Results 1 to 3 of 3
Like Tree2Likes
  • 1 Post By Brian Cummiskey

VBSEO Issues: Possibly hacked?

This is a discussion on VBSEO Issues: Possibly hacked? within the Bug Reporting forums, part of the vBSEO SEO Plugin category; All, Having a very weird problem with VBSEO on our forum. A little bit of background first for you guys: ...

  1. #1
    Junior Member
    Real Name
    Joey
    Join Date
    Mar 2011
    Posts
    10
    Liked
    0 times

    VBSEO Issues: Possibly hacked?

    All,

    Having a very weird problem with VBSEO on our forum. A little bit of background first for you guys: We recently upgraded to vB4 and installed a fresh copy of VBSEO. Previously on vB3 we had VBSEO running as well and had zero problems or issues.

    Fast forward to the present with vB4 and VBSEO currently on our forum. It runs fine and performs as expected unless there is an attempt to make changes via VBSEO Control Panel. We properly edit the permissions so the config.xml file is writeable. However, once we go into the Control Panel all hell breaks loose. Right away you can see something is wrong as the license key says invalid. However, we confirmed with VBSEO that the license key is in fact valid and the proper one is sitting in the line.

    Here is where is get real weird. After any change is attempted in the Control Panel the links to posts and forums on our site go dead. Upon further inspection it was discovered that a vast amount of junk code was being added to the config.xml file when the file is opened to edit.

    The junk code starts with:
    <name>VBSEO_REFBACK_BLACKLIST</name>
    <value><![CDATA[google\\\\

    and it keeps going on with about 150 lines of false code.

    It's defiantly not a server issue but a some kind of hack. I am really curious as to how this happened as i don't have too many plugins on the forum (all of which are either professional plugins or trusted ones on vbulletin.org) and i feel our security is pretty established.

    As for now i am really not sure where to go with this issue. As i stated before it is running fine as we leave it alone, but i would like to go in and make some simple changes. Has anyone every experienced anything like this before? Any ideas for a possible solution?

    Any help on the matter would be much appreciated. Thanks in advance for your time

    Joey

  2. #2
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    The refbak black list SHOULD look like that, a list of search engines mostly so that search hits don't record a refback.

    Code:
    <name>VBSEO_REFBACK_BLACKLIST</name>
    <value><=!=[=C=D=A=T=A=[google\..+/(u/|search|blogsearch|custom|pda|linux|ie|ig)|search\.yahoo\.|search\.msn\.|msncache\.com|altavista\.com|answers\.com|ask\.|search\.lycos\.|dogpile\.|alltheinternet\.com|tiscali\.|baidu\.|verden\.abcsok\.no|[/&\?=\.](search|arama|blogsearch|query|results|sok|srch|yandsearch|aolsearch|q)[^a-z-]|backlink_checker\.php|extremetracking\.com|www\.kvasir\.no/nettsok/searchResult|awstats\.pl\?|translate\.google\.com|suchen\.(pl|php|aspx)\?|mail\.yahoo\.com|mail\.live\.com|squirrelmail\/src\/]=]=></value>
    </setting>
    is the default code block


    Are you running mod_Secuirty or suhosin on the server which may eat form input? It looks like your server is adding slashes to stuff that it shouldn't.
    g00gl3r likes this.
    Brian Cummiskey / Crawlability Inc.
    Security vbulletin - Patch Level for all supported versions released!

    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  3. #3
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    this CK editor is such a POS. it ate half of the real code in code tags.

    how about an image?
    refbackblacklist.jpg

Similar Threads

  1. vBulletin 4.x vbSEO Sitemap Generator hacked?
    By Hendricius in forum Troubleshooting
    Replies: 8
    Last Post: 05-08-2011, 02:59 PM
  2. vBulletin 4.x vBSEO Hacked - Cloaking Cialis Ads
    By schlottke in forum Troubleshooting
    Replies: 6
    Last Post: 04-27-2011, 06:38 AM
  3. vBulletin 3.x vBSEO Hacked On A Dedicated Server
    By neociti in forum Troubleshooting
    Replies: 4
    Last Post: 02-01-2010, 12:13 AM
  4. Vbseo.com hacked or pentrated right now ?
    By Future in forum Off-Topic & Chit Chat
    Replies: 6
    Last Post: 11-03-2009, 02:48 PM
  5. IMPORTANT: boards gone because of vbseo or hacked
    By the nwo in forum General Discussion
    Replies: 12
    Last Post: 03-18-2008, 02:33 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •