Help Hackers hacked my vBulletin Forum

Discussion in 'vBulletin' started by Davey Crocket, Sep 2, 2006.

  1. #1
    My forum www.orchidgeeks.com has been hacked by Russian hackers

    When you go to orchidgeeks.com/forum (I think you might have to be logged in to view it) the page re-directs to http://dengesiz-team.org/vb.htm.

    How do I remove or fix this? I need help asap as non of my members can really post a message.
     
    Davey Crocket, Sep 2, 2006 IP
  2. Nintendo

    Nintendo ♬ King of da Wackos ♬

    Messages:
    12,890
    Likes Received:
    1,064
    Best Answers:
    0
    Trophy Points:
    430
    #2
    Use the back-up, and if any files were edited, re-upload them and set the permission so they can't be writen over. And make sure they don't have any of your passwords. aka...changing passwords might be a good idea.
     
    Nintendo, Sep 2, 2006 IP
  3. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #3
    You running either of these mods by chance?
     
    digitalpoint, Sep 3, 2006 IP
  4. dcristo

    dcristo Illustrious Member

    Messages:
    19,776
    Likes Received:
    1,200
    Best Answers:
    7
    Trophy Points:
    470
    Articles:
    7
    #4
    Shit dude, first time I have heard of a vB board getting hacked. Hopefully you had a backup.
     
    dcristo, Sep 3, 2006 IP
  5. reteep

    reteep Active Member

    Messages:
    181
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    58
    #5
    Well, actually Dengesiz is turkish, if you check out the flag and language on their site ;).

    This happened to me, too, one week ago, same Team, they're script kiddies from turkey.

    They hacked my vBulletin 3.6.0 musician board (over 40 000 members). However, it has not been a vBulletin flaw and they were just able to change the index.php. Flashchat has various security flaws and they were able to get in through Flashchat (with vBulletin integration).

    I'd recommend everyone to get rid of Flashchat, don't use it together with vBulletin or don't use it at all. I'm sorry for the author but it's just crappy coded.
     
    reteep, Sep 3, 2006 IP
  6. UguG

    UguG Peon

    Messages:
    42
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Yes they're from Turkiye.

    they r using a vulnerability from a mod.
    if u will delete topx stat mod i think it will be normal.


    OR

    censor this
    {">"">>>><meta}

    OR

    go to topXstats_thread_bit and

    change all things to

    <tr>
    <td nowrap="nowrap"><div class="smallfont"><strong><if condition="$getstats_thread[newpost]">$newpostprefix<else />$oldpostprefix</if> <a href="showthread.php?$session[sessionurl]goto=newpost&amp;t=$getstats_thread[threadid]">$getstats_thread[titletrimmed]</a></stong></div></td>
    <if condition="$getstats_thread[isdeleted]">
    <td colspan=3" align="left" nowrap="nowrap"><div class="smallfont"><phrase 1="member.php?$session[sessionurl]u=$getstats_thread[del_userid]" 2="$getstats_thread[del_username]">$vbphrase[thread_deleted_by_x]</phrase></div></td>
    <else />
    <td nowrap="nowrap"><div class="smallfont"><a href="member.php?$session[sessionurl]u=$getstats_thread[userid]">$getstats_thread[musername]</a></div></td>
    <td align="right" nowrap="nowrap"><div class="smallfont">$getstats_thread[views]</div></td>
    <td align="right" nowrap="nowrap"><div class="smallfont">$getstats_thread[replycount]</div></td>
    </if>
    </tr>
     
    UguG, Sep 3, 2006 IP
  7. Davey Crocket

    Davey Crocket Well-Known Member

    Messages:
    690
    Likes Received:
    25
    Best Answers:
    0
    Trophy Points:
    128
    #7
    The mods I'm running are Photopost, top x stats, vBadvanced CMPS, vBSEO...Hmm I will check out the index.php file

    How do hackers "hack" do they guess at your usernam and password?
     
    Davey Crocket, Sep 3, 2006 IP
  8. iowadawg

    iowadawg Prominent Member

    Messages:
    10,918
    Likes Received:
    811
    Best Answers:
    0
    Trophy Points:
    380
    #8
    Yeah, I had one of my sites hacked into by they say russians.
    Fixed it, and damn if they did not do it again the same day!

    So went back, fixed it again, and changed all my passwords to gibberish.

    So far, site up and okay.

    Am guessing that is what they do, is run a program to hunt down usernames and passwords.
     
    iowadawg, Sep 3, 2006 IP
  9. Davey Crocket

    Davey Crocket Well-Known Member

    Messages:
    690
    Likes Received:
    25
    Best Answers:
    0
    Trophy Points:
    128
    #9
    Thanks UguG, someone else has suggested I do this over at the vB forum. I uninstalled the topstats for now and so far everything seems to be okay :)
     
    Davey Crocket, Sep 3, 2006 IP
  10. EJRaven

    EJRaven Active Member

    Messages:
    253
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    60
    #10
    Best thing to do is to lock your forum, and not let visitors in for about 2-3 days, Hackers usually are satisfied with that result and move on to the next target.

    Do not provoke them by posting things like, "we have fixed the hacking problem, or our forums are secured now" that would just bring down more hacking.

    Hacking is the so simple, a 14 year old who can follow instructions can do it, and the worst thing is that software vulnerabilities are found very easily on the internet as well.

    Be glad you have VBulletin, their code is crappy and inneficient but at least most hackers like it and use it for their forums and for some reason don't hack as much as IPB and phpBB.
     
    EJRaven, Sep 3, 2006 IP
  11. mdvaldosta

    mdvaldosta Peon

    Messages:
    4,079
    Likes Received:
    362
    Best Answers:
    0
    Trophy Points:
    0
    #11
    I just read somewhere there is a security exploit in top x stats. You may want to check that, probably how you got hacked. Also an exploit in flashchat. Fixes for both have been released.
     
    mdvaldosta, Sep 3, 2006 IP
  12. jward

    jward Active Member

    Messages:
    452
    Likes Received:
    23
    Best Answers:
    0
    Trophy Points:
    90
    #12
    I can confirm that this vulnerability was not related to vBSEO.
     
    jward, Sep 4, 2006 IP
  13. tpn87

    tpn87 Well-Known Member

    Messages:
    522
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    100
    #13
    One of my VB forums was also hacked by turkish hackers tonight. It was a redirection hack. They used html in a post. You can read more about the hack here
     
    tpn87, Sep 5, 2006 IP
  14. tpn87

    tpn87 Well-Known Member

    Messages:
    522
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    100
    #14
    Had several more redirect hack attempts. All from ip 85.xxx.xxx.xxx which are coming from Turkey.

    Disabling all BBcode html in posts seems to have solved the problems.
     
    tpn87, Sep 6, 2006 IP