MyBB Community Forums

Full Version: possible MyBB Plugin Malware or Adware?!
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Issue was resolved Smile


This is a newer installation with the following plugins installed:
Advanced Quick Reply Form (1.0.3)
This plugin adds the MyCode Editor and the Smilie Inserter to the Quick Reply form.
Created by Phenomenon
MyBB Advanced Portal v (7)
Advanced Portal Plugin for MyBB.
Created by bomfile - dared
Advanced MyCode Permissions (1.4)
Allows you to set permissions for custom MyCode use. Also allows you to use variables in your mycode.
Created by Jammerx2
Auto Media (2.1)
Embeds automatically videos and music from different sites in posts.
For more information view documentation.
Default Avatar (1.0)
Force users to have an avatar. Set default information in ACP -> Settings -> User Registration and Profile Options.
Click here to set a default avatar to current users which do not have one selected.
Created by Santiago Dimattia
Forum Icons (3.0)
Adds icons to forums on index.
Created by Jesse Labrocca
Game Section (1.2.2)
Makes a powerfull system for playing games on your MyBB board.
Created by Paretje
Google SEO (1.6.3)
Google Search Engine Optimization as described in the official Google's SEO starter guide. Please see the documentation for details.
Its My Birthday! (2.2)
Sends Mail/PM to user on his/her Birthday. Fully customizable including option to start a thread or post and having users add wishes without posting replys.
Created by - G33K -
Mods Cant Edit Admins Posts (1.1)
Moderators cannot edit administrators posts.
Created by Jammerx2
ModNotice Plus (1.5.2)
This plugin create a new edit option for moderators. It allow moderators to create a message which a normal user can't erase or change.
Created by Prtik
My Ad Manager (1.2)
The Ultimate Mybb Ad Management System
Created by Jesse Labrocca
My Awards (2.3)
Give awards icons to members.
Created by Jesse Labrocca
MyBBpublisher (1.7.0)
Publishes selected MyBB content to several social media sites.
Created by CommunityPlugins.com
MySupport (0.4.2)
Add features to your forum to help with giving support. Allows you to mark a thread as solved or technical, assign threads to users, give threads priorities, mark a post as the best answer in a thread, and more to help you run a support forum.
Created by MattRogowski
Naoar Donation (2.0)
Accept Donations through AlertPay / LibertyReserve / Moneybookers(Skrill) / PayPal, manage donations / donors, add donations goal / target donations stat and more..
PluginLibrary (8)
A collection of useful functions for other plugins.
Created by Andreas Klauer
Private Messages Admin (2.4.3)
Gives admins the ability to look through their forums private messages.
Created by Aaron
Advanced Rainbow Colors For All Links (1.0)
Displays javascript logout confirmation.
DONATE and support us if you like the service.
Created by GodFather
SCD Hide From Groups (Free SCD Plugin) (2.5)
When activated it will hide the contents of selected MyCode tags in your posts from selected groups.
Created by Dylan Myers
Sig Image Size (1.0)
Adds a signature image size check.
Created by Jesse Labrocca
Staff Online (0.1)
Allows you to show an Staff Online section under Board Stats.
Created by Yaldaram
Tapatalk (3.1.0)
Tapatalk MyBB Plugin
Created by Quoord Systems Limited
Undo Delete (1.2.1)
Allows you to restore deleted threads, posts, polls and attachments.
Created by Sebastian Wunderlich
Who download this attachment (1.0)
Log who download attachments and display them as a list on postbit.
Created by Surdeanu Mihai


Has anyone had this happen to them before or could it be from any of these plugins? How do I find the source/culprit?
Haven't seen that plugin before, where did you get that from ?
Which plugin frank? I've listed a lot of plugins that I have installed.

Also.. I just verified.. this happens on no other sites but mine... so I know it's something installed on the forum itself....
Oh sry : Who download this attachment (1.0)
oh, it's Who download this attachment v1.0 BETA
by MyBBRomania Team,
I downloaded it from this forum..
although I'm having a hard time right now finding it in the mods section for you...
all I found was this:
http://community.mybb.com/thread-118012....achment%22
Oh ok that looks ok. Have you tried checking your server root for any rogue files.
yep, site root and server root are clean... it's a new host too.
When searching the entire source of the forum for "meta name"
The only plugins that have that are:
advportalv7
google_seo\google_seo.html and meta.php
and an html file for the automedia plugin.

and not a single plugin has "freebie" in it's source...

so this leads me to believe it's a perm linked or local script being loaded.... not directly source code written.

Any ideas?

FOUND IT! I don't know why it didn't show up in a dreamweaver source search... ah.. it's probably because it's in the database... okay... not sure what put it there but it was here:
Admin CP>>Templates & Style>>Main Template>>Ungrouped Templates>>headerinclude

I thought the header template was where to put metadata but when trying to solve this I realized my metadata was in the body not the head so when googling for how to put metadata in the header in MyBB I found a thread that said to put it in the headerinclude template... when going to it I found the bad metadata in there... I suspect one of these plugins did that when installing/activating them... I can't think of any other explanation.


Edit:
Facebook is still showing the mal-metadata.... and I no longer see it in the header with firebug... so I have no idea now.. does FB cache it's scrapes?
Run file verification in the ACP and see what that returns. Also, try downloading a fresh jscripts folder.