the attacks.

    We investigated the report Topas supplied ( who claimed it was a vBSEO issue ) and it is directly related to register_global on his case.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  13. #13
    Member Array
    Real Name
    Davide
    Join Date
    Jan 2009
    Posts
    35
    Liked
    2 times
    Hello Mert, what about my question?
    If we had problems only with register_global, is enough disabling it without reinstalling VBulletin and Vbseo?
    Thanks in advance

  14. #14
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    721 times
    Blog Entries
    4
    Hello David ,

    The safest thing to do imo :

    1. Search your public dir for any suspicious files
    2. Disable register_global
    3. Make sure your server has correct user - privillege's set
    4. Protect chmod 777 directories
    5. Make sure your server doesn't allow wildcard remote MySQL connection
    6. Replace all passwords on your ftp , admincp , vbseo cp , db etc... with strong informtion
    7. Use custom config.php file
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  15. #15
    Senior Member Array I, Brian's Avatar
    Join Date
    Sep 2005
    Location
    Scotland
    Posts
    132
    Liked
    1 times
    Quote Originally Posted by Mert Gökçeimam View Post
    I can quickly find 20-30 link on vBulletin with the exact same issue. Attackers are targetting vBSEO because they know vBSEO users are having good traffic so they will make money with the attacks.

    We investigated the report Topas supplied ( who claimed it was a vBSEO issue ) and it is directly related to register_global on his case.
    The few examples I've seen on vbulletin have vbseo'd forums in their sig links.

    By saying that vbseo is specifically attacked, you seem to be admitting that the vulnerability is specific to vbseo. Or are you saying that the way vb handles plugins in general is the vulnerability?

    Either way, I've been 24hours without an attack since having register_globals switched to off - sincerely hoping this is the end of it.

Page 1 of 11 1 2 3 4 5 6 7 8 9 10 11 LastLast

Similar Threads

  1. Hilfe bei Highjacking auf url123.info
    By cool-andy in forum Deutsch
    Replies: 3
    Last Post: 11-23-2012, 08:08 AM
  2. hacked by url123.info
    By fade in forum Security Topics
    Replies: 151
    Last Post: 07-12-2012, 10:37 AM
  3. Need 301 Redirect Help redirect to default vb urls
    By s2kinteg916 in forum General Discussion
    Replies: 1
    Last Post: 01-27-2010, 03:18 AM
  4. linklerde neden böle redirect-to/?redirect
    By samet54 in forum Türkçe
    Replies: 2
    Last Post: 10-14-2008, 05:45 AM
  5. Replies: 5
    Last Post: 07-06-2008, 05:39 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •