Page 1 of 21 1 2 3 4 5 6 7 8 9 10 11 12 13 14 ... LastLast
Results 1 to 15 of 309
Like Tree2Likes

Security issue

This is a discussion on Security issue within the Bug Reporting forums, part of the vBSEO SEO Plugin category; Just want to let you know, that our forum running with vBulletin 3.8 / vBSEO 3.3x got manipulated by an ...

  1. #1
    Junior Member Lagaf's Avatar
    Real Name
    Dominik
    Join Date
    Feb 2006
    Posts
    8
    Liked
    0 times

    Exclamation Security issue

    Just want to let you know, that our forum running with vBulletin 3.8 / vBSEO 3.3x got manipulated by an attacker yesterday. Visitors attempting to visit our website via Google where instead redirected to an URL "http://url2short.info/5dfcf739". We lost about 50% of our daily visitors by these circumstances.

    After deactivating the add-on vBSEO the problem disappeared within seconds. Then we upgraded to vBSEO 3.5 and everything was fine.

    Today additional websites - running with vBSEO 3.3x too - are reporting the same problems, f.e. here:

    Been directed to another site instead of the forum - MyP2P Forum

    I hope you find a solution soon, that security hole can't be tolerated at all.

    Greetings from Germany,

    Dominik aka Lagaf
    tutorials.de - User helfen Usern: Forum & Hilfe

  2. #2
    vBSEO Staff Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,689
    Liked
    157 times
    Hello,

    please try to uninstall and then reinstall vBSEO xml product file, looks like the plugin code was modified by a malicious script on your server.

    It means that the redirect issue is not in vBSEO itself, but some other script has modified vBSEO's plugin code to do that.
    Oleg Ignatiuk / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  3. #3
    Member
    Real Name
    Danny
    Join Date
    Aug 2008
    Posts
    36
    Liked
    0 times
    I have this exact same problem. Absolute nightmare. Oleg could you please explain this in as much detail as you can?;

    please try to uninstall and then reinstall vBSEO xml product file,
    I;

    Admin CP-> Plugin & Products System -> Uninstalled vBSEO
    Downloaded a fresh a copy of 3.3.0 from here.
    Installed just the vbSEO xml file.

    That correct?

  4. #4
    vBSEO.com Webmaster Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    22,367
    Liked
    542 times
    Blog Entries
    4
    Hello Danny ,

    That is correct .

    Is there any specific modification you guys installed lately ?
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  5. #5
    Member
    Real Name
    Danny
    Join Date
    Aug 2008
    Posts
    36
    Liked
    0 times
    Thanks Mert. Appreciated.

    No, none at all. It was definitely vbSEO that was causing the issue. I only have a few mods installed and through trial and elimination, vBSEO was the cause. Since following the above, the issue has gone for now.

    I would expect an influx of this alert, probably wise to stick a thread...

  6. #6
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,782
    Liked
    648 times
    Blog Entries
    2
    It looks like you last downloaded (prior to today) before our security alert from last fall:
    vBSEO Security Bulletin - vBSEO 3.3.2 Released

    Did you have this patch installed?
    Brian Cummiskey / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  7. #7
    Member
    Real Name
    Danny
    Join Date
    Aug 2008
    Posts
    36
    Liked
    0 times
    I can't say with 100% confidence sorry Brian. I had an bad experience with vbSEO (no improvement) so neglected the forums.

    To be safe I just installed that patch. Thanks

  8. #8
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,782
    Liked
    648 times
    Blog Entries
    2
    All downloads in the download area are pre-patched.

    Odds are, if you weren't patched from this previous exploit, that's likely how they got in. I'd recommend changing EVERY password you have... forums, ftp, email, root, etc on ALL your sites on your server.
    Brian Cummiskey / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  9. #9
    Member
    Real Name
    Danny
    Join Date
    Aug 2008
    Posts
    36
    Liked
    0 times
    Will be sure to do that. Changed all passwords I'm able to (cpanel/forums/email/ftp etc etc). I'm assuming I'll also need to inform my server?

    Thanks again Brian - On the surface it may be an idea to patch the downloads in the download area.

  10. #10
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,782
    Liked
    648 times
    Blog Entries
    2
    Yes, change every password that you can. Who knows what they might have gained access to.

    And yes, all downloads have already been updated to include the patches.
    Brian Cummiskey / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  11. #11
    Junior Member
    Real Name
    tkam
    Join Date
    Jun 2008
    Posts
    3
    Liked
    0 times
    I am seeing this exact same thing, it only started after i updated vb 4.01 to 4.02 and vbseo 3.5 rc 2 pre release to the rc2 final. When any pages from my forum show up in google the first time you click the links it re-directs to the url2short.info page. If I go back and click again it takes me to the proper page.

  12. #12
    Junior Member
    Real Name
    Rolf
    Join Date
    Jun 2008
    Location
    Reading, Berkshire
    Posts
    24
    Liked
    0 times

    Same problem here

    Had this happen the other day and was told to update to to 3.3.2, did this and it was OK for 3 days, but is now exhibiting the same symptoms, as is our sister site using vb4.02 and vbseo 3.5.0 RC2.

    This is not a cache page, caches were cleared.

    _http://filestore73.com/download.php?id=AE41AB38

    Edit, support ticket was answered on sister site, appears to have stopped doing it now, just going to put in support ticked on my site.

  13. #13
    vBSEO Staff Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,689
    Liked
    157 times
    Edit, support ticket was answered on sister site, appears to have stopped doing it now, just goint to put in support ticked on my site.
    Replied to that ticket - I did not change anything, just re-enabled vBSEO and the issue couldn't be reproduce, hence I supposed the redirected URL was cached on browser side.
    Oleg Ignatiuk / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  14. #14
    Junior Member
    Real Name
    tkam
    Join Date
    Jun 2008
    Posts
    3
    Liked
    0 times
    i ended up just uninstalling vbseo and re-uploading all the files from a freshly downloaded copy and then reinstalling vbseo. it seems to have fixed the problem and I hope it's a permanent fix because the only response i got to my ticket here is

    "if your sure you have the latest files you should change all the passwords you can"

    super useful.

  15. #15
    vBSEO Staff Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,689
    Liked
    157 times
    I would also recommend to check your site for possible malicious files in writable folders as described in:
    vBSEO Security Bulletin - vBSEO 3.3.2 Released

    and create .htaccess files in those folders: vBSEO Security Bulletin - vBSEO 3.3.2 Released
    Oleg Ignatiuk / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


Page 1 of 21 1 2 3 4 5 6 7 8 9 10 11 12 13 14 ... LastLast

Similar Threads

  1. Security issue with filevbseo_getsitemap.php
    By mihai11 in forum Bug Reporting
    Replies: 3
    Last Post: 11-05-2008, 03:34 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •