Hacked! Vbulletin Redirect - Turkish Hackers & HostGator Sucks
September 13th, 2007 by Jeremy EnkeOh my, what a long 36 hours I have had. I feel like going to the store and buying a couple 40 ounces, then after swallowing those down perhaps I could smoke a fat blunt. That would be very fitting, unfortunately that would probably even get fucked up somehow.. It all started yesterday when I hit reply to a thread at PAW and BOOM, up pops the Turkish Hack. Well actually it’s not really even a hack, it’s just a redirect. More about that in a second though. Just to get you in the mood to discuss Turkish Hacking, you should play this song, minimize, and continue reading. Apologies for the upcoming foul language in this post in advance too…..
Turkish Hackers Using A Vbulletin Redirect
Okay, now that the mood is proper let’s continue. The first thing that puzzles me about these assholes is that there is really no purpose or point of doing this. Likewise there is no motive, although on their kiddie hacking log it did say “political reason” in Turkish. For fuck sake guys, at least try to extort me for some of this filthy U.S. money. Like I said this is kiddie work, and it wasn’t really a true hack. No help to the fucktards that work in HostGator support (more on that in a bit) I was able to research the actual exploit and find this out on my own.
I believe the redirect was allowed to be inserted into either a thread title or username on new user registration. Normally VB will not allow html to be placed in titles, usernames, or anywhere else on the board by default. However when you have 3rd party plugins or mods installed, these can sometimes be opened up to exploitation. The only plugins I have installed are VBSEO, NoSpam, and VBSociable. So it actually could have been another setting in the admincp. Nonetheless here is the easy fix. Again this is nothing but a simple html redirect being inserted somewhere.
There are two ways to fix this or avoid this. First, make sure that html is disabled in all posts. Then you need to add these words and characters to your “Censored Words List” in the Vbulletin admin panel.
{meta} http-equiv content=”0 content=0 content=<
If the hack is being caused by a plugin of some sort you can also immediately stop the redirect by disabling the Plugin/Hooks globally via the admncp. That is my final conclusion on what happened both this time and last time the forum was hacked. I have disabled a few of the plugins as well as added the proper words to the censored words list. I’ll keep my fingers crossed.
Hostgator Sucks For Large Websites and Dedicated Servers
I have been with hostgator for several years but will be leaving soon. Well as soon as the Lithuanians get PAW off this box (which was supposed to be completed weeks ago)…..that’s whole other rant. Anyways, I have a dedicated server with them that houses around 10 sites at a cost of aprox. $350 a month. I also have a reseller account with them that houses aprox. 30-40 smaller less trafficked sites.
I have never had a single issue with my reseller account. However in less than 12 months, I have had to open over 24 support tickets for my “managed” dedicated server. Let me list the reasons of why you should never ever under any circumstance get a dedicated server with hostgator.
Reason #1 - When I first signed up for the dedicated server, they were more than happy to facilitate the move of PAW from the reseller account. Many of you that have been around for a while may remember the following. When they moved the site, they somehow fucked up the SQL database and lost a months worth of postings. The only backup they had was a month old. Dohhhhh, wouldn’t a competent server admin make a backup of the site before attempting to move critical pieces of it. Apparently not these guys.
Reason #2 - When I signed up for this $350 dedicated server I was told, and it is published on their sales page that Urchin Stats are included. Well guess what, although nobody made it known to me, my server was actually outsourced and to this day is still a server from a company called Layered Technologies! These LT servers don’t come with Urchin like advertised by Hostgator. Likewise when I have support issues where someone actually has to work on the box, it first goes to hostgator, and then to some random tech at Layered Technologies. This is a joke, and I never would have known this had I not asked for Urchin. If I buy a fucking server from Hostagtor, I expect it to be housed at The Planet with every other Hostgator server.
Reason #3 - The people in their support department have no fucking clue what they are doing. All they know how to do is escalate tickets. Then heaven forbid your support ticket gets escalated to Level 3 or critical. Now it’s in the hands of some system admin that is offshore and not even in a hostgator office. Good Luck if he leaves for the day, you’re fucked for 16 hours while you call and they escalate your ticket to some other dipshit. Like I said earlier, if you just need a reseller account or to host small sites, hostgator is adequate. But for a dedicated managed server, forget it.
