WARNING ... I got 0WN3D !

K3V

New Member
Hello fello vBTEAM members,

Yesterday my vBulletin Forum was Hacked and every time you visited my url you got re-directed to the Hackers Site ...

Code:
http://tradas2.t35.com/images/index.html

2gy8zma.jpg


To start with i was a bit worried that i had lost it all, but after logging into FTP i found everything still in place and ok, It was a this stage i realised this is just a simple re-direct hack and not to worry too much.

After the Hacker was so nice to leave his contact details i decided to contact him and ask him to fix it, which he could not ?! noob, lol

I then put 2 & 2 together and realised this might be a SQL Injection, So i ran my Backed Up SQL Database from the 01/06/09 against the new (Hacked) one 02/06/09 and found this hiding in there ...

Code:
<meta http-equiv="refresh" content="2;url=http://tradas2.t35.com/images/index.html">

I then traced it back to the Admincp ... vBulletin Options ... Site Name / URL / Contact Details ... Homepage Name,

Changed it back to my Homepage Name & bingo, No more re-direct !

So if this happens to you, Dont worry, I have already done all the hard work, lol, Just go to Admincp (Which is still accessible & dont re-direct) and change the setting above.

P.S ... K3Vs Final Thought ...
"He who laughs last prolly has backup !"
 

mmmxiv

New Member
His vB is hosted locally, as far as I can tell, as I can access it via the IP ;) He should have logs on his wamp or xampp
 

K3V

New Member
The only thing you left out is how it was done and what you have done to keep it from happening again.

Still trying to find out & will have to move host :(

Yep, what vBuleltin version were you running K3V?

3.8.0

Site Name / URL / Contact Details probley 1 of his mods or admin got mad at him and entered it in

Nope, Dont have any, My Test Site ...

His vB is hosted locally, as far as I can tell, as I can access it via the IP He should have logs on his wamp or xampp

Hosting provided by a friend.
 
Top