Welcome to the vBulletin support forums! In our community forums you can receive professional support and assistance with any issues you might have with your vBulletin Products.
I didn't get a chance to download the files from their site when it was up, so I've shut my portal off for the time being.
Anyone know if the updated version is posted somewhere else? We're missing the portal already It can wait though as I know their is license issues involved.
I'd like to know a little more about what this entails, only so that I can protect against it temporarily. I am not in a position to install the updates (are they available through other means since vbportals is down?) because I'm not the actual license holder. Yes, the site owner/webmaster needs to get the updates and do this and he will soon, but that isn't possible at the moment and neither is removing vbportal from the site.
We aren't using phpsuexec, yet the site did manage to get some readme.txt files with "Hacked By vbPortal hackers" in them.
What I would specifically like to know is if setting disable_functions = passthru in php.ini will mitigate this for now?
Also it was mentioned to set "the passthru setting to 1" in php.ini but I could not find a reference to that anywhere (and I did spend considerable time googling). The closest thing I could find was in the [odbc] section for binary data handling. (0 means passthru, 1 means return as is)
I'd be grateful if someone in the know could reply.
Our host 'Liquidweb' to date has been little or no help at all. The first line tech's have responded with a few things an have tried to help, but bottom line the abuse support is non existent as far as security.
Security has not even answered my tickets in 4 days. I ask last night to have my database restored (they supposably backup every night) Not even a answer about that.
Seeing the hack has happened again (didn't I read in this thread the problem was fixed?), I'd like to know whether the problem is vbportal-(software)-specific, vbportal-hosting-specific or vBulletin-specific.
I have registered years ago for to the vbportal.org forum out of potential interest, but I am not using it, so I am asking myself right now if my site, too, is in danger.
I'm glad I didn't use a regular email alias years ago when I first signed up for that site.
I'm also glad I stopped using vbportals years ago even after paying the "contribution" fee or whatever they called it at the time. I feel for them, but I'm also still highly annoyed they didn't alert their userbase first before the hackers did it for them. In any case, now that they've pissed them off I suspect this will continue for a good long time.
I feel for them, but I'm also still highly annoyed they didn't alert their userbase first before the hackers did it for them.
HUH??? Alert their users that they we're about to be hacked? Does that even make any sense?
And apparently this an an attempt to get money. It's a pretty common ploy in the hacker community, perpetrated many times against places like Online Casinos, and even porn sites. However, they are widening the scope of targets; as unfortunately Scott & WJones have discovered.
Scott & WJones, please contact me if you want any assistance. With out going into details in public, I work in InfoSec. So contact me if you want, and I'll see what help I can offer.
widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
Working...
X
We process personal data about users of our site, through the use of cookies and other technologies, to deliver our services, personalize advertising, and to analyze site activity. We may share certain information about our users with our advertising and analytics partners. For additional details, refer to our Privacy Policy.
By clicking "I AGREE" below, you agree to our Privacy Policy and our personal data processing and cookie practices as described therein. You also consent to the transfer of your data to our servers in the United States, where data protection laws may be different from those in your country.
Comment