Hacked Web Hosting Forum - What To Do?

Discussion in 'Security' started by WebmasterPost.com, Oct 22, 2011.

  1. #1
    Good Morning. I have a Web Hosting Forum running vBulletin that has been hacked: www.HostBoards.com
    Any advice on how to repair and prevent this in the future would be appreciated.

    Has anyone heard of this group, V!RuS_BaGhDaD? Is this just kids having fun?

    Thank you
     
    WebmasterPost.com, Oct 22, 2011 IP
  2. habib10

    habib10 Member

    Messages:
    188
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    28
    #2
    restore backups in db? reupload files and change ur passes
     
    habib10, Oct 22, 2011 IP
  3. WebmasterPost.com

    WebmasterPost.com Active Member

    Messages:
    234
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    58
    #3
    Sadly I made no backups. However, I think this might be a simple index swap hack that might be able to be reversed (I'm hoping so anyway :)
     
    WebmasterPost.com, Oct 22, 2011 IP
  4. mrwiippy

    mrwiippy Member

    Messages:
    179
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    26
    #4
    You need to change the index.php file and update vbulletin / theme / mods

    Steve
     
    mrwiippy, Oct 22, 2011 IP
  5. Jay-S

    Jay-S Member

    Messages:
    201
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    36
    #5
    They most likely exploited your website either from another account on the server (assuming you are on shared hosting). I would recommend updating vBulletin to the latest version once you get the forum back up to date and move to VPS or Dedicated hosting so other users cannot access your files.
     
    Jay-S, Oct 22, 2011 IP
  6. mrwiippy

    mrwiippy Member

    Messages:
    179
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    26
    #6
    Hi jay-S

    I don't believe that this is a server isssue, i believe he was hacked through the index.php and for having outdated software. I guess the only way he will find out how he was hacked is by looking at his logs.

    Steve
     
    mrwiippy, Oct 23, 2011 IP
  7. HSJason

    HSJason Peon

    Messages:
    52
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Have you contacted your hosting provider to see if they keep any kind of automated backups?
     
    HSJason, Oct 23, 2011 IP
  8. cornishhosting

    cornishhosting Peon

    Messages:
    15
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Hi most web hosts take backups everyday for there customers we take daily and weekly
     
    cornishhosting, Oct 23, 2011 IP
  9. supportex

    supportex Peon

    Messages:
    66
    Likes Received:
    0
    Best Answers:
    1
    Trophy Points:
    0
    #9
    You need use latest versions of vBulletin and make regular backup.
     
    supportex, Oct 24, 2011 IP
  10. WebmasterPost.com

    WebmasterPost.com Active Member

    Messages:
    234
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    58
    #10
    That is a good idea, thanks. I did not think of that but I will contact them.
     
    WebmasterPost.com, Oct 26, 2011 IP
  11. pupul

    pupul Prominent Member

    Messages:
    1,737
    Likes Received:
    66
    Best Answers:
    2
    Trophy Points:
    340
    #11
    If you have a good hosting provider then they may have a back up.
    Try to contact them and also fix your site with latest VBulletin.
     
    pupul, Oct 26, 2011 IP
  12. Nishant_Hostinizer

    Nishant_Hostinizer Peon

    Messages:
    4
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Best thing you can do is, ask your hosting company for the latest backup.
    Delete your current board as it may have some malicious scripts or backdoor shell installed.
    Install a fresh copy and import the DB!
     
    Nishant_Hostinizer, Nov 10, 2011 IP
  13. DaringHost

    DaringHost Greenhorn

    Messages:
    50
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    18
    #13
    Looks like your site is hacked again, or you never were able to fix it the first time.
    Anyway, after getting your site backup I would take a look at the plugins you are running. I've heard of some V Bulletin chat plugins having vulnerabilities.
    I'd also ask your web host if the entire server got hacked, and not just your website.
     
    DaringHost, Nov 14, 2011 IP
  14. 7h3 Wh173 R4bb17

    7h3 Wh173 R4bb17 Peon

    Messages:
    19
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    I got hacked a few weeks ago and it was a case of the hacker exploiting the hosting providers cpanel in order to gain access to all sites hosted on that server (around 70000!) from there i figured there was nothing that could be done and it was a web hosting provider vulnerability, check that first and change your index page back to the old one.
     
    7h3 Wh173 R4bb17, Nov 15, 2011 IP
  15. iLovehosting

    iLovehosting Peon

    Messages:
    6
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #15
    There is no way that 70,000 websites can be hosted on one server! To stop this from happening update all of your sites/software to the latest version. If your database is in tact you should be fine.
     
    iLovehosting, Nov 17, 2011 IP
  16. Qarizma

    Qarizma Member

    Messages:
    55
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    45
    #16
    Switch to another host, and check for malicious files in your root.
     
    Qarizma, Nov 27, 2011 IP
  17. 7h3 Wh173 R4bb17

    7h3 Wh173 R4bb17 Peon

    Messages:
    19
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #17
    Sorry i made a typo with the number of websites, it was actually 700,000 that were hacked, and yes I should have been more specific, I am aware 70,000 websites cant be hosted on one server but I was thinking of the singular term when referring to the hosting provider.

    Heres some news stories relating to the hacks experienced:
    http://www.webhostinghub.com/suppor...shooting/status-of-september-tiger-mte-attack
    http://latesthackingnews.com/?p=112
     
    Last edited: Nov 28, 2011
    7h3 Wh173 R4bb17, Nov 28, 2011 IP
  18. Hostingder

    Hostingder Peon

    Messages:
    251
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #18
    You have a great domain name, and it looks like your site is still not back yet. I would suggest installing a fresh installation of vbulletin (latest version) after installation delete the database and upload your latest MySQL Backup from the old board.

    If you had any mods installed you would have to re-install them again but that's the only thing you would be losing, I would suggest that you move your site to a vps and that way you have better control over your account. You can install CSF it's a good firewall and DDOS Prevention, it looks for open ports and security threats and gives you specific details on what to do.

    I did a little research on the group that hacked you, and it appears that they have been around hacking more sites.

    http://modirerooz.com/
    http://al7ob-almst7el.com/vb/
     
    Hostingder, Dec 24, 2011 IP
  19. amigoserv.com

    amigoserv.com Peon

    Messages:
    35
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #19
    Those groups attacked alot of site including forums , they look for any vulneri. on any forum like faked or nulled hooks and then attack the site

    if the server is protected well from opening shells , they will only uploading their index and will not attack your databases which are very very important
     
    amigoserv.com, Jan 2, 2012 IP