Page 11 of 21 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 LastLast
Results 151 to 165 of 309
Like Tree2Likes

Security issue

This is a discussion on Security issue within the Bug Reporting forums, part of the vBSEO SEO Plugin category; It may take a few days for Google to clear up the error on its side and start sending traffic ...

  1. #151
    vBSEO Staff Array Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    675 times
    Blog Entries
    2
    It may take a few days for Google to clear up the error on its side and start sending traffic back to your site.
    Brian Cummiskey / Crawlability Inc.
    Security bulletin - Patch Level for all supported versions released

    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  2. #152
    Senior Member Array
    Real Name
    Christian Thiessen
    Join Date
    May 2007
    Posts
    101
    Liked
    0 times
    Blog Entries
    1
    Goog Morning,
    This Hacker is intelligent.
    So what the vbSEO Team find out in my log. He visit me twice.
    Both times he edit the same plugin.
    So i think he put in the Code and 5 Days later he remove the code.

    Why that?
    His target is, that people download his malware from this free downlod sites.
    He know that the Malware will be removed from this site if discovered.
    So he need to do that on as many Target sits as possible.
    If possible he like to be undiscovered.
    To reach this target, he use a cookie, he remove the code, he let his code work only for search engine traffic.

    Due the way he did it, it look like that there was only a normal login to the adminCP.
    Reaction form vBulletin = Must be a Problem of the Admin he do not care about his password security
    Reaction form the Hacker = ROFL

    Nerver mind, it ever might happens that one of us has a porblem with his PC - A virus or whatever, even if we take care that our virus scanner is ever up to date.
    Things like this happens in the past an will happed in the future.

    but in the case there are too many forums involved. And we discovers only 3 Target sites.
    There might me many more out there.

    So the question are:

    • If he did this without password - how?
    • If he had all this password - how he get this?
    • Are there more target sites out there?
    • What should the Malware do (not important for us but for general Internet security)

    I check yesterday the ulr2short.info, form the 10 Upstream sites were 8 vBulletin (2 Google)
    On 4 of them the code was still present. I informd 3 of the webmaster (on the 4th site every click open too many ads, sorry)

    Greetings
    Christian

  3. #153
    Junior Member Array
    Real Name
    Angelo
    Join Date
    Mar 2010
    Posts
    7
    Liked
    0 times
    Goodmorning, I have the problem on my site of redirect to http://myfilestore.com/download.php/.... I have read the old post, but I have not understand.
    If you find my site justoverclok in google and if you click on "forum" from result of google, you'll be redirect in http://myfilestore.com/download.php/id...
    The problem can you see only on first clck on forum and not always.

    I have joomla 1.5.15 ,vbulletin 3.7.1 and vbseo 3.3.2
    Last edited by anjx; 03-20-2010 at 07:31 AM.

  4. #154
    Junior Member Array
    Real Name
    DM
    Join Date
    Jun 2008
    Posts
    1
    Liked
    0 times
    Are there any further results of this problem? We were affected too.

  5. #155
    Senior Member Array
    Real Name
    Christian Thiessen
    Join Date
    May 2007
    Posts
    101
    Liked
    0 times
    Blog Entries
    1
    Hi Angelo,
    Please give me you URL i will check.

    It happens only one time because a cooie is set.
    Search for the cookie "vbsp" on your Computer delete it and you are able to see if the problem is still present.
    Only if you follow Google Links.

    Than lets find your bad coode an get rid of it.
    You might disable and enable vBSEO, that clear the datasore Cache, If the code is no mor in the Plugin it helps.

    The Target site has a lot of traffic from Brasil and Italy.
    If you are Brazilian i could help in Portuguese (Italian - we need to use English)


    Greetings Christian

  6. #156
    Junior Member Array
    Real Name
    Angelo
    Join Date
    Mar 2010
    Posts
    7
    Liked
    0 times
    I'm Italian, and dont know portuguese :(
    My url is JustOverclock.com - Raffreddamento a liquido e ad aria, hardware, overclock e modding but the problem live only when go on from google.

