MyBB Community Forums

Full Version: Mybb Forum Spam
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2
Hello

in my mybb forum on a regular interval someone upload a php file and send a spam through it

here what file he uploads

http://pastebin.com/yHm1zUf3

Can anyone here help to secure the forum will pay if some one secure it

Thanks
Here are some good docs to help you get things back under control:

http://docs.mybb.com/1.8/administration/.../recovery/
http://docs.mybb.com/1.8/administration/...protection

Who do you use as a host, out of curiosity?
Hello!
Just out of interest, I decoded the file: http://pastebin.com/HLDjRfEN

Thomas131
(2015-08-24, 07:51 AM)Thomas131 Wrote: [ -> ]Hello!
Just out of interest, I decoded the file: http://pastebin.com/HLDjRfEN

Thomas131

hello

thanks for this any help from the above to not going the spam from it
how can i find either the plugin or mybb file is having this issue
Do you know how exactly this backdoor is getting uploaded to your forum?
sorry dont have much knowledge about it but daily its keep getting upload to random folders

anyone here provide paid support to this issue please pm me
I would contact your host for help and they might be able to dig into some logs to see if they can figure out what exactly is happening.

In the meantime, run a File Verification in the ACP and if there are any changed files that you didn't know have changed (i.e. you didn't make a core edit yourself), then read through each of the respective files to see if there's any code that just looks out of place (such as a whole bunch of random unintelligible strings).

Also, run an antimalware scan on your computer, then change all site passwords (cPanel and any other administrative ones).
You should probably configure your web server to serve any file with php as an extension in your uploads folder as text/plain.
(2015-09-02, 05:05 PM)laie_techie Wrote: [ -> ]You should probably configure your web server to serve any file with php as an extension in your uploads folder as text/plain.

from admin panel or server settings let me know
(2015-10-11, 09:10 AM)gamejump Wrote: [ -> ]
(2015-09-02, 05:05 PM)laie_techie Wrote: [ -> ]You should probably configure your web server to serve any file with php as an extension in your uploads folder as text/plain.

from admin panel or server settings let me know

Server settings.
Pages: 1 2