Vbulletin hacked again...

Discussion in 'Security' started by AfterHim.com, Jul 6, 2008.

  1. #1
    My hackers are the smart kind. They upload files to obscure folders then use those as phishing attempts. The last one was for Halifax bank in the UK.

    Is there any way to see all of the modified files and folders for all of the recursive directories? I'm running cpanel.
     
    AfterHim.com, Jul 6, 2008 IP
  2. riya_senk

    riya_senk Well-Known Member

    Messages:
    2,014
    Likes Received:
    174
    Best Answers:
    0
    Trophy Points:
    160
    #2
    Well why don't you block other folders which are not usefull with .htaccess?
     
    riya_senk, Jul 8, 2008 IP
  3. HostPenguin

    HostPenguin Peon

    Messages:
    68
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    What type of hosting account do you have? We may be able to help you better on ways to protected yourself.
     
    HostPenguin, Jul 8, 2008 IP
  4. Brandon Sheley

    Brandon Sheley Illustrious Member

    Messages:
    9,721
    Likes Received:
    612
    Best Answers:
    2
    Trophy Points:
    420
    #4
    You need to talk with your hosting company, the only reason your vb was hacked, is because of what you've done to it ;)
     
    Brandon Sheley, Jul 9, 2008 IP
  5. calum

    calum Peon

    Messages:
    2,821
    Likes Received:
    141
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Many hosts will help you secure your sites and prevent you being hacked, so I would talk to your host.
     
    calum, Jul 9, 2008 IP
  6. Enfinityhost

    Enfinityhost Peon

    Messages:
    20
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Talk to your host or if this is your VPS / Dedicated server think about hiring an administrator.
     
    Enfinityhost, Jul 10, 2008 IP
  7. Yousif

    Yousif Banned

    Messages:
    233
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Well, if your in a shared environment, and especially using cPanel, you can't really monitor file/folder activity, unless you had internal access. I recommend you follow-up with your host from tech support. I don't know what languages your website is exercising, but if they have the rights as you are saying, I would consider using .htaccess control, lock your folders with a password, upload an index.html to each folder, and change your password to at least 12 characters at length, followed by a mix of numbers, letters, and symbols, and ascii is possible. Otherwise, give me a PM if you are still having trouble.
     
    Yousif, Jul 11, 2008 IP
  8. Irfi0009

    Irfi0009 Banned

    Messages:
    17,584
    Likes Received:
    33
    Best Answers:
    1
    Trophy Points:
    48
    #8
    Irfi0009, Jul 12, 2008 IP
  9. twhiting9275

    twhiting9275 Active Member

    Messages:
    305
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    80
    #9
    There are a few ways to prevent this type of thing. This isn't a "hack", this is a phishing attempt. They are two very, very different things.

    How to prevent this?
    #1: Turn off uploads. This will prevent individuals from uploading this kind of thing
    #2: Disable image uploads. Again, this will prevent individuals from uploading this kind of thing.
    #3: Store your upload folder OUTSIDE of the public_html root. VB can do this very easily, and it's always advised when you must have write permission
    #4: Store your uploads in the database, NOT in files.
     
    twhiting9275, Jul 14, 2008 IP