  7. #157
    Senior Member Array
    Real Name
    Christian Thiessen
    Join Date
    May 2007
    Posts
    101
    Liked
    0 times
    Blog Entries
    1
    OK,
    yes you are infected.
    So we need to find out, were the code is.

    You need to go to your Admin CP and take a look at you Plug in codes.
    The Hacker need a global Plugin to let it work on all Sites.

    In my case he used one of the plugins at: global_start
    The code is encoded it should start with "base64"
    so you need to find tis code an delete it.

    Greetings
    Christian

  8. #158
    Junior Member Array
    Real Name
    Angelo
    Join Date
    Mar 2010
    Posts
    7
    Liked
    0 times
    Sorry but I have many files in my ftp, and I can't open all files for find this code. Have you a tip? The file that most attacked where is in vbulletin and joomla? I havent a folder o file that name is global_start.
    Sorry if i not understand

    I must find "base64" in files or base 64 is a tipe of codes?

  9. #159
    Senior Member Array
    Real Name
    Christian Thiessen
    Join Date
    May 2007
    Posts
    101
    Liked
    0 times
    Blog Entries
    1
    Hi,
    it is vBulletin related but it is not in the files its stored in the database:
    You need to go to your AdminCP:
    Entra - JustOverclock.com - vBulletin Pannello Admin

    and then - Text in Italian or English?:
    Click image for larger version. 

Name:	admincp..jpg 
Views:	1651 
Size:	163.9 KB 
ID:	6987

    Greetings
    Christian

  10. #160
    Junior Member Array
    Real Name
    Angelo
    Join Date
    Mar 2010
    Posts
    7
    Liked
    0 times
    Wow thank you

    I now can find in all file global, but i can search the voice "base64" and delete all code?

  11. #161
    Senior Member Array
    Real Name
    Christian Thiessen
    Join Date
    May 2007
    Posts
    101
    Liked
    0 times
    Blog Entries
    1
    Well you should only delete the Bad part of the code.
    I never saw that on my Forum because the code was removed and only present in the datasore cache.

    But if you fin somthng start with base64 you migth post the hole code here (inside Tags) and wee compare with our forums to what is standard an that is extra an should be deleted.

    Christian

  12. #162
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    721 times
    Blog Entries
    4
    Quote Originally Posted by anjx View Post
    Goodmorning, I have the problem on my site of redirect to http://myfilestore.com/download.php/.... I have read the old post, but I have not understand.
    If you find my site justoverclok in google and if you click on "forum" from result of google, you'll be redirect in http://myfilestore.com/download.php/id...
    The problem can you see only on first clck on forum and not always.

    I have joomla 1.5.15 ,vbulletin 3.7.1 and vbseo 3.3.2
    Please try asking license owner to add you to Priority Support within their customer profile.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  13. #163
    Junior Member Array
    Real Name
    Angelo
    Join Date
    Mar 2010
    Posts
    7
    Liked
    0 times
    I have see in this plugin but I havent find "base64"

  14. #164
    Junior Member Array
    Real Name
    Angelo
    Join Date
    Mar 2010
    Posts
    7
    Liked
    0 times
    In a module I find two sospected link to site of manga, I have delete it and the problem is vanished. You can confirmed?

  15. #165
    Senior Member Array
    Real Name
    Christian Thiessen
    Join Date
    May 2007
    Posts
    101
    Liked
    0 times
    Blog Entries
    1
    Hi.
    looks OK now.
    You should read the howl Thread and put som extra protection on you Admin CP.
    Rename and/or .htaccess Protection.

    Christian

Page 11 of 21 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 LastLast

Similar Threads

  1. Security issue with filevbseo_getsitemap.php
    By mihai11 in forum Bug Reporting
    Replies: 3
    Last Post: 11-05-2008, 02:34 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •