Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
0 registered (), 41 Guests and 9 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 08/04/04
Posts: 442
Top Posters (30 Days)
Ruben 27
Gizmo 22
Bert 18
sb 5
After the Rose 4
hema0359 4
BellaOnline 3
gladiator 3
skicomau 3
UbbLegacyUser 2
Latest Photos
Uhm...
Mayan End of World
Gas Station Disco Video Shoot
Test Pictures
Audrey Kate
Page 1 of 4 1 2 3 4 >
Topic Options
#198100 - 09/25/07 09:42 PM Intruder keeps hacking my header.tpl file
doug Offline
member
Registered: 01/24/07
Posts: 173
Any idea of how a hacker manages to gain access to put malicious code in my header.tpl file?

I have taken out Front page extensions and changed the admin passwords but it still keeps happening.

Any ideas?
_________________________
UBB user since 1998
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#198101 - 09/25/07 10:03 PM Re: Intruder keeps hacking my header.tpl file [Re: doug]
Rick Offline
Post-a-holic
Registered: 06/04/06
Posts: 10177
Loc: Aberdeen, WA
Was this an upgrade from a previous version of the software, like an older version of UBB.threads? If so, you may want to make sure that all of the old scripts, besides the redirects have been removed.

Second question would be what are the file permissions on the header.tpl file? You might want to change them to back to something like 644, or not world writeable if it's a windows server, which it sounds like it is, to see if it's being done through some type of web interface or through more direct means.
Top
#198102 - 09/25/07 10:05 PM Re: Intruder keeps hacking my header.tpl file [Re: Rick]
Rick Offline
Post-a-holic
Registered: 06/04/06
Posts: 10177
Loc: Aberdeen, WA
Also, make sure you review your admin logs in the control panel and check for anything out of the ordinary.
Top
#198103 - 09/25/07 10:06 PM Re: Intruder keeps hacking my header.tpl file [Re: Rick]
Rick Offline
Post-a-holic
Registered: 06/04/06
Posts: 10177
Loc: Aberdeen, WA
And one last thing. Any other php/cgi scripts on your domain?
Top
#198105 - 09/25/07 10:14 PM Re: Intruder keeps hacking my header.tpl file [Re: Rick]
AllenAyres Offline
Registered: 12/29/03
Posts: 2020
Loc: Texas
and .pl - lots of shell scripts are perl.
_________________________
- Allen
- ThreadsDev | PraiseCafe
Top
#198114 - 09/26/07 08:16 AM Re: Intruder keeps hacking my header.tpl file [Re: AllenAyres]
doug Offline
member
Registered: 01/24/07
Posts: 173
Now I have done it - They hacked the file again last night and when I tried to edit it I must have missed something - now the header.tpl shows an error and the forums will not load. I do not have a bakup of the file and my license and password is being rejected in the members area!

Can someone email me a copy of a generic header.tpl contents for 7.1 to admin@rncinternet.com
_________________________
UBB user since 1998
Top
#198115 - 09/26/07 08:20 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
doug Offline
member
Registered: 01/24/07
Posts: 173
There is no trace of intrusion in the log files - someone suggested it could be sql injection. Would that be possible?
_________________________
UBB user since 1998
Top
#198119 - 09/26/07 09:07 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
AllenAyres Offline
Registered: 12/29/03
Posts: 2020
Loc: Texas
I believe the license supports sharing of template files - whih version are you running?
_________________________
- Allen
- ThreadsDev | PraiseCafe
Top
#198121 - 09/26/07 09:13 AM Re: Intruder keeps hacking my header.tpl file [Re: AllenAyres]
Yarp™ Offline

Registered: 08/30/06
Posts: 1522
Loc: Breda, NL
 Originally Posted By: AllenAyres
I believe the license supports sharing of template files - whih version are you running?


