Page 10 of 13 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 12 13 LastLast
Results 136 to 150 of 190

vBSEO Security Bulletin - vBSEO 3.3.2 Released

This is a discussion on vBSEO Security Bulletin - vBSEO 3.3.2 Released within the vBSEO Announcements forums, part of the Announcements & Pre-Sales category; Thanks for the response. I know patching is not optional. I'll try to patch if we have problems I'll do ...

  1. #136
    Junior Member
    Real Name
    Diego
    Join Date
    Aug 2006
    Posts
    22
    Liked
    0 times
    Thanks for the response. I know patching is not optional. I'll try to patch if we have problems I'll do a full upgrade on that particular site.

    One other question. Does patching put branding back on brand free sites? (I have no idea whether branding removal is done in the core PHP or elsewhere such as plugin)

  2. #137
    Senior Member
    Real Name
    Michael Biddle
    Join Date
    Jan 2007
    Location
    Southern California
    Posts
    7,097
    Liked
    5 times
    Quote Originally Posted by eksodos View Post
    Thanks for the response. I know patching is not optional. I'll try to patch if we have problems I'll do a full upgrade on that particular site.

    One other question. Does patching put branding back on brand free sites? (I have no idea whether branding removal is done in the core PHP or elsewhere such as plugin)
    Hello,

    It will not affect it. The branding free is in your vbseo key.
    The Forum Hosting - Forum Hosting from the Forum Experts

  3. #138
    Junior Member
    Real Name
    Michael
    Join Date
    Feb 2006
    Posts
    12
    Liked
    0 times
    Sadly my site was compromised; as I was out of town, I didnt see this until today.

    They got in on the 19th using vbseo.php; planted a couple php scripts in my customprofilepics, albums and customavatars directories.

    I have yet to determine what they may have done in the process - so far nothing seems damaged, although they did manage to do something I am curious just how they managed.

    The scripts were also executed on the 20th and 22nd for short bursts.

    EDIT: They were able to install a rootkit and get root access. Changed my root password (costing me a service call to reboot and change my root password. Running rkhunter and cleaning up some stuff.

  4. #139
    Junior Member
    Real Name
    Danny Cooper
    Join Date
    Jul 2007
    Posts
    25
    Liked
    0 times
    Removed text so I don't freak anyone out.

  5. #140
    Senior Member
    Real Name
    Ceri May
    Join Date
    Jul 2009
    Location
    United Kingdom
    Posts
    1,726
    Liked
    15 times
    Blog Entries
    1
    Hi Danny,

    It is more probable that someone planted a backdoor onto your server before you patched and has waited until now to activate it. There are a number of suggestions in this thread in detecting and removing these files but they are normally very well hidden.

    Ceri
    Last edited by Ceri May; 12-08-2009 at 11:53 AM.

  6. #141
    Junior Member
    Real Name
    Danny Cooper
    Join Date
    Jul 2007
    Posts
    25
    Liked
    0 times
    Hi Ceri - I found a backdoor that had been installed. I edited my post so that I don't cause any hysteria.

  7. #142
    Junior Member Endurer's Avatar
    Real Name
    Endurer
    Join Date
    May 2007
    Posts
    28
    Liked
    0 times
    Latest to get hit by the centiyo iframe all over the place. I have now upgraded vbseo to 3.2.2 and removed the shell from profile pics directory.

    PS: A user registered at my site, uploaded a GIF file that had this executable php code in it and ran it through vbseo.php - If your board was compromised, watch out for a similar GIF/JPEG file in your server's writabe directories.

    Thanks vbseo!

  8. #143
    Member
    Real Name
    Veerachai
    Join Date
    Feb 2009
    Location
    London, UK
    Posts
    51
    Liked
    0 times
    I have this problem centiyo ifram 4 tiems already
    I just upgrade to 3.2.2
    let's see itiwill happen again

  9. #144
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    Make sure you've cleared the php script in the uploaded directory and have changed all of your admin account and server account passwords.

  10. #145
    Member
    Real Name
    Veerachai
    Join Date
    Feb 2009
    Location
    London, UK
    Posts
    51
    Liked
    0 times
    already upgraded 3.2.2 and changed server password adn all admin password
    and removed all .php from upload dir
    Infect again today

    any way to protect this ?

  11. #146
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    Please open a ticket with a copy of your access log showing the exploit. It will help us determine what was accessed and how, or if it was already on your server.

  12. #147
    Member
    Real Name
    Veerachai
    Join Date
    Feb 2009
    Location
    London, UK
    Posts
    51
    Liked
    0 times
    Where can i get access log from ?
    which access log ?

    if it's apache access log i didn't enable it.

  13. #148
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    Yes, the access_log from apache.

    I highly suggest enabling it as it will help you pinpoint intrusions such as this. Without the log file, there's really no way to find out how they got in.

    We have had NO reports of people being hacked since the 2nd 3.3.2 patch and a clean(ed) system.

  14. #149
    Member
    Real Name
    Veerachai
    Join Date
    Feb 2009
    Location
    London, UK
    Posts
    51
    Liked
    0 times
    Thank you
    I wil enable apache logfile now
    if it happen again i will open ticket

  15. #150
    Member
    Real Name
    Veerachai
    Join Date
    Feb 2009
    Location
    London, UK
    Posts
    51
    Liked
    0 times
    I fond some one have pproblem

    Quote Originally Posted by ekool
    Just happened to a site of ours here, we are running 3.8.4pl1 and vBSEO 3.3.2 -- both the latest versions. Any other ideas?

    Iframe MYSQL Injection (http://centiyo.com/in.cgi?default)

Page 10 of 13 FirstFirst 1 2 3 4 5 6 7 8 9 10 11 12 13 LastLast

Similar Threads

  1. [How to] Get the most Security for vBSEO
    By marco1 in forum Member Articles
    Replies: 8
    Last Post: 01-09-2009, 01:23 PM
  2. JELSOFT SECURITY BULLETIN - vBulletin 3.6.8 Patch Level 1 Released
    By vBulletin.com Staff in forum vBulletin.com Announcements
    Replies: 0
    Last Post: 11-08-2007, 02:38 PM
  3. Replies: 20
    Last Post: 11-22-2006, 05:06 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •