Page 1 of 2 1 2 LastLast
Results 1 to 15 of 28
Like Tree2Likes

Hacked

This is a discussion on Hacked within the Troubleshooting forums, part of the vBSEO SEO Plugin category; Yesterday, I immediately carried out the code changes in the recent security announcement, but this morning I have a zillion ...

  1. #1
    Member Array
    Real Name
    JB
    Join Date
    Oct 2007
    Posts
    73
    Liked
    2 times

    Hacked

    Yesterday, I immediately carried out the code changes in the recent security announcement, but this morning I have a zillion DB errors in my inbox and my links are red. I have trawled through a ton of pages in the announcement thread but still no fix. And that thread is closed

    Can someone please post a simple idiots guide to fixing this exploit or at least open the thread. Thanks

  2. #2
    Junior Member Array
    Real Name
    Nook
    Join Date
    Jul 2008
    Posts
    29
    Liked
    0 times
    oh got the same. i don't know why, but after few times i disable and enable vbseo, everything went fine again

  3. #3
    Junior Member Array
    Real Name
    Nook
    Join Date
    Jul 2008
    Posts
    29
    Liked
    0 times
    so, what i noticed, the color of links caused by css of database error that appears in the bottom

    error was this:
    Database error in vBulletin 3.8.7:

    Invalid SQL:
    SELECT * FROM vb_datastore WHERE title='pluginlist';


    hope to hear something from vbseo staff

  4. #4
    Member Array
    Real Name
    JB
    Join Date
    Oct 2007
    Posts
    73
    Liked
    2 times
    I disabled VBSEO to check that it was this mod causing the problems, and the forums worked fine, then reenabling VBSEO seemed to make everything good, no more errors and no more red links. I feel this is a just an interim fix and its not over yet, but if you have not disabled/enabled VBSEO yet, give it a go.

  5. #5
    vBSEO Staff Array Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    675 times
    Blog Entries
    2
    Please try re-importing the vbseo product XML file into the adminCP. This should flush out any bad code in any of the vbseo plugins and refresh the datastore.
    Brian Cummiskey / Crawlability Inc.
    Security bulletin - Patch Level for all supported versions released

    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  6. #6
    Junior Member Array
    Real Name
    G. A.
    Join Date
    Dec 2009
    Posts
    5
    Liked
    0 times
    I have the same issue
    I used vbseo_checkplugins.php (ver 2) and it found something in datastore plugin
    Then I followed with the fix and actually I don't get database errors

    but

    how can VBSEO 3.3 users patch this? I don't have /vbseo/includes/functions_vbseocp_abstract.php

  7. #7
    Junior Member Array
    Real Name
    G. A.
    Join Date
    Dec 2009
    Posts
    5
    Liked
    0 times
    in the announcement section VBSeo staff explains that the exploit is related to this
    <script type="text/javascript" src="http://www.vbseo.com/info/vbseo_checkver.js?ver=<?php echo

    so I did remove that line from my vbseocp.php

    So actually:
    1) I did run vbseo_checkplugins2 and fixed a datastore plugin
    2) removed <script type="text/javascript" src="http://www.vbseo.com/info/vbseo_checkver.js?ver=<?php echo

    Anythingelse I need to do? I'm using VBSeo 3.3.2
    Please help

  8. #8
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    721 times
    Blog Entries
    4
    You should upgrade to latest stable vBSEO version.

    Additionally you should not remove that line.
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  9. #9
    Junior Member Array
    Real Name
    G. A.
    Join Date
    Dec 2009
    Posts
    5
    Liked
    0 times
    OK but I don't understand:
    VBSEO provided a patch for versions 3.5 and 3.6

    I have VBSeo 3.3.2, I suppose that I need to change something, to patch something, to close the vulnerability
    otherwise someone can use the same vulnerability again

    So, what I need to do for patching the vulnerability on VBSeo 3.3.2?

  10. #10
    Junior Member Array
    Real Name
    G. A.
    Join Date
    Dec 2009
    Posts
    5
    Liked
    0 times
    Moreover I can't update actually because I have a modded version (even if we didn't change the main part of the code)

  11. #11
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    721 times
    Blog Entries
    4
    vBSEO 3.3.2 does not have the vulnerability
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  12. #12
    Junior Member Array
    Real Name
    G. A.
    Join Date
    Dec 2009
    Posts
    5
    Liked
    0 times
    there's something I can't undestand.
    This morning I wake up with tons of mails pointing out this problem:
    Invalid SQL:
    SELECT * FROM vb_datastore WHERE title='pluginlist';

    I did google a bit and I found that there was a security issue with VBSeo

    I did use vbseo_checkplugins2 and it foud something wrong in datastore plugin

    And I'm not affected by the vulnerability?

  13. #13
    vBSEO.com Webmaster Array Mert Gökçeimam's Avatar
    Real Name
    Lizard King
    Join Date
    Oct 2005
    Location
    Istanbul, Turkey, Turkey
    Posts
    23,463
    Liked
    721 times
    Blog Entries
    4
    You need to run vbseo_checkpluins2 and reset your datastore
    Mert Gökçeimam / Crawlability Inc.

    vBSEO 3.6.0 Alpha Önizlemesi - Including Like Tree
    Unveiling the NEW vBSEO Sitemap Generator 3.0 - available NOW for vBSEO Customers!


    Twitter:@Depkac
    Personal Blog : Mert Gökçeimam

  14. #14
    Member Array AlpineZone's Avatar
    Real Name
    Nick
    Join Date
    Mar 2006
    Location
    Uxbridge, MA
    Posts
    44
    Liked
    0 times
    Quote Originally Posted by menbi View Post
    I have the same issue
    I used vbseo_checkplugins.php (ver 2) and it found something in datastore plugin
    Then I followed with the fix and actually I don't get database errors

    but

    how can VBSEO 3.3 users patch this? I don't have /vbseo/includes/functions_vbseocp_abstract.php
    This is the same issue I have. I am running 3.3.2 and I don't have that file either, but I was also hit with the same hack.

    I disabled / re-enabled VBSeo and I am still getting the errors, albeit intermittently. I'd like to just completely uninstall VBSeo but I'm not sure how to do that without dorking anything up.

  15. #15
    Member Array AlpineZone's Avatar
    Real Name
    Nick
    Join Date
    Mar 2006
    Location
    Uxbridge, MA
    Posts
    44
    Liked
    0 times
    Quote Originally Posted by Mert Gökçeimam View Post
    You need to run vbseo_checkpluins2 and reset your datastore
    I ran the checkplugins with no response.

    How do I reset the datastore?

Page 1 of 2 1 2 LastLast

Similar Threads

  1. Got hacked, need some help
    By ludachris in forum Troubleshooting
    Replies: 2
    Last Post: 12-02-2009, 07:35 PM
  2. I was hacked
    By goranbaxy in forum General Discussion
    Replies: 14
    Last Post: 07-31-2008, 03:15 AM
  3. hacked??
    By genusis in forum Off-Topic & Chit Chat
    Replies: 2
    Last Post: 09-13-2007, 05:11 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •