Vbulletin 3.8 and 4 security issues / hacking of forums

Discussion in 'vBulletin' started by Lee G, Mar 30, 2010.

  1. #1
    Just lookjed over the forum here and there is no mention of whats happened to a few forum owners who run Vbulletin. And Im one thats been affected by the following, hence giving out the warning on here.

    There has been a few Vbulletin forums hacked recently, it seems to be a lot running VBSEO affecte as well.

    The first signs are a massive drop in traffic to your forums.
    If you go directly to the forums, you see nothing that looks out of place. No sign, what ever the sign would be, of being hacked.

    What the hackers have been doing is inserting code that redirects people coming to the forums from Google searches and redirects them to other websites. In my case a few others it was a web page at myfilestore.com

    When I first noticed the problem, it never registered why I had been diverted after a clicking on a link from a google search. Just blamed user error. Rather than seeing a problem.

    There is more about the problem on the VBSEO forum.
    http://www.vbseo.com/f3/security-issue-41463/

    The hackers are inserting code into one of the global_start templates

    If you run VBSEO, its a quick and simple fix to cure the problem

    disable vbseo
    re-upload product file with overwrite,
    re-enabled vbseo.

    Then lock everything down. My own admin area is only accesable via having the right ip now, via htacess.

    Those of us that have been hit are now fighting to get our sites off any penalties incured through this one. My forums not a big hitter, but Im down about 600 to 800 hits a day.

    There are a lot of sites out there that have been hit and dont know about it, thats why I have made this post about the problem.
     
    Lee G, Mar 30, 2010 IP