 |
 |
 |
 |
Registered: 04/19/07
Posts: 4206
|
|
|
 |
 |
 |
 |
|
 |
 |
 |
 |
#250181 - 09/10/12 02:56 AM
Many ubbthreads sites seem compromised.
|
enthusiast
|
Registered: 06/05/06
Posts: 266
Loc: Taiwan
|
|
First , there are files injected into this dir : ${ubbthreads}/images/forumimages/default
-rw-r--r-- 1 x x 23 2011-12-18 12:09 exploit.conf
-rw-r--r-- 1 x x 993 2011-12-13 11:56 cons.php
-rw-rw-rw- 1 x x 40756 2011-11-19 16:06 admin_2011.php
-rw-r--r-- 1 x x 77035 2011-09-23 00:06 gold.php
-rw-rw-rw- 1 x x 34 2011-09-15 16:28 config.php
And then , I notice a lot of 'POST action' to admin_2011.php , modifying includes/header.php and includes/footer.php That's why there's another thread complaining unwanted Google Ads shown. I think UBBT team should take actions ASAP ! Most important of all , find out how these PHPs are injected to the directory , are there any exploits within ? (7.5.6p2) By the way , the attacking IPs are from China : 118.253.12.77 , 101.226.33.201 If admin needs these exploit files , just tell me.
_________________________
English is not my native language. I try my best to express my thought precisely. I hope you understand what I mean. If any misunderstanding results from culture gaps , I apologize first.
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
|
Express Hosting
"We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
|
|
|
 |
 |
 |
 |
 |
 |
 |
 |
#250191 - 09/10/12 06:33 PM
Re: Many ubbthreads sites seem compromised.
[Re: smallufo]
|
journeyman
|
Registered: 07/21/08
Posts: 52
|
|
Hey Guys, I seem to have been hacked for the first time. The delete member button row below the member profile has been removed so I must use an old cached page to access that area and manually change the member number to access it. Perhaps this is a known or old problem for a version as old as ours. We've been hoping for the new version for years like many others but now we've been bitten. Suggestions short of updating it? And perhaps if it's hacked, updating will be an issue? Our folks have actually been satisfied mostly with the site as is, short of wish it had functionality to react to Facebook, Twitter etc. Thanks for any light you guys can shed! Brian www.justplainfolks.org
_________________________
Brian Austin Whitney Founder Just Plain Folks Music Organization www.justplainfolks.org
|
|
Top
|
|
|
|
|
 |
 |
 |
 |
|
|