Go Back   vBulletin Setup > vBulletinSetup Information > Troubleshooting vBulletin Problems

Reply 
 
LinkBack Thread Tools Display Modes
Old 09-27-2008, 07:14 AM   #1
entrepreneur
 
Join Date: Sep 2008
Posts: 4
GamersGFX will become famous soon enough
Need advice?

I recently had 2 of my VB sites hacked I done all the security checks (How To Make My Forums More Secure), and working in the industry full time (as a designer not a developer) all my sites are very secure

So basicly I had a parse error on the index of my sites and on my forums, so I commented out the following line in my global.php where the error was pointing to:

eval('$spacer_open = "' . fetch_template('spacer_open') . '";');
eval('$spacer_close = "' . fetch_template('spacer_close') . '";');

and I get the following at the top of the site:

ViRuSMaN Ow3nd Your SiTe .. v.-m@hotmail.com

Immediatley I have taken the sites down, but it baffles me how he got in as I looked within the databases and done a search for the above and it is only located in the template table (on both custom and default templates).

So my question is would this be a server problem (ie. with the host bad security)? Or is there something I am overlooking here? As I have all the upto date patches admin/mod cp are secure, I am the only Superadmin on the board and password is pretty tight (changed every month). I do want to restore the database because I have alot of posts and alot of members so any advice anyone can give would be more than greatfull?

Btw. I did try on vB support but they said its either me not securing it prop or the host.. but knowing how they got in the first place would realy strenghten my argument with the host..
And also on 1 of the sites there is no mods installed!

Thanks in advance

Last edited by GamersGFX; 09-27-2008 at 07:17 AM.
GamersGFX is offline   Reply With Quote

Advertisement [Remove Advertisement]

Old 09-27-2008, 07:50 AM   #2
vBulletin Owner
 
Soliloquy's Avatar
 
Join Date: Jun 2007
Location: New York City
Posts: 2,663
Soliloquy is a jewel in the rough
Re: Need advice?

wrong window, please delete

Last edited by Soliloquy; 09-27-2008 at 07:56 AM.
Soliloquy is offline   Reply With Quote
Old 09-27-2008, 07:50 AM   #3
Supporters
vBulletin Owner
 
glennybee's Avatar
 
Join Date: Mar 2008
Location: Scotland
Posts: 1,058
glennybee is just really niceglennybee is just really nice
Re: Need advice?

Most of the times hackers just want to let you know they can hack into your site and not actually cause any harm. Try replacing your index.php file from a backup if you have one or download it again from the members area of vb.com.
glennybee is offline   Reply With Quote
Old 09-27-2008, 07:57 AM   #4
vBulletin Owner
 
Soliloquy's Avatar
 
Join Date: Jun 2007
Location: New York City
Posts: 2,663
Soliloquy is a jewel in the rough
Re: Need advice?

gack, how did that get in this thread? Sorry, I must have been typing in the wrong window. Just delete, I'll move it myself...

and I agree with glenny, often these guys just indiscriminately hack any and all forums so they can say "I hacked 110,000 forums today!" It's unlikely he'll be back unless he actually has a grudge against you.
Soliloquy is offline   Reply With Quote
Old 09-27-2008, 07:58 AM   #5
Supporters
vBulletin Owner
 
glennybee's Avatar
 
Join Date: Mar 2008
Location: Scotland
Posts: 1,058
glennybee is just really niceglennybee is just really nice
Re: Need advice?

If you get in quick Soliloquy you can delete it yourself, advanced edit option.
glennybee is offline   Reply With Quote
Old 09-27-2008, 08:04 AM   #6
entrepreneur
 
Join Date: Sep 2008
Posts: 4
GamersGFX will become famous soon enough
Re: Need advice?

What would you suggest regarding restoring my database (obviously taking out the template edits which he has done)?

If he does come back what should I do?

Thanks for your quick replies btw
GamersGFX is offline   Reply With Quote
Old 09-27-2008, 08:05 AM   #7
vBulletin Owner
 
Soliloquy's Avatar
 
Join Date: Jun 2007
Location: New York City
Posts: 2,663
Soliloquy is a jewel in the rough
Re: Need advice?

guess I missed it glenny, didn't see any option to delete on the advanced edit screen.
Soliloquy is offline   Reply With Quote
Old 09-27-2008, 08:10 AM   #8
Supporters
vBulletin Owner
vBSetup Mods
 
Cerberus's Avatar
 
Join Date: Mar 2008
Posts: 1,630
Cerberus is a glorious beacon of lightCerberus is a glorious beacon of lightCerberus is a glorious beacon of lightCerberus is a glorious beacon of light
Re: Need advice?

