phpBB.com hacked - been offline all day

  Post new topicReply to topicPrintable Version
<< View previous topic View next topic >>
Share: Del.icio.us  Digg  Google  Spurl  Blink  Furl  Y! MyWeb  
#1   phpBB.com hacked - been offline all day
VirtualChicano
CZ Newbie
 Codezwiz Site Donator
VirtualChicano has been a member for over 19 year's 19 Year Member
Status: Offline
Joined: Dec 05, 2004
0.00 posts per day
Posts: 6
Points: 1,129
   
[ Register or login to view links on this board. ]
Creating Communities

At present [ Register or login to view links on this board. ] is offline due to a group of politically motivated hackers wishing to use an opensource project to push their agenda ... shame on them.

I will take this opportunity to note that given currently available information this hacking episode does not appear to be due to phpBB itself. Instead a third party application looks to have been the problem. Other sites were attacked at the same time as [ Register or login to view links on this board. ] by the same group displaying the same information and in these cases the same third party application has been suggested as the common factor (thus far). Equally we are not aware of any other phpBB boards being attacked and we have not been notified of any valid security issues recently. Obviously we will have more details when we've reviewed just what happened.

We are working to recover the server but this may take some time. Meanwhile users can visit our development board, area51.phpbb.com where they can receive support for phpBB 2.0.x. Of course you can also view the next version of phpBB, 3.0 "Olympus" in the process (minus the new style of course!)

We are also maintaining our IRC support channel, #phpbb on the irc.freenode.net network

We apologise for any problems this may cause our userbase. We obviously take the huge support our community gives phpBB very seriously. And we will do our best to return to "normal operations" just as soon as we can.

psoTFX - phpBB Group




_________________
Back to top Reply with quote
#2   
Staffie
CZ Revered Member
 Codezwiz Site Donator
Staffie has been a member for over 20 year's 20 Year Member
uk.gif
Occupation: Investigation Officer
Age: 39
Gender: Male
Website:
Status: Offline
Joined: May 27, 2003
0.19 posts per day
Posts: 1454
Points: 401,085
   
ty for the info




_________________
Back to top Reply with quote
#3   re: phpBB.com hacked - been offline all day
echo
CZ Wiz
 Codezwiz Site Donator
echo has been a member for over 20 year's 20 Year Member
Gender: Male
Status: Offline
Joined: Oct 04, 2003
0.15 posts per day
Posts: 1147
Points: 93
   
Now I know why I couldn't access the phpBB site, thanks for the update.



Back to top Reply with quote
#4   
fncool
CZ Super Newbie
 Codezwiz Site Donator
fncool has been a member for over 19 year's 19 Year Member
canada.gif
Age: 62
Gender: Male
Status: Offline
Joined: Dec 19, 2004
0.01 posts per day
Posts: 56
Points: 4,786
   
i was just over there and saw that, came back here to post and found this post.

i don't know about you guys, but i find it a bit disconcerning when the developer's own site gets hacked.

i'm kind of glad i haven't started promoting my site yet, otherwise i'd likely be doing backups twice a day right now.




_________________
I'm only replying because I want those extra 22.52 points!
Back to top Reply with quote
#5   
Telli
Site Admin
Telli has been a member for over 20 year's 20 Year Member
Occupation: Self Employed
Age: 45
Gender: Male
Fav. Sports Team: Detroit Red Wings
Website:
Status: Offline
Joined: May 26, 2003
1.06 posts per day
Posts: 8089
Points: 494,430
   
Yes they are claiming its because of third party software. I personally dont use a standard phpBB (not obvious?) but I would be on the look out.




_________________
The path of the righteous man is beset on all sides by the inequities of the selfish and the tyranny of evil men. Blessed is he, who in the name of charity and good will, shepherds the weak through the valley of darkness, for he is truly his brother's keeper and the finder of lost children. And I will strike down upon thee with great vengeance and furious anger those who would attempt to poison and destroy my brothers. And you will know my name is the Lord when I lay my vengeance upon thee. Ezekiel 25:17
Back to top Reply with quote
#6   re: phpBB.com hacked - been offline all day
Kelly_Hero
PayPal Donation
CZ Revered Member
 Codezwiz Site Donator
Kelly_Hero has been a member for over 20 year's 20 Year Member
usa.gif southcarolina.gif
Occupation: Web Developer
Age: 59
Gender: Female
Website:
Status: Offline
Joined: Aug 20, 2003
0.50 posts per day
Posts: 3765
Points: 351,412
   
I've read about this on several websites today. Any idea what the "third-party software" is that they're referring to?



Back to top Reply with quote
#7   
Telli
Site Admin
Telli has been a member for over 20 year's 20 Year Member
Occupation: Self Employed
Age: 45
Gender: Male
Fav. Sports Team: Detroit Red Wings
Website:
Status: Offline
Joined: May 26, 2003
1.06 posts per day
Posts: 8089
Points: 494,430
   
If I had to guess I would say there php engine. Not real sure though.




_________________
The path of the righteous man is beset on all sides by the inequities of the selfish and the tyranny of evil men. Blessed is he, who in the name of charity and good will, shepherds the weak through the valley of darkness, for he is truly his brother's keeper and the finder of lost children. And I will strike down upon thee with great vengeance and furious anger those who would attempt to poison and destroy my brothers. And you will know my name is the Lord when I lay my vengeance upon thee. Ezekiel 25:17
Back to top Reply with quote
#8   re: phpBB.com hacked - been offline all day
bull_ish2004
CZ Newbie
bull_ish2004 has been a member for over 19 year's 19 Year Member
Gender: Male
Status: Offline
Joined: Dec 17, 2004
0.00 posts per day
Posts: 2
Points: 699
   
i heard it was AWStats.
http://www.awstats.org/

this is a msg on awstats site



Warning, a security hole was recently found in AWStats versions from 5.0 to 6.2 when AWStats is used as a CGI: A remote user can execute arbitrary commands on your server using permissions of your web server user (in most cases user "nobody").
If you use AWStats with another version or with option AllowToUpdateStatsFromBrowser to 0, you are safe. If not, it is highly recommanded to update to 6.3 version that fix this security hole.



Back to top Reply with quote
#9   re: phpBB.com hacked - been offline all day
bull_ish2004
CZ Newbie
bull_ish2004 has been a member for over 19 year's 19 Year Member
Gender: Male
Status: Offline
Joined: Dec 17, 2004
0.00 posts per day
Posts: 2
Points: 699
   
did a little research to protect my site....apparently this guy has been busy
[ Register or login to view links on this board.]
[ Register or login to view links on this board.]

he also attacked xoops cms via awstats
[ Register or login to view links on this board.]



Back to top Reply with quote
#10   re: phpBB.com hacked - been offline all day
fncool
CZ Super Newbie
 Codezwiz Site Donator
fncool has been a member for over 19 year's 19 Year Member
canada.gif
Age: 62
Gender: Male
Status: Offline
Joined: Dec 19, 2004
0.01 posts per day
Posts: 56
Points: 4,786
   
maybe this should be posted in the news section?




_________________
I'm only replying because I want those extra 22.52 points!
Back to top Reply with quote
Display posts from previous:      
Add To: Del.icio.us  Digg  Google  Spurl  Blink  Furl  Y! MyWeb  
<< View previous topic View next topic >>
Post new topicReply to topic

Jump to 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum