vBulletin 4.2.5 is end of life and will not be receiving any future development. Warning: vBulletin 4.2.5 is not compatible with PHP 7.2.0 or higher.
Welcome to the vBulletin support forums! In our community forums you can receive professional support and assistance with any issues you might have with your vBulletin Products.
If you are having problems posting in the relevant areas for your software, please see this topic.
Upgrade to vBulletin 5
We're pleased to announce a special promotion for upgrading your vBulletin 3/4 sites to vBulletin 5. From now until December 31st, we are offering vBulletin 5 license upgrades at $169 each. This promotion is available to all vBulletin 3 (owned) and vBulletin 4 license holders, entitling you to the latest version of vBulletin 5.
If you would like to purchase this upgrade, please log into the vBulletin Members Area and use Promo Code: vB5UPGRADE during checkout to apply the discount.
Announcement
Collapse
No announcement yet.
Please help - Malicious code inserted into my forum!!
Please help - Malicious code inserted into my forum!!
Hi All
I don't know how but someone has managed to add some malicious code to my Vbulletin forum! I'm a bit stumped with this one as I don't know where to look to clear this and presently Google Chrome is blocking my site :-(
If anyone has any suggestions or can help me out I would really appreciate it indeed!!
Basically delete the install folder.
Check your admncp/users and delete any new admins that may have registered.
Then check your plugins to see if any have been created that you don't recognize..Delete them..
Also read the material donald1234 has been kind enough to link for you..They will help you tidy up the place.
Thanks for the site above! This looks to be more complicated than I first thought :-( I checked the register.php, content.php and forum.php with a text compare tool as I still have the files from when I built the site and there is no changes in them files :-(
Any ideas where I start looking for this peace of **** script some little tosser has inserted?
Thanks for the site above! This looks to be more complicated than I first thought :-( I checked the register.php, content.php and forum.php with a text compare tool as I still have the files from when I built the site and there is no changes in them files :-(
Any ideas where I start looking for this peace of **** script some little tosser has inserted?
It is usually in the footer template. People like this aren't very creative.
There are four steps to securing your site. If you don't do them all or you do them in the wrong order than you're still susceptible to being attacked again.
Close the hole... This has three subparts in this instance.
Delete your install folder
Review your admin users and delete any that don't belong. Don't ban them. Don't make them regular users. Delete them.
Close access to your AdminCP using .htaccess. Use either user authorization with a different username and password or IP address restrictions.
Fill the Hole... There are seven subparts in this instance.
Review your files for changes. You can do this under Maintenance -> Diagnostics.
Delete any Suspect Files.
Replace any files marked as "Does not contain expected contents"
Scan your plugins for malicious code (exec, base64, system, pass_thru, iframe are all suspect keywords). Delete any you find.
Repair any templates. Any templates that you don't have notes on changing, you need to revert. If you're using a custom style, it is best to delete your existing style and reimport from a fresh download.
Update your Addon Products.
Rebuild your datastores. You can use tools.php in the "do not upload" folder to do this. Upload it to your admincp directory, delete when done.
Secure the Hole
Parts of this were done by closing the hole but there are still things to do here.
Keep notes of all changes you make to the system - what templates and phrases you change, what files belong to which addons, what plugins do the addons install.
Consider using a separate Super Admin who has access to admin logs in the AdminCP. There should be only one Super Admin.
Create a lower permission Administrator for every day use.
Review your permissions in the system.
Block off access to the includes, modcp, packages and vb folders via .htaccess. Deny All can work here, unless you use the ModCP. You need user authorization there.
Move your attachments outside the forum root directory.
Create a complete backup of your site. Make database backups weekly.
Vigilance
You need to keep active on the security of the site.
Give out the fewest permissions necessary for anyone to do their job
Make sure your hosting provider updates the software.
Update to the latest vBulletin when it is released.
Make sure your addons are always up to date.
Translations provided by Google. Wayne Luke The Rabid Badger - a vBulletin Cloud demonstration site.
vBulletin 5 API - Full / Mobile
Vote for your favorite feature requests and the bugs you want to see fixed.
1. I have deleted the "Install" folder and all of it's contents
2. I changed my CPanel, FTP and Admincp passwords
3. I have removed 8 "Admin User Accounts " that where defiantly used buy the attacker
4. I have disabled and removed the plugin titled "Product : vBulletin"
Next steps I will need some help with!
At present I do not have a database backup, I have sent a support request to my hosting company and am awaiting a reply on that.
QUESTIONS?
1. Before I deleted the plugin "Product : vBulletin" I took detailed screen captures and notes of the scripts that were run. Would it help if I added this information here?
2. Can I view a log of any database changes that were added by the hacker
3. "Restoring the default vBulletin files"
If I delete all my vBulletin files Version "4.1.5" on the server and upload "the latest stable version 4.2.2", then run the upgrade (Basically following the upgrade procedure) will this error or clear any database changes the hacker has done, or am I better to just re-upload and overwrite all the 4.1.5 files I have on there at present to see if that clears it?
I plan to dump the database and back that up before I run any upgrade.
Many thanks for your help so far.
Last edited by xrayhead; Sat 19th Oct '13, 3:25am.
How do I go about finding that file? Delete the /core/install/ folder in the above paragraph. I'm a newbie. Thanks for any help! That will be my first step in trying to get the toggle switch ...
Mon 10th Feb '14, 5:21pm
Working...
X
We process personal data about users of our site, through the use of cookies and other technologies, to deliver our services, personalize advertising, and to analyze site activity. We may share certain information about our users with our advertising and analytics partners. For additional details, refer to our Privacy Policy.
By clicking "I AGREE" below, you agree to our Privacy Policy and our personal data processing and cookie practices as described therein. You also consent to the transfer of your data to our servers in the United States, where data protection laws may be different from those in your country.
Comment