vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Community Lounge (https://vborg.vbsupport.ru/forumdisplay.php?f=13)
-   -   phpBB.com HACKED!! (https://vborg.vbsupport.ru/showthread.php?t=203848)

ChrisChristian 02-01-2009 05:19 PM

phpBB.com HACKED!!
 
Bad News for phpBB users:

So far, the phpbb.com remains offline.

*** Removed link and content of this post. We do not need to link to websites ran by hackers or list passwords of another site. ***

lasto 02-01-2009 05:39 PM

sad news indeed

ChrisChristian 02-01-2009 05:58 PM

It´s very unfortunate. I hope they get everything sorted.

UKBusinessLive 02-01-2009 06:37 PM

Well all i can say is that i hope they sort this out asap, Its a nightmare when something like this happens, it feels like you've been robbed. What was the whole point of this??, Very Sad indeed :(

UncoderMom 02-01-2009 06:42 PM

I hope they get it sorted too.

OMG, is that the hacker posting copies of its user database to rapid share????

Shazz 02-01-2009 06:52 PM

Just be fortunate that you don't have a phpbb forum, this would be good for jelsoft... More potential customers ;)

klaush 02-01-2009 06:53 PM

They used a security hole in phplist.

If anyone use this newsletter tool, here is the fix for this hole:

security update version 2.10.9
29 January 2009

We've released version 2.10.9 that fixes a local file include vulnerability.This vulnerability allows attackers to display the contents of files on the server, which can aid them to gain unauthorised access.

Everyone using any version up to this one is advised to upgrade as soon as possible. Any clients hosted by Tincan have already been patched or upgraded.

If you don't want to upgrade now, you can fix the vulnerability quickly by adding the following line to the top of the index file in the admin directory:

----------

if (isset($_REQUEST['_SERVER'])) { exit; }


http://www.phplist.com/?lid=274

Shelley_c 02-01-2009 06:53 PM

Quote:

Originally Posted by UncoderMom (Post 1731176)
I hope they get it sorted too.

OMG, is that the hacker posting copies of its user database to rapid share????

Looks like it and much more. Shame, people like this are full of beans until they are caught & prosecuted and blubber like little babies. Shame, I'm sure they will be back to business before long a little wiser in the process.

Winterworks 02-01-2009 06:55 PM

Quote:

Originally Posted by UncoderMom (Post 1731176)
I hope they get it sorted too.

OMG, is that the hacker posting copies of its user database to rapid share????

He did, but visit the link now and it's...

Quote:

This file is suspected to contain illegal content and has been blocked. After the file has been blocked for 7 days it will automatically be deleted, if the block is not removed by RapidShare. For this reason, a download of this file is currently not possible.

ChrisChristian 02-01-2009 06:57 PM

Info from AREA51 (phpbb dev forum):

Quote:

http://area51.phpbb.com/phpBB/styles...ost_target.gifby Erisar ? Today 5:27 am
phpBB.com is offline due to a security vulnerability in PHPList, a third party software being used on the site. The phpBB3 software is not responsible and is not compromised in any way. phpBB.com will be offline until the problem can be fixed. Support may continue as usual in the temporary support forum or on IRC (#phpBB on irc.freenode.net). We thank everyone for your patience and understanding. https://vborg.vbsupport.ru/external/2009/02/49.gif

UncoderMom 02-01-2009 07:04 PM

Quote:

Originally Posted by Winterworks (Post 1731193)
He did, but visit the link now and it's...


yeah but not before 100's or even 1000's downloaded the data. :eek:

ChrisChristian 02-01-2009 07:14 PM

Man, it seems they were using plain text passwords... in text files... WOW! :eek:

Winterworks 02-01-2009 07:15 PM

Yeah exactly. That's pretty bad... I hope they find the people that hacked them. Lawsuit? :)

Dean C 02-01-2009 07:56 PM

That was a great read.

KevinL 02-01-2009 09:44 PM

This is really a shame. I used to have a phpbb board.

nexialys 02-01-2009 11:20 PM

the shame is not to be related to phpBB but to the way you can be hacked using another script that is not as secure as your own source of revenues...

most people here would call it one day... "i've been hacked, vBulletin is just crap"... but you see now that it's not the main software that is always the case... a Newletter can do it... and PHPList is a very popular one... the bug came from a human error, not the script itself...

freewilley 02-01-2009 11:56 PM

phpBB is always vulnerable to hackers! many phpBB boards get hacked all the time now they even cant get their hands out of the main terminal! this is a shame to phpBB system they should consider developing a system that is more secure.

harmor19 02-02-2009 01:35 AM

I'm sorry to type in caps...

PHPBB DID NOT GET HACKED DIRECTLY. A VULNERABILITY IN PHPLIST LEAD TO THE HACKING OF PHPBB

UncoderMom 02-02-2009 01:39 AM

But wasnt it them that didnt update a know vulnerable version?

02-02-2009 02:07 AM

Quote:

Originally Posted by ChrisChristian (Post 1731213)
Man, it seems they were using plain text passwords... in text files... WOW! :eek:

Quote:

Originally Posted by Winterworks (Post 1731216)
Yeah exactly. That's pretty bad... I hope they find the people that hacked them. Lawsuit? :)


Have you looked at your own VB config.php file ;)

02-02-2009 04:44 AM

Quote:

Originally Posted by UncoderMom (Post 1731489)
But wasnt it them that didnt update a know vulnerable version?

The attacker says that they first broke in on January 14th using a local file inclusion vulnerability. PHPlist fixed that vulnerability on January 29th:

http://www.phplist.com/?lid=274

Seriously, there isn't much phpbb.com could have done.

And as people have commented in the blog post, he's not much more than a script kiddie. Suggesting config files be encrypted? What's next? <sarcasm>Maybe he'll suggest everyone use ASP.NET because obviously ASP.NET never got anyone hacked.</sarcasm>

02-02-2009 06:37 AM

Thanks guys for being supportive to phpbb.com

I'm a phpbb3 user (Until I can afford an "upgrade") and I am very loyal to them.. They are a great team of people that do not even get paid for what they do (Other then the Bertie Bears)

I'm sure that Vbulletin's software is secure but for all forum owners, now is a good time to start double checking and analyzing your forum. The larger the forum, the more likely of an attack.

Just please be careful..

~<',>< Jason

iAnj 02-02-2009 06:58 AM

Quote:

Originally Posted by Mudjosh (Post 1731637)
Thanks guys for being supportive to phpbb.com

I'm a phpbb3 user (Until I can afford an "upgrade") and I am very loyal to them.. They are a great team of people that do not even get paid for what they do (Other then the Bertie Bears)

I'm sure that Vbulletin's software is secure but for all forum owners, now is a good time to start double checking and analyzing your forum. The larger the forum, the more likely of an attack.

Just please be careful..

~<',>< Jason

Lol close and do a full backup asap :D

GSeybold 02-02-2009 08:56 AM

How often are these hackers caught and prosecuted? Hang em!

Vaupell 02-02-2009 09:49 AM

Quote:

Originally Posted by GSeybold (Post 1731696)
How often are these hackers caught and prosecuted? Hang em!

Rarely done, both cases, some laws usually dont apply across borders
unless your american, then the whole world should apply to their laws
they think, which is odd..

anyway not here to religious/political debate,

just here to gloat.. happy to be using vb. :p

KTBleeding 02-02-2009 11:28 AM

Quote:

Originally Posted by iAnj (Post 1731651)
Lol close and do a full backup asap :D

He claimed to be using phpbb, not phplist. So explain why he needs to panic and do a full backup immediately.. Or did you not read anything other than the title of this thread?

Magnumutz 02-02-2009 11:40 AM

Some simply want to increase their post count, not knowing that posts in this section don't get counted.

02-02-2009 02:25 PM

Quote:

Originally Posted by Magnumutz
Some simply want to increase their post count, not knowing that posts in this section don't get counted.

Exactly.. lol.

I am very satisfied with my phpbb3 forum.. (Though I notice that all high ranking forums just happen to be vbulletin.. not fair you guys.. :D )

But I would still like to upgrade.

But anyway, more on topic..

I still can't believe some of the jerks on the internet.. I mean, I met some doosies in real life but some of these people take the cake.. He should be working for a security site, not hacking into people offering a free software to help others.

They put way too much time working on phpbb to have this happen to them.. :mad:

lasto 02-02-2009 03:44 PM

Quote:

Originally Posted by Magnumutz (Post 1731799)
Some simply want to increase their post count, not knowing that posts in this section don't get counted.

You kidding me - thats its im gonna post in other sections now :)

Quote:

Originally Posted by Mudjosh (Post 1731952)
I still can't believe some of the jerks on the internet.. I mean, I met some doosies in real life but some of these people take the cake.. He should be working for a security site, not hacking into people offering a free software to help others.:

They not good enough - most of them use scripts or code from Boards and just mess till they get a hit.

02-02-2009 04:21 PM

Quote:

Originally Posted by lasto (Post 1732030)
They not good enough - most of them