Sinisterly
Any possible reason ? - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Any possible reason ? (/Thread-Any-possible-reason)



Any possible reason ? - lucashoang - 04-08-2012

Hi!
My website is running Vbulletin 4.1.11 and it has been hacked yesterday.
it's just a deface, database is ok and all the cp is working.
I've tried to deleted forum.php and index.php and reupload them but no use

Here is my question:
- Is there any possible way to hack in to vbulletin with only deface.
- If there was sql injection, how can I check it

p/s: here is my website: 123-airsoft.info in case any of you want to see how it been deface Wink


Regards


RE: Any possible reason ? - kiko0735 - 04-08-2012

It have XSS if you want i can reg and test it?


RE: Any possible reason ? - 1llusion - 04-08-2012

(04-08-2012, 10:46 AM)lucashoang Wrote: Here is my question:
- Is there any possible way to hack in to vbulletin with only deface.

Wait... what? Using the deface to hack? No way.

If he defaced your website, it means he had access to the files. He could do anything with them. Search your forum name on google to find out if he released your db or something like this =)


RE: Any possible reason ? - lucashoang - 04-08-2012

I've recover my database, reinstall vbb and they attack again.
This time my database is gone.
I can recover again as I still have backup file but I know if I do that, there are no use.
Can any one help me to exploit my website.?
I really wanted to know how and which way can they do that !
I got 0 knowledge about hacking Sad

/kiko0735: how can I contact you Smile Very pleasure if you can help me to exploit my site