Announcement

Collapse
No announcement yet.

Site hacked, can someone please help?

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • HMBeaty
    replied
    What's funny is RECoders.org is running vbulletin as well. 3.8.7 to be exact. And I'll bet anything its nulled :P lol

    Leave a comment:


  • beishe8
    replied
    WARNING!
    Something is wrong with this page here: http://www.vbulletin.com/forum/showt...68#post2153568

    Internet Explorer blocked this website from displaying content with
    security certificate errors.

    Leave a comment:


  • SilentSleeper
    replied
    I to was hacked last Night

    My Forum to was hacked last night as well by

    "Hacked by Contra - RECoders.org"

    My index.php's were changed to embed a video to display. I am
    am running v3.8.7 as well.

    Leave a comment:


  • EricGT
    replied
    I am running v3.8.7 on my site.

    Leave a comment:


  • EricGT
    replied
    In the user table, he didn't just set up one account, he set up a bunch of them. Here is a list of them from my site:



    90019001 6 AnimusHax 536ca35136d29089c5f050b5179577b7 [email protected] 0 Hacked by Contra - RECoders.org 1 0 0 0 0 0 0 0 0 0 0000-00-00 -1 1 0 0 0 0 2011-05-05 lol 0 0 0 10 1 0 0 0 -1 0000-00-00 0 2 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019007 4 Neyoln 3b8cff1a3b59c28940969f093aac51eb [email protected] 0 Registered User 0 1304432100 0 1304432100 1304432100 0 0 0 1 0 45095943 -1 -1 78.46.149.49 0 0 0 0 2011-05-03 }qn&nl%5sCc2Jxirr^AUxOo&[Jb)Gq 2 0 0 10 5 1 0 0 -1 0000-00-00 0 2 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019003 4 Squ1dward b513bb2211c9b0927b4ecb31f5036704 [email protected] 0 Registered User 0 1304428020 0 1304428020 1304428510 0 0 -8 1 0 45096151 -1 -1 148.165.17.119 0 0 0 0 2011-05-03 {V,WKLLqS)~w^w{Jw]kF$bL-e'TZt` 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019013 4 dale7786 007c42ed045441dcd8b982b4337abf49 [email protected] 0 Registered User 0 1304434957 0 1304434957 1304435237 0 0 -5 1 0 45096007 -1 -1 74.43.4.66 0 0 0 0 2011-05-03 H*>#Ij"I7=GU0|OoF5VJ~mcM5P)Pb> 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019009 4 bsfollows 30f0ba362a3f9f8bddfad505b0bae380 [email protected] 0 Registered User 0 1304432533 0 1304432533 1304434200 0 0 -6 1 0 45096023 -1 -1 72.213.52.116 0 0 0 0 2011-05-03 :[email protected](DDs\AfbFF>Y6P=3%$Yv`j]j 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019008 4 xfireG17 56ef30a61028b2eeb4db7484fd953099 [email protected] 0 Registered User 0 1304432178 0 1304432178 1304432506 0 0 -5 1 0 45096007 -1 -1 75.150.132.17 0 0 0 0 2011-05-03 @cie>@T,.Bd$_7-=AZQk-O$;`07|w: 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019005 3 andrejpotocar76 a841ac434cc39b8a980218d090b05539 [email protected] 0 Registered User 0 1304430872 0 1304430872 1304430872 0 0 -8 1 0 45096007 06-09-1976 -1 -1 195.91.111.55 0 0 0 0 2011-05-03 AJ]m~ji:!w8XuL*[=QoDZ)q?h$62). 2 0 0 10 5 1 0 0 -1 1976-06-09 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0 90019002 4 bobbeavin 44f87d0344cd8b93d480b9823bd13b40 [email protected] 0 Registered User 0 1304427797 0 1304427797 1304427797 0 0 -8 1 0 45096023 -1 -1 76.27.255.78 0 0 0 0 2011-05-03 \XQ1X/1Nty*vFefX+RlLk2iwX4Fwb} 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019004 4 NealCZTG 624215d324578d3d2357cbadcd1403b0 [email protected] 0 Registered User 0 1304428120 0 1304428120 1304428569 0 0 -6 1 0 45096279 -1 -1 99.53.223.110 0 0 0 0 2011-05-03 Tu7+~b-9xzZFsy.-7(mxF}0HNpVU]r 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019010 4 vel525 1e768fe06992c114e685d55f63d1bd8c [email protected] 0 Registered User 0 1304433070 0 1304433070 1304433301 0 0 -5 1 0 45096023 -1 -1 68.98.133.44 0 0 0 0 2011-05-03 4FXk:"a=GMtc7]qh?jpZBM\NsYxmL+ 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019012 4 Gramps1947 9fc8b7b2b11a7b82244e74ea60a88937 [email protected] 0 Registered User 0 1304434313 0 1304434313 1304436203 0 0 -6 1 288 45096407 03-28-1947 -1 -1 173.23.122.150 0 0 0 0 2011-05-03 ch"ryw'Ij<]HQi8E<f}/GeYia"w33D 2 0 0 10 5 1 0 0 -1 1947-03-28 0 1 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019014 3 Dracliprot e7b49cc3c7d3bdd66b2d3f81e85a828f [email protected] 0 http://www.folkestonetransfers.co.uk/ Registered User 0 1304435492 0 1304435492 1304435621 0 0 0 1 0 45095943 -1 -1 78.46.149.49 0 0 0 0 2011-05-03 ;"|XOwkpg1ei`I6I[IWyU.mzU+1esB 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019006 4 scotton 2a11c31f492c1fa131d54daaa0522a04 [email protected] 0 Registered User 0 1304431096 0 1304431096 1304431152 0 0 -6 1 0 45096279 -1 -1 66.245.90.16 0 0 0 0 2011-05-03 X(%W$*uuMM|-fbga$wZ]NG-IK!s~ 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019015 4 Schuller 6f16790c1eb263447c79702e343c6ef3 [email protected] 0 Registered User 0 1304436056 0 1304436056 1304436142 0 0 -6 1 0 45096023 -1 -1 24.164.36.44 0 0 0 0 2011-05-03 q1v>N7ms*X1jX?U&Ax|u:+<vku!E:q 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    90019011 3 O2CUMMINS 5e62c9dbf28ee1efeb8d6c9ab9f36339 [email protected] 0 Registered User 0 1304433367 0 1304433367 1304435497 0 0 -5 1 0 45096151 -1 -1 138.162.128.52 0 0 0 0 2011-05-03 [Z~a2=;&q5{:[email protected]/Gayf+>Se 2 0 0 10 5 1 0 0 -1 0000-00-00 0 0 0 0 0 0 0 0 0 1000 0 0 0 0 0 0 0 0 0 1 0 0 500 0 0 0 1 0 0 0 0 3 0 0 0 0 0 0 0 0 0 100 1 NULL NULL NULL 500 0 1 0 0

    Leave a comment:


  • EricGT
    replied
    Actually, when viewing the raw DB info, the admin account has the userid number of 90019001. Eric

    Leave a comment:


  • EricGT
    replied
    My site, Glock Talk http://glocktalk.com, suffered exactly the same event last night. The user titles have changed and there is an admin user named AnimusHax. The account appears to be incomplete. When viewed in the admin panel all the data fields are empty for his account are empty, except for join date and last activity, which were current dates. We really need to discover how this guy got in. any info would be helpful. Eric

    Leave a comment:


  • meijin
    replied
    Originally posted by borbole View Post
    What version of vb are you running?

    Did you also contact your host about this so they can check their access logs for your forum and see what happened?
    I am running an older system on 3.8. I have not contacted my server host (we are running on a dedicated box). What I did find that is really unusual is an account called AnimusHax. This is the name that showed up in my mod list that I have deleted. I can find that person in the "members logged in today" area of the site. When I click on that user name, it shows me a profile page (www.mydomain.net/member.php?u=90019001) and he was logged in. However, when I go and try to look up that account via the admincp in "Users", it finds nothing. Also, when I search for the user via Community > Memebers List > Search Members, I see nothing for this user. So I am really perplexed. It looks like this guy has managed to create an account that I can't see (with a join date of 1969 no less).

    NOTE: While typing the info above, I contacted my host for our dedicated box and they are telling me that they see nothing unusual.

    Any help here would be much appreciated. I am a total noob when it comes to this software.

    Thanks!


    Leave a comment:


  • borbole
    replied
    What version of vb are you running?

    Did you also contact your host about this so they can check their access logs for your forum and see what happened?

    Leave a comment:


  • meijin
    replied
    PM sent

    Leave a comment:


  • DirtRider
    replied
    I could have a look for you if you like, PM me

    Leave a comment:


  • meijin
    started a topic Site hacked, can someone please help?

    Site hacked, can someone please help?

    Hello! I have been running a site for a while now. Got it up and running and really have not had to mess with too much. Not all that knowledgable about the software as things have been running well for some time. Woke up to the fact that someone managed to get into the site and turn it off with a very offensive message for my users to see.

    At this point I am clueless as to what to do. I can't call into support as they are not open. Can someone help me to figure out how this person managed to get in and get an entry into the Super Moderator section? Also, everyone's user title says the following:

    "Hacked by Contra - RECoders.org"

    I have no idea how to change this.

    If anyone might be available by phone, I can work something out for help with this. I am really freaking out over this, so help would be much appreciated as to what I should be doing here.

    Thanks!

Related Topics

Collapse

  • TsG XxGHOSTxX
    I need help
    by TsG XxGHOSTxX
    I just signed up for vbulletin. It is used in a lot of gaming communities. I am trying to build my own community and now have enough members to justify building a forum. So I know alot of the clans/gaming...
    Wed 7 Jun '17, 8:25am
Working...
X