My forum got hacked

Discussion in 'vBulletin' started by heatherw_01, Nov 14, 2007.

  1. #1
    My forum got hacked, but all they seemed to do was replace the config.php

    Where should I look for anything else to make sure everything is ok?

    They were the Turkish hackers.
     
    heatherw_01, Nov 14, 2007 IP
  2. chriswick

    chriswick Peon

    Messages:
    907
    Likes Received:
    17
    Best Answers:
    0
    Trophy Points:
    0
    #2
    They target forums for the mass amount of email address that are in the database to spam and sell on, they will get $0.50 - $5 per email address on the black market.

    I duno why they changed your config.php? May I ask what part they changed or added?
     
    chriswick, Nov 14, 2007 IP
  3. heatherw_01

    heatherw_01 Well-Known Member

    Messages:
    610
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    108
    #3
    They just added their message to it which changed my homepage to say I had been hacked.
     
    heatherw_01, Nov 14, 2007 IP
  4. itdevil

    itdevil Well-Known Member

    Messages:
    632
    Likes Received:
    17
    Best Answers:
    0
    Trophy Points:
    110
    #4
    Best things would be re-upload all the files, change you db password and ask admin/mods/staff and all members to change their passwords...

    If you can Dedicated server, then OS reload might be good thing to do... just to be sure there aren't any high risk files uploded.
     
    itdevil, Nov 14, 2007 IP
  5. heatherw_01

    heatherw_01 Well-Known Member

    Messages:
    610
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    108
    #5
    Thanks, I will have to do that.

    I can't see anything else changed, but I could be wrong so I will re-upload everything.
     
    heatherw_01, Nov 14, 2007 IP
  6. Niklas.k

    Niklas.k Peon

    Messages:
    67
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Upload all files again and change passwords!

    Good luck

    // Nick
     
    Niklas.k, Nov 14, 2007 IP
  7. ForgottenCreature

    ForgottenCreature Notable Member

    Messages:
    7,473
    Likes Received:
    173
    Best Answers:
    0
    Trophy Points:
    260
    #7
    What forum software are you running? Try changing your cpanel password.
     
    ForgottenCreature, Nov 14, 2007 IP
  8. calum

    calum Peon

    Messages:
    2,821
    Likes Received:
    141
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Change your password for everything, email, forum, cpanel and other things. What forum software are you on? You should re-upload everthing back, and then update to the latest version of the forum software.
     
    calum, Nov 14, 2007 IP
  9. Stax_Daniel

    Stax_Daniel Guest

    Best Answers:
    0
    #9
    also, when you reupload everything...don't just reupload it over the current files...delete the directory first.

    If they uploaded a malicious file (rather than altering an existing one), a simple upload of backup files won't erase that malicious file
     
    Stax_Daniel, Nov 14, 2007 IP
  10. ForgottenCreature

    ForgottenCreature Notable Member

    Messages:
    7,473
    Likes Received:
    173
    Best Answers:
    0
    Trophy Points:
    260
    #10
    And delete the directories as well. I believe vbulletin is the only one that uses a config file.

    What directory was it in? Go through all your files.
     
    ForgottenCreature, Nov 14, 2007 IP
  11. WatchOut

    WatchOut Guest

    Messages:
    1,359
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    0
    #11
    Do a fresh install and make sure you don't have unrequired permissions on certain files. Permissions is always an issue. Change each password, same applies for your FTP account and webhost control panel.

    @ForgottenCreature, there's far more BB systems that use config.php, in order for a script to work they must include some kind of mySQL, usually found on a config.php file, its located under /includes/ folder on vB, not sure about the others though.


    Meti
     
    WatchOut, Nov 20, 2007 IP
  12. peter_anderson

    peter_anderson Notable Member

    Messages:
    3,382
    Likes Received:
    152
    Best Answers:
    0
    Trophy Points:
    240
    #12
    sorry to hear that. i hate hackers, i once had a great site hacked
     
    peter_anderson, Nov 20, 2007 IP
  13. Karen May Jones

    Karen May Jones Prominent Member

    Messages:
    3,469
    Likes Received:
    290
    Best Answers:
    1
    Trophy Points:
    380
    #13
    No, everything is NOT okay. The fact that they accessed your config file is the whole problem. Protect it! Are you able to set permissions on that file? Password protect it somehow.
     
    Karen May Jones, Nov 20, 2007 IP
  14. olti

    olti Well-Known Member

    Messages:
    436
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    145
    #14
    What forum script do you use?
     
    olti, Nov 21, 2007 IP
  15. BlueDevilMedia

    BlueDevilMedia Well-Known Member

    Messages:
    1,917
    Likes Received:
    87
    Best Answers:
    0
    Trophy Points:
    190
    #15
    ALWAYS drop permissions on the config.php file!! This situation is easy to avoid if you do...
     
    BlueDevilMedia, Nov 21, 2007 IP
  16. sawz

    sawz Prominent Member

    Messages:
    8,225
    Likes Received:
    808
    Best Answers:
    0
    Trophy Points:
    360
    #16
    i was thinking around the same thing when i saw there was a reply here.

    chmod all your folders 0755
    and php files 0644
    you can probably chmod config.php 0600

    and it'll be ok.
    should be anyway. :D
     
    sawz, Nov 21, 2007 IP
  17. BlueDevilMedia

    BlueDevilMedia Well-Known Member

    Messages:
    1,917
    Likes Received:
    87
    Best Answers:
    0
    Trophy Points:
    190
    #17
    At least 95% of the successful hacks I've dealt with are because the owner/developer did not set appropriate permissions.
     
    BlueDevilMedia, Nov 21, 2007 IP
  18. buldozerceto

    buldozerceto Active Member

    Messages:
    1,137
    Likes Received:
    43
    Best Answers:
    0
    Trophy Points:
    88
    #18
    you better do this
    chmod 700 all your folders and files
     
    buldozerceto, Nov 21, 2007 IP
  19. sawz

    sawz Prominent Member

    Messages:
    8,225
    Likes Received:
    808
    Best Answers:
    0
    Trophy Points:
    360
    #19
    don't listen to this guy.
    0700 makes it un viewable in a browser.


    you don't know what your talking about.
    keep your bad advice to yourself.
     
    sawz, Nov 21, 2007 IP
  20. Shazz

    Shazz Prominent Member

    Messages:
    8,395
    Likes Received:
    453
    Best Answers:
    0
    Trophy Points:
    330
    #20
    LOL thats one way of keeping it safe :D
     
    Shazz, Nov 21, 2007 IP