Reason #4 - Let’s look at this incident. I saw the forums were hacked and immediately opened up a ticket. From the beginning I knew this was going to be a cluster fuck between Chicago, Lithuiania, Australia, Texas, and some hut in Pakistan. So I asked them to just restore the site from the most recent backup. It fell on deaf ears and some server admin started picking apart the SQL database as he was convinced the hack was an SQL Injection that “has done severe damage” to the entire site. So 12 hours later, PAW comes back up without the re-direct……ummmm but wait, there are no forums or content……. I reply to the ticket and when I see the server admin reply I almost have a heart attack. He tells me that there are no backups and the information is damaged.
Rewind 3 months, I have email documentation from Hostgator telling me that my “managed” and dedicated server is backed up every day. After all the B.S. I have dealt with this was extremely important. When I reply with the email documentation and a few other choice words, they magically find the daily backup. So they backed it up to yesterday before the hack. As you may have seen this morning the forums were still a mess. After fucking everything up for almost 24 hours and screwing with SQL databases that didn’t need to be messed with, Hostgator replies and says I will need to rebuild it from here and that the hack did quite a bit of damage.
Hey Dipshits, Isn’t the backup from before the hack? Regardless, my man Bobi from TopQ saved the day as always and got the right files where they needed to be. Bottom line is that Hostgator has been nothing but a disappointment from day 1 with my dedicated server.
Speeding Ticket
So finally today when everything seems to be under control with PAW, I go to the bank to see if a large affiliate payment that is owed to me was received. Imagine that……No Money!. That’s about par for course………….but wait it gets better. On the way home a pleasant Illinois State Trooper pulled me over and wrote me a ticket for 12 mph over the limit. I’m so thankful he slowed me down before I lost control and caused chaos on the expressway. Although I was going with the flow of traffic, I am convinced I was pulled over because I am white, drive a Lexus, and was drinking Starbucks. These kind of racial profiling excuses work for everyone else in the U.S….. why not me?



I suppose an “About Me” page is where you would expect to read a third person professional write up on myself. Hmmm…. well that’s not really my style, so I’ll just go ahead and tell you “about me” in my own words.












September 13th, 2007 at 4:53 pm
Murphy’s Law man, I say you ask for them to mail you the box after you switch and smash it up. See video for example.
http://www.youtube.com/watch?v=J_dHJYyQDJk&mode=related&search=
September 13th, 2007 at 6:31 pm
nice job getting the site back up. don’t forget to keep local backups on file each week just to be safe.
September 13th, 2007 at 9:47 pm
Jeremy Time to switch hosts . i remember using hostgator about 18 months ago , they were slow as shit . I lasted 3 days with them then went to bluehost , best decision i ever made . On top of that hostgator never credited me my refund which they state you have 30 days to request on there website
September 14th, 2007 at 6:58 am
I don’t understand why they have to keep holding the white man down like that… booo state troopers!
September 24th, 2007 at 6:31 pm
where did you get this social bookmark script from? can i buy it from you if you wrote it yourself?
September 28th, 2007 at 4:45 am
Is vBulletin still the best forum software around? I hear so many problems about vBulletin forums being vunerable, but I can’t think of a good alternative… surely there must be one stable forum script
September 29th, 2007 at 12:03 am
Hi
Very much for a long time searched for article on this theme.Thanks.
by
October 24th, 2007 at 10:20 am
[…] that PAW is either down today or experiencing some massive lag today. Don’t worry, the vbulletin forum was not hacked again. Finally I was able to get the guys to move PAW to a new server. Hopefully this will alleviate […]
June 27th, 2008 at 10:13 am
Thanks for this post. I was able to fix the turkish hack on my vbulletin forum as well.
July 5th, 2008 at 12:04 pm
[…] - not behaving ???????????L&?f???? BarbieriRacingForum Guestbook for detention.20fr.com Hacked! Vbulletin Redirect - Turkish Hackers & HostGator Sucks | JeremyEnke.com - Your Daily Do… Network of Care - Jasper ???????? ????? ????-? Projet d’acad?mie 2003-2007 : bilan - Ecrire un […]
July 9th, 2008 at 2:28 am
I’m not sure what you are talking about with Hostgator’s admins being offshore. I was an admin there before your server issues and we were on the same floor as the support techs. When support couldn’t handle the big stuff they would bump the ticket over to us and we would fix it as they came in. Usually on dedicated servers we needed to bump it up to level 2 who was also working on the same floor with us. There are support techs and network admins on 24/7. You don’t have to catch them before they get off at 5 because we were always there.
My shift had 6 admins and about 20 chat techs. Plenty of support staff to fix stuff.
July 23rd, 2008 at 12:09 pm
Thanks for this post. I was just hacked by these assholes today!