Page 1 of 2 1 2 LastLast
Results 1 to 15 of 26

file2store issue is back?

This is a discussion on file2store issue is back? within the Bug Reporting forums, part of the vBSEO SEO Plugin category; http://www.vbseo.com/f3/security-issue-41463/ What's the final verdict? I followed all the steps in the thread above (secure pw, changed admin dir, CHMOD), ...

  1. #1
    Junior Member
    Real Name
    Carl
    Join Date
    Nov 2007
    Posts
    14
    Liked
    0 times

    file2store issue is back?

    Security issue

    What's the final verdict? I followed all the steps in the thread above (secure pw, changed admin dir, CHMOD), but it seems that the problem keeps coming back.

    Running vBSEO 3.5.2 and vBulletin 3.8.4 PL2

  2. #2
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,100
    Liked
    622 times
    Blog Entries
    4
    You need to make sure your file and folder permissions are correctly set. That issue has nothing to do with vBSEO.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  3. #3
    Junior Member
    Real Name
    Carl
    Join Date
    Nov 2007
    Posts
    14
    Liked
    0 times
    Do you have any pointers on where to look?

    644 for files, and 755 for folders -- right?

  4. #4
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,100
    Liked
    622 times
    Blog Entries
    4
    Yes but you also need to search for suspected files on your server as highlighted in the thread you linked. I advise you to read that thread carefully.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  5. #5
    Junior Member
    Real Name
    Carl
    Join Date
    Nov 2007
    Posts
    14
    Liked
    0 times
    Thanks Mert, I will go through the entire thread today and then report back.

    Also, just wanted to update those interested on the current behavior: It first redirects to file2store.info, and then it redirects again to smartphonegalaxy.info...

  6. #6
    Junior Member
    Real Name
    Carl
    Join Date
    Nov 2007
    Posts
    14
    Liked
    0 times
    I found _error.php file in customavatars with malicious code, however this directory already had the relevant .htaccess. Deleted.

    I also found one directory where I had forgotten to add the .htaccess. Inside, there were 3 core.xxxx files each 11-14 megabytes. They were encrypted, but I could see some commands calling vbseo, so I'm guessing this is malicious too. Deleted all 3 files and added .htaccess.

    Hoping that this problem won't come back.

  7. #7
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    If you're constantly under attack, it may be a wise decision to move all your rules to httpd.conf and then set AllowOverride to No so that htaccess files can't be renamed or re-coded at all.

  8. #8
    Junior Member
    Real Name
    Carl
    Join Date
    Nov 2007
    Posts
    14
    Liked
    0 times
    The problem is back... I'll check permissions again, but I'm positive everything is set up correctly now. In the meantime, is there anything else I can do?

    What I've already done:
    - Changed admin dir
    - Changed all admin passwords so that they are super secure
    - CHMOD 644 for files and 755 for folders
    - Added the recommended .htaccess in directories with 777 permission
    - Scanned via SSH for base64 code and removed malicious files

    Edit: Just searched through my MySQL database for "base64" and "file2store" and found nothing.

  9. #9
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    check your upload directories (all that are writable) for any rogue scripts. usually its easy to find a php file amongst images/etc.

  10. #10
    Junior Member
    Real Name
    Carl
    Join Date
    Nov 2007
    Posts
    14
    Liked
    0 times
    I found some before. Although they were deleted, this still keeps happening. Do you have any further suggestions? :(

    My temporary solution is to disable and enable vBSEO, but every time I check (daily), it's back again.

  11. #11
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    They must be still be able to get into a writable file or directory or you missed one of their previously uploaded scripts. That's really the only way this can still be happening.

  12. #12
    Junior Member
    Real Name
    Carl
    Join Date
    Nov 2007
    Posts
    14
    Liked
    0 times
    Thanks for the help. Through the steps listed above, it seems that something was fixed. It now no longer redirects to smartphonegalaxy.info. Previously, it would first redirect to file2store, and then smartphonegalaxy.info.

    I've checked all directories and used different grep searches, so I don't know what I'll do.

    Will upgrading to vBulletin 4 fix this?

    There were a lot of people with this problem, how did they go about fixing it? Are there those who've succeeded without vB4?

  13. #13
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    The issue isn't related to vb or vbseo at all. It's from writable files and directories. Upgrading to vb4 won't fix anything.

  14. #14
    Junior Member
    Real Name
    Carl
    Join Date
    Nov 2007
    Posts
    14
    Liked
    0 times
    Quote Originally Posted by Brian Cummiskey View Post
    The issue isn't related to vb or vbseo at all.
    Google "file2store vbseo" or "file2store vbulletin". Compare results with "file2store phpbb" "file2store invision" or "file2store drupal". How can you say that this isn't related to vB/vBSEO?

    Quote Originally Posted by Brian Cummiskey View Post
    It's from writable files and directories.
    If this is true, can you please check the steps I've done and tell me what I've missed?

  15. #15
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,100
    Liked
    622 times
    Blog Entries
    4
    We are sure because boards that don't have vBSEO installed faced this issue. If you read the thread i supplied to you , you can also see this.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

Page 1 of 2 1 2 LastLast

Similar Threads

  1. Replies: 36
    Last Post: 07-01-2010, 07:38 PM
  2. vBulletin 3.x file2store.info Exploit
    By DieselMinded in forum Bug Reporting
    Replies: 1
    Last Post: 03-16-2010, 12:14 AM
  3. And we're back!
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 3
    Last Post: 10-25-2009, 06:57 AM
  4. I'm Back
    By friscogal in forum Introduce Yourself
    Replies: 3
    Last Post: 11-03-2008, 02:02 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •