Closed Thread
Old 09-06-2009, 04:57 PM WT Security Incident
Admin's Avatar
Administrator

Posts: 16
Trades: 0
Last night at about 7:30PM WT was redirected to a porn site. This was a result of the latest Wordpress vulnerability that has been affecting a large number of websites.

We took the server offline until we could isolate the exact cause of the issue. From our investigation the attacker used the WP vulnerability to overwrite one of the main vBulletin files resulting in the redirection of the site.

At this point there is no data loss and we were able to restore the site files from the day before backup. From what we can tell no one's email addresses or other information was compromised or taken.

If you have any questions please post them here. Thanks for everyone's patience and we apologize for the inconvience this caused to WT users.

We have fully updated all of the software running on WT, including vBulletin and Wordpress to the latest versions.
Admin is offline
View Public Profile
 
 
When You Register, These Ads Go Away!
Old 09-06-2009, 05:32 PM Re: WT Security Incident
LadynRed's Avatar
Super Moderator

Posts: 9,036
Location: Tennessee
Trades: 0
Glad to see you were able to get this resolved so quickly !
__________________
Web Goddess & Web Standards Evangelist :) - Tables Be Gone !!
"Using or working with IE is like having to wear a 1970's polyester suit with pantyhose and a girdle, to work everyday"
Carolina Corvette Club
LadynRed is offline
View Public Profile
 
Old 09-06-2009, 05:45 PM Re: WT Security Incident
Moxxnixx's Avatar
33.33333% Evil

Posts: 1,146
Name: Lance
Location: Virginia Beach
Trades: 0
Nice to know everything's back to normal. I was going crazy there for a while.

Oops, spoke too soon. When I click on a member's username I get this error...
Code:
Parse error:  syntax error, unexpected ':', expecting ']' in /home/waynetim/public_html/includes/class_profileblock.php(292) : eval()'d code on line 2
__________________
Get your facts first, and then you can distort them as much as you please. - Mark Twain
Moxxnixx --- FreewareDog --- Beaches Designs
All My Sites Are Proudly Hosted @ HostGator

Last edited by Moxxnixx; 09-06-2009 at 05:51 PM..
Moxxnixx is online now
View Public Profile Visit Moxxnixx's homepage!
 
Old 09-06-2009, 05:48 PM Re: WT Security Incident
jamestl2's Avatar
No scale-itch here...

Posts: 2,334
Name: <member type="brilliant" alt="foolish">James Lewitzke</member>
Location: / public_html / Universe / Virgo_Supercluster / Local_Group / Milky_Way / Orion_Arm / Solar_System / Earth / North_America / USA / Wisconsin
Trades: 0
So that p0rn site redirection wasn't planned then?
__________________
Engipress - Wordpress Community and Resources
Hire me for Wordpress Projects | Wordpress Forums
jamestl2 is offline
View Public Profile Visit jamestl2's homepage!
 
Old 09-06-2009, 05:53 PM Re: WT Security Incident
chrishirst's Avatar
Super Moderator

Posts: 26,557
Location: Blackpool. UK
Trades: 0
Didn't take long for the phone spammers to restart either!!!!
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
Growing old is mandatory - Growing up is optional
Code Samples | Crowded Nightclub? | Bits & Bobs
chrishirst is offline
View Public Profile Visit chrishirst's homepage!
 
Old 09-06-2009, 06:18 PM Re: WT Security Incident
wayfarer07's Avatar
I like pie

Posts: 3,369
Name: Abel Mohler
Location: Asheville, North Carolina USA
Trades: 0
Quote:
Originally Posted by chrishirst View Post
Didn't take long for the phone spammers to restart either!!!!
At least that is spam that we can just delete.
__________________
Wayfarer | jQuery Tooltip | Mapbox: the jQuery Map
Latest Project: Houston Movers
If Google is the Coca-Cola of Web search, Bing is RC Cola
wayfarer07 is offline
View Public Profile Visit wayfarer07's homepage!
 
Old 09-06-2009, 06:28 PM Re: WT Security Incident
Admin's Avatar
Administrator

Posts: 16
Trades: 0
Quote:
Originally Posted by Moxxnixx View Post
Nice to know everything's back to normal. I was going crazy there for a while.

Oops, spoke too soon. When I click on a member's username I get this error...
Code:
Parse error:  syntax error, unexpected ':', expecting ']' in /home/waynetim/public_html/includes/class_profileblock.php(292) : eval()'d code on line 2
Thanks for pointing this out we will take a look.
Admin is offline
View Public Profile
 
Old 09-06-2009, 06:34 PM Re: WT Security Incident
chrishirst's Avatar
Super Moderator

Posts: 26,557
Location: Blackpool. UK
Trades: 0
Nice to see the latest admin features have made it to the site as well.

Ban the spammers and bin their posts in three easy clicks
__________________
Chris. ->> Links are advertising NOT optimising!! <<-
Growing old is mandatory - Growing up is optional
Code Samples | Crowded Nightclub? | Bits & Bobs
chrishirst is offline
View Public Profile Visit chrishirst's homepage!
 
Old 09-06-2009, 09:28 PM Re: WT Security Incident
JSTYLISH's Avatar
Grphc Dsngr & Nrd

Posts: 362
Name: Styla
Location: City of London
Trades: 0
Quote:
Originally Posted by Admin View Post
Thanks for pointing this out we will take a look.
Another one to add to your stressful day!

Quote:
Your submission could not be processed because a security token was missing.<br />
<br />
If this occurred unexpectedly, please <a href="sendmessage.php">inform the administrator</a> and describe the action you performed before you received this error.
This occurred when I tried to give some talkupation.
__________________
a website | If you have time
a magazine | If you don't have time
JSTYLISH is offline
View Public Profile Visit JSTYLISH's homepage!
 
Old 09-06-2009, 09:32 PM Re: WT Security Incident
Skilled Talker

Posts: 96
Trades: 0
I'm a bit confused, this is a vbulletin forum right? so why was it affected by a wordpress vulnerability
Towhid is offline
View Public Profile
 
Old 09-06-2009, 09:52 PM Re: WT Security Incident
Giselle's Avatar
"Springtime!"

Posts: 4,330
Name: Giselle
Location: Washington State
Trades: 0
Everything was working pretty good awhile back, even posted some posts, went to the user panel and wanted to go back to the main page and was completely locked out. I couldn't go anywhere, there was an error of some sort, wish I had thought to take a picture. I tried to log back in but the same error came up, I was just able to come back into the forum a little while ago.

Also I am not receiving email notifications to subscribed threads. When I go to the cp panel and the list of new threads that I had subscribed to are up when somebody made a new post, could I just resubscribe in the thread tools when I go to that thread? If this could work, I can do this myself.

Truly am sorry for the trouble and work this has put you through, what a nightmare!

I was checking on a profile and received this message:

Parse error: syntax error, unexpected ':', expecting ']' in /home/waynetim/public_html/includes/class_profileblock.php(292) : eval()'d code on line 2

The good news, a few seconds later the profile did come up and I wasn't locked out.
__________________

Last edited by Giselle; 09-06-2009 at 10:12 PM..
Giselle is offline
View Public Profile
 
Old 09-06-2009, 11:34 PM Re: WT Security Incident
fresh-d's Avatar
Experienced Talker

Posts: 33
Trades: 0
Glad to see you guys are back.
fresh-d is online now
View Public Profile
 
Old 09-07-2009, 04:25 PM Re: WT Security Incident
Admin's Avatar
Administrator

Posts: 16
Trades: 0
Yeah it's been a trying time as we had a ton of wordpress installs that had to be updated due to the vulnerability. Not much of a long weekend !

Please post any other issue in here I will be keeping an eye on it.
Admin is offline
View Public Profile
 
Old 09-07-2009, 05:14 PM Re: WT Security Incident
LadynRed's Avatar
Super Moderator

Posts: 9,036
Location: Tennessee
Trades: 0
Quote:
Ban the spammers and bin their posts in three easy clicks
Yay!! I'm glad you took my suggestion

Glad you're back now too
__________________
Web Goddess & Web Standards Evangelist :) - Tables Be Gone !!
"Using or working with IE is like having to wear a 1970's polyester suit with pantyhose and a girdle, to work everyday"
Carolina Corvette Club
LadynRed is offline
View Public Profile
 
Old 09-08-2009, 11:46 AM Re: WT Security Incident
Giselle's Avatar
"Springtime!"