He mentions 7.1.
_________________________
Top
#198122 - 09/26/07 09:19 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
doug Offline
member
Registered: 01/24/07
Posts: 173
I managed to get into the members area and download the header.tpl - I am now up and running. They did hack the footer.tpl as well. I will try changing the permissions as suggested above.
_________________________
UBB user since 1998
Top
#198124 - 09/26/07 10:48 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
AllenAyres Offline
Registered: 12/29/03
Posts: 2020
Loc: Texas
hmm, you might want to upgrade to the latest (7.2.2) - it's nearly impossible to support older installs against something like this without eliminating the obvious possible issue. A good number of bugfixes were fixed in the last year or so.
_________________________
- Allen
- ThreadsDev | PraiseCafe
Top
#198132 - 09/26/07 12:09 PM Re: Intruder keeps hacking my header.tpl file [Re: AllenAyres]
doug Offline
member
Registered: 01/24/07
Posts: 173
Please excuse my lack of prompt replies - I am currently out of town in a remote location - this could not be happening at a worse time.

I did change the permissions on both the header.tpl and footer.tpl files and a little while ago found that the footer.tpl had been hacked again. It may be that it was done right before I changed the permissions - I am not sure. Or it may have been done after the permissions were changed. If that is the case, what am I up against here?
_________________________
UBB user since 1998
Top
#198133 - 09/26/07 12:33 PM Re: Intruder keeps hacking my header.tpl file [Re: doug]
AllenAyres Offline
Registered: 12/29/03
Posts: 2020
Loc: Texas
Well, there really are no known security exploits in current UBB.threads code - that's not saying someone hasn't found one tho. First option is to upgrade code to current released code. If you are unable to from your remote location I can do it for you very reasonably. PM me access details and I'll handle it today.

Outside the forum code itself - it really could be anything - if you recently upgraded from an older 6.5 series you could still have shell scripts on your server from the openings back then (prior to v 6.5.5). If there are any other scripts on your server they could be allowing access - anything else installed?

It could be the server software itself - are you running current software? (I would not run on anything less than current generally available versions on my own web sites).
_________________________
- Allen
- ThreadsDev | PraiseCafe
Top
#198135 - 09/26/07 01:00 PM Re: Intruder keeps hacking my header.tpl file [Re: AllenAyres]
Rick Offline
Post-a-holic
Registered: 06/04/06
Posts: 10177
Loc: Aberdeen, WA
Doug has filled out a support ticket so I was able to get in and at least look at the access logs for the past month. It's definitely not being done by any sort of web access.
Top
#198137 - 09/26/07 01:11 PM Re: Intruder keeps hacking my header.tpl file [Re: Rick]
AllenAyres Offline
Registered: 12/29/03
Posts: 2020
Loc: Texas
Some prankster at the host?
_________________________
- Allen
- ThreadsDev | PraiseCafe
Top
#198186 - 09/26/07 08:05 PM Re: Intruder keeps hacking my header.tpl file [Re: AllenAyres]
doug Offline
member
Registered: 01/24/07
Posts: 173
I think I will back up the database using the utility within the UBB control panel this evening and then check tomorrow morning and see if the change of permissions stopped the hacks overnight and when I get back in the city on the weekend I will upgrade to the latest version and contact my host regarding possible pranksters.

Thank you for your help.
_________________________
UBB user since 1998
Top
#198233 - 09/27/07 07:54 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
doug Offline
member
Registered: 01/24/07
Posts: 173
Last night I removed all of the old files that were left over from version 6 and had changed the permissions on the header.tpl and footer.tpl files. This morning my site was hacked again - this time they inserted the code into the ubbthreads.php file - my ftp program gave the time the file changed as 4:52 am

Any ideas? Could the shout box be used to gain access? There was some shoutbox activity around 4:52
_________________________
UBB user since 1998
Top
#198234 - 09/27/07 07:55 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
doug Offline
member
Registered: 01/24/07
Posts: 173
I have contacted the host and they say they do not see any intrusion from others on the server. The host says this was likely done through one of the files still set to 777 on the server - the majority of those would be UBB files so I guess I can't change those.


Edited by doug (09/27/07 08:29 AM)
_________________________
UBB user since 1998
Top
#198238 - 09/27/07 08:22 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
Yarp™ Offline

Registered: 08/30/06
Posts: 1522
Loc: Breda, NL
Nobody else with server access besides you? Old techy?
_________________________
Top
#198239 - 09/27/07 08:30 AM Re: Intruder keeps hacking my header.tpl file [Re: Yarp™]
doug Offline
member
Registered: 01/24/07
Posts: 173
I am the only one with access to my account on the server. Never had a "techy" - I am a one man show.

Host says the file was not changed using FTP
_________________________
UBB user since 1998
Top
#198241 - 09/27/07 08:35 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
Yarp™ Offline

Registered: 08/30/06
Posts: 1522
Loc: Breda, NL
can't the host turn on some extended logging to see what is happening?
_________________________
Top
#198245 - 09/27/07 09:01 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
SD Offline
Registered: 04/19/07
Posts: 4206
Loc: SoCal, USA
i'm curious as to what it's hacked into.

is it something obvious or just not what you think it should really be displaying.
_________________________

Threads tutorials . Threads & Wordpress experts . UBB resume

If I you, click this link as to why
Top
#198260 - 09/27/07 10:06 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
Rick Offline
Post-a-holic
Registered: 06/04/06
Posts: 10177
Loc: Aberdeen, WA
I'll review your webserver access log again. I scanned through the past month when I last looked, now that you have an exact time, I can get a better idea.
Top
#198271 - 09/27/07 10:36 AM Re: Intruder keeps hacking my header.tpl file [Re: Rick]
Rick Offline
Post-a-holic
Registered: 06/04/06
Posts: 10177
Loc: Aberdeen, WA
It just so happens that all of your access logs for the month have conveniently disappeared. Instead of being able to see everything in the past month, I can only see everything starting in the past hour, so it looks like these were purged by someone.

You might want to contact your host and see if there is anywhere else a copy of these might be located as I can't find anything at this point.
Top
#198321 - 09/27/07 07:38 PM Re: Intruder keeps hacking my header.tpl file [Re: Rick]
doug Offline
member
Registered: 01/24/07
Posts: 173
Thanks to all for your help in this and especially to Rick for the excellent support and for rescuing my forum!

From what you all mentioned earlier in the post and from what I have subsequently found out - here is my theory of what has happened here...

I still did have all of the old version 6 cgi files on the server and for some reason many were set to 777. I think the intruder used those old files to acquire my account's Cpanel password and changed my files through Cpanel. I had changed the password after a previous incident but because the old files were still on the server he could get the new password.

This guy was even editing and deleting log files to cover his tracks - very persistant!

Last night I removed the old files and today I changed the Cpanel password (after multiple attacks this morning) - so I am hoping my "theory" is correct and that this is over.

We shall see what happens tomorrow I guess.
_________________________
UBB user since 1998
Top
#198326 - 09/27/07 07:54 PM Re: Intruder keeps hacking my header.tpl file [Re: doug]
doug Offline
member
Registered: 01/24/07
Posts: 173
Actaully, thinking back - Version 6 should not be given a bad rap. Version 6 may have not been the original cause of all this as I was hacked back in July and attributed it to the Front Page extensions that were "on" on my server. They probably originally gained access through Front Page extensions and may have modified some of the old CGI files for later use if needed...
_________________________
UBB user since 1998
Top
#198334 - 09/28/07 12:50 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
Yarp™ Offline

Registered: 08/30/06
Posts: 1522
Loc: Breda, NL
Let's hope you just changed the locks on your backdoor now!
_________________________
Top
#198350 - 09/28/07 05:32 AM Re: Intruder keeps hacking my header.tpl file [Re: Yarp™]
Gizmo Offline

Registered: 06/05/06
Posts: 15475
Loc: Portland, OR; USA
well, there where several file inclusion issues in ubb.t6 for versions prior to 6.5.5
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime Supporter, Beta Tester & Resident Post-A-Holic.
Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Top
#198356 - 09/28/07 05:48 AM Re: Intruder keeps hacking my header.tpl file [Re: Yarp™]
Mark S Offline
Carpal Tunnel
Registered: 07/04/06
Posts: 4480
Loc: Liverpool : England : UK
Fingers crossed for you \:\)
Hope it settles down for you now.

