hacked by fox team

Discussion in 'vBulletin' started by turbosatan, Sep 22, 2007.

  1. #1
    the tattoo forum has been hacked by the fox team.

    www.thetattooforum.com

    there is some sort of plugin trying to run so please be careful not to allow them when you take a look.

    running vbulletin but i can see how they hacked it. the index page looks the same as before how do i get the site back?

    i dont seem to be able to login even after editing the mysql to reinstate myself as an admin
     
    turbosatan, Sep 22, 2007 IP
  2. grungemedia

    grungemedia Well-Known Member

    Messages:
    590
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    110
    #2
    grungemedia, Sep 22, 2007 IP
  3. turbosatan

    turbosatan Well-Known Member

    Messages:
    957
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    135
    #3
    well i changed the hompage now to explain my feelings

    anyone know how they are doing this?

    i think it is a vbulletin exploit as my cpanels all seem fine.
     
    turbosatan, Sep 22, 2007 IP
  4. ForgottenCreature

    ForgottenCreature Notable Member

    Messages:
    7,473
    Likes Received:
    173
    Best Answers:
    0
    Trophy Points:
    260
    #4
    Why would it be a vBulletin exploit?
     
    ForgottenCreature, Sep 23, 2007 IP
  5. turbosatan

    turbosatan Well-Known Member

    Messages:
    957
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    135
    #5
    my nameservers havnt been changed.

    the username and password on my cpanel hasnt changed

    th rest of my site is still there except my home page is redirectingto another site

    i though an exploit in vbulletin was the most sensible assumption

    do you think it might have been something else?
     
    turbosatan, Sep 23, 2007 IP
  6. ForgottenCreature

    ForgottenCreature Notable Member

    Messages:
    7,473
    Likes Received:
    173
    Best Answers:
    0
    Trophy Points:
    260
    #6
    Was your password easy to guess?
     
    ForgottenCreature, Sep 23, 2007 IP
  7. BTS

    BTS Active Member

    Messages:
    184
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    58
    #7
    they also can penetrate to your site from other site hosted in your server not necessary bug at vb
     
    BTS, Sep 23, 2007 IP
  8. turbosatan

    turbosatan Well-Known Member

    Messages:
    957
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    135
    #8
    not at all. mix of numbers cap and lowercase letters that i dont use elsewhere

    i guess thats possible. would stand to reason that a lot of other sites on the server would have been done also.

    plus it is odd that the hack involves changing the template to display their new index page. would indicate to me that its someone who knows VB and is targeting it specifically
     
    turbosatan, Sep 24, 2007 IP
  9. turbosatan

    turbosatan Well-Known Member

    Messages:
    957
    Likes Received:
    24
    Best Answers:
    0
    Trophy Points:
    135
    #9
    ok i have managed to get back in and i was hacked by


    212.71.32.84

    saudi arabia

    the ripe DB shows that there are only 256 addressees assigned to that particular set so it shouldnt really be to hard to track down who did it.

    Anyone know where to start with tracking people by ISP etc.
     
    turbosatan, Sep 24, 2007 IP
  10. kybernetes

    kybernetes Peon

    Messages:
    40
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #10
    OK even if you do find out the IP, what would the next step be?
     
    kybernetes, Oct 28, 2007 IP
  11. microdude431

    microdude431 Active Member

    Messages:
    451
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    85
    #11
    Not much really. They probably covered themselves up pretty well. It would be hard to do anything since they are in Saudi Arabia..... :eek:
     
    microdude431, Oct 28, 2007 IP