Posts: 4,330
Name: Giselle
Location: Washington State
Trades: 0
When you get a chance, could you please reset the avatars. I tried to change my avatar and a sign tells me it was unable to save the file. Also on posting a message, the font and size works fine, but the colors are dead, well at least for me. I don't use different colors for text but once in awhile I do, it's a nice function to have.

Sure would greatly appreciate it and also when you get a chance, thanks!
__________________
Giselle is offline
View Public Profile
 
Old 09-08-2009, 02:28 PM Re: WT Security Incident
jamestl2's Avatar
No scale-itch here...

Posts: 2,334
Name: <member type="brilliant" alt="foolish">James Lewitzke</member>
Location: / public_html / Universe / Virgo_Supercluster / Local_Group / Milky_Way / Orion_Arm / Solar_System / Earth / North_America / USA / Wisconsin
Trades: 0
It also appears that the hackers messed with the vBSEO add-on. The thread URLs changed and vBSEO is no longer mentioned in the footer (unless this was altered by the staff, of course...).
__________________
Engipress - Wordpress Community and Resources
Hire me for Wordpress Projects | Wordpress Forums
jamestl2 is offline
View Public Profile Visit jamestl2's homepage!
 
Old 09-08-2009, 03:02 PM Re: WT Security Incident
jamestl2's Avatar
No scale-itch here...

Posts: 2,334
Name: <member type="brilliant" alt="foolish">James Lewitzke</member>
Location: / public_html / Universe / Virgo_Supercluster / Local_Group / Milky_Way / Orion_Arm / Solar_System / Earth / North_America / USA / Wisconsin
Trades: 0
BTW: It also appears the sidebar ad is gone (if that was done intentionally, then THANK GOD!!!).
__________________
Engipress - Wordpress Community and Resources
Hire me for Wordpress Projects | Wordpress Forums
jamestl2 is offline
View Public Profile Visit jamestl2's homepage!
 
Old 09-08-2009, 04:59 PM Re: WT Security Incident
Giselle's Avatar
"Springtime!"

Posts: 4,330
Name: Giselle
Location: Washington State
Trades: 0
Quote:
Originally Posted by jamestl2 View Post
BTW: It also appears the sidebar ad is gone (if that was done intentionally, then THANK GOD!!!).
Shhhhhhhhhhhhhhhh, we don't want to bring that to their attention!
__________________
Giselle is offline
View Public Profile
 
Old 09-08-2009, 08:18 PM Re: WT Security Incident
NullPointer's Avatar
Will Code for Food

Latest Blog Post:
Apparatus Update Preview
Posts: 1,173
Name: Matt
Location: Irvine, CA
Trades: 0
Glad to see everything is up and running again.

Funny story:

My girlfriend came into the living room and was acting a bit strange toward me for a while. I asked her if she wanted to watch a movie later and she just kind of looked at me in a strange way and said she didn't want to. I brushed it off and went into my room to discover the porn site WMT was being redirected to on my computer. Apparently the last time I was using my computer I was browsing the forum and as soon as the browser was opened (by my girlfriend) the active tab was set to WMT (ie the porn site).

That took a bit of explaining...
__________________
Tinsology | How to Post Code | RosettaCodex
NullPointer is online now
View Public Profile Visit NullPointer's homepage!
 
Old 09-08-2009, 09:44 PM Re: WT Security Incident
Giselle's Avatar
"Springtime!"

Posts: 4,330
Name: Giselle
Location: Washington State
Trades: 0
I just laughed and laughed Matt, a really funny story, although at the time it certainly wasn't funny. I assume all is well with your lady friend, I can only imagine what went through her mind, seeing as I am a woman. Thanks for sharing the story!
__________________
Giselle is offline
View Public Profile
 
Closed Thread     « Reply to WT Security Incident

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML

 


Page generated in 0.13711 seconds with 13 queries