I would secure the admin panel with a password. And I would also change all passwords. But before doing so I would run a virus scan on your computer. Maybe even change passwords from a different computer. Most of these people use software to get it by just going to your admin panel and getting in that way. I would secure everything and change passwords.
__________________
Cerberus / vBulletinSetup Staff
Check the Newsletter & Marketplace for the latest deals.
Looking for a place to Support vBulletinSetup?
Submit your Forum and other Quality Websites.


Cerberus is offline   Reply With Quote
Old 09-27-2008, 08:21 AM   #9
vBulletin Owner
 
Soliloquy's Avatar
 
Join Date: Jun 2007
Location: New York City
Posts: 2,663
Soliloquy is a jewel in the rough
Re: Need advice?

also did you change the name of your admin directory? Maybe change it again for good measure.
Soliloquy is offline   Reply With Quote
Old 09-27-2008, 08:24 AM   #10
Supporters
vBulletin Owner
vBSetup Mods
 
Cerberus's Avatar
 
Join Date: Mar 2008
Posts: 1,630
Cerberus is a glorious beacon of lightCerberus is a glorious beacon of lightCerberus is a glorious beacon of lightCerberus is a glorious beacon of light
Re: Need advice?

Yeah I have mine changed and then htaccess password protected. And the password is generated so I have no idea what it is. I was using a script before to secure where the password changed everytime. You used a generated key to put in box and then box would spit out password for that session. But I lost the script. So just normal password now. Plus that was kind of overkill. But always changed admin folder mod folder too. I mean might as well be safe. Though you cant password protect both. If you pass protect mod panel you break features in the admin panel. I found that out LOL
__________________
Cerberus / vBulletinSetup Staff
Check the Newsletter & Marketplace for the latest deals.
Looking for a place to Support vBulletinSetup?
Submit your Forum and other Quality Websites.


Cerberus is offline   Reply With Quote
Old 09-27-2008, 08:32 AM   #11
vBulletin Owner
 
Soliloquy's Avatar
 
Join Date: Jun 2007
Location: New York City
Posts: 2,663
Soliloquy is a jewel in the rough
Re: Need advice?

wow Blake, that sounds like some heavy-duty security...
Soliloquy is offline   Reply With Quote
Old 09-28-2008, 03:23 AM   #12
entrepreneur
 
Join Date: Sep 2008
Posts: 4
GamersGFX will become famous soon enough
Re: Need advice?

thanks for you replies guys I have the site back online now. I think it was a prob with my host as after I spoke to them 10mins later the site was a ok.. strange huh?

Not trying to make myself look like a novice here or anything, but changing the admin folder for eg to "myvbadminfolder" do I need to mod any other files so that it recognises where it is etc..
GamersGFX is offline   Reply With Quote
Old 09-28-2008, 04:59 AM   #13
vBulletin Owner
 
valdet's Avatar
 
Join Date: Jan 2008
Location: Kosova
Posts: 284
valdet is a jewel in the rough
Send a message via Yahoo to valdet
Re: Need advice?

You need to make the change in config.php file too so it reflects the changes to admincp and modcp folder names.
valdet is offline   Reply With Quote
Old 09-28-2008, 05:52 AM   #14
vBulletin Owner
 
Soliloquy's Avatar
 
Join Date: Jun 2007
Location: New York City
Posts: 2,663
Soliloquy is a jewel in the rough
Re: Need advice?

glad your host got everything working again GamersGFX
Soliloquy is offline   Reply With Quote
Old 09-28-2008, 06:21 AM   #15
entrepreneur
 
Join Date: Sep 2008
Posts: 4
GamersGFX will become famous soon enough
Re: Need advice?

@valdet
Thanks for the heads up got that sorted now, thats a good little securty feature which I must of overlooked.

@Soliloquy
Thanks I might be wrong they maynot have done anything but it just seems strange that it worked 10mins after the support ticket went in :P


Thanks for the advice all..
GamersGFX is offline   Reply With Quote
Reply 
vBulletin Setup > vBulletinSetup Information > Troubleshooting vBulletin Problems

Tags
advice

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
WebTemplates, Need Advice.... ArnyVee Troubleshooting vBulletin Problems 49 09-19-2008 07:18 AM
Advice needed magz Troubleshooting vBulletin Problems 4 09-01-2008 01:45 PM
Need some advice Garala Community Forum Management 6 08-28-2008 04:15 AM
Advice for a newbie! melina General Discussion 2 04-17-2008 12:43 PM
Need SEO advice! grint vBulletin SEO Tips and SEO Questions 1 08-18-2007 07:04 AM


All times are GMT -8. The time now is 07:18 AM.