I guess your hacker could also be a member to watch the show
as it happens from the stands so to speak.
_________________________
Version v7.5.6 smile smile < Threads satisfaction status
People who inspire me Rick Gizmo Ian David jgeoff ntdoc
Oooo i hear 8 is coming? just after 7 my friend.
Top
#198367 - 09/28/07 08:49 AM Re: Intruder keeps hacking my header.tpl file [Re: Mark S]
doug Offline
member
Registered: 01/24/07
Posts: 173
So far so good - usually by this time I have already been hacked. I searched for the perp's IP on Google and found it in several discussions about hacking into community sites - apparently it is a problem all over the web. I assumed that the IP was spoofed but maybe not - that would explain why he was deleteing log files and changing "last login from" files.

In case anyone else suspects they have been hacked - what happens is the hackers place inline frames on your site using encryped code. These frames are invisible and sometimes you may not even realize that you have been hacked - especially on subsequent events.

The worst thing about all of this is that your members think they are getting viruses from visiting your site and traffic (and ad revenue) drops due to the redirects and members avoiding the site.

For me, the easiest way to check if I had been hacked was to click on "Show Hidden Elements" under the Miscellaneous tab on the Webmaster toolbar for Firefox.

Maybe you should try that on your site every once in a while as this issue is rampant on the web right now \:\)
_________________________
UBB user since 1998
Top
#198418 - 09/30/07 03:33 AM Re: Intruder keeps hacking my header.tpl file [Re: doug]
Zarzal Offline
old hand
Registered: 06/05/06
Posts: 1145
Loc: Berlin, Germany
There was a hole in cPanel. I read a security notice from 21.6.2007 about attacks with MPack. You are sure that your hoster close the holes in cPanel? This was used in 2006 to prepare lots of webserver with iFrames and now this servers respond to the MPack attack and deliver malicious code to the users.
_________________________
my board: http://www.dragon-clan.de
my hobby: http://www.biker-reise.de
Ich kann bei Fragen zu UBBthreads in Deutsch weiterhelfen oder es zumindest versuchen
Top
#198440 - 09/30/07 05:48 PM Re: Intruder keeps hacking my header.tpl file [Re: Zarzal]
Mark S Offline
Carpal Tunnel
Registered: 07/04/06
Posts: 4480
Loc: Liverpool : England : UK
Thanks for the feedback ;\)
_________________________
Version v7.5.6 smile smile < Threads satisfaction status
People who inspire me Rick Gizmo Ian David jgeoff ntdoc
Oooo i hear 8 is coming? just after 7 my friend.
Top
#199615 - 10/19/07 08:11 AM Re: Intruder keeps hacking my header.tpl file [Re: Mark S]
doug Offline
member
Registered: 01/24/07
Posts: 173
Zarzal, after reading up on Mpack, I believe you are correct. It sure irks me that tech support for hosts would not be aware of this issue. Instead they waste my time and ramble on and on about how I must have an insecure script when it is them that is insecure.
_________________________
UBB user since 1998
Top
#199626 - 10/19/07 06:03 PM Re: Intruder keeps hacking my header.tpl file [Re: doug]
Gizmo Offline

Registered: 06/05/06
Posts: 15475
Loc: Portland, OR; USA
This tends to happen sometimes; a webhost installs everything on the server and leaves it there; thinking "well I'm secure, everyone else is fine, so it has to be this guy", why do they do this you ask? They oversell the server, they don't want to maintain it (as it runs "properly" (IE isn't crashing) and they don't upgrade things they had to pay for (like their Control Panel) because they don't feel like dipping into their "profits" to do upkeep to protect their users.

IMO, if you have the misfortune to run into one of these shady operations, you should go elsewhere.
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime Supporter, Beta Tester & Resident Post-A-Holic.
Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Top
Page 1 of 4 1 2 3 4 >



Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Marking a topic as 'read' manually
by sw55
Yesterday at 04:29 PM
How to add AD island?
by Conrad
Yesterday at 01:19 PM
Need to update from 6 to latest: can't until server checked
by Digilady
06/17/13 08:17 AM
Shout Box
by Bert
06/15/13 04:15 PM
Calendar
by Bert
06/15/13 04:11 PM
Forum Stats
11000 Members
36 Forums
33988 Topics
183527 Posts

Max Online: 978 @ 06/24/07 10:19 PM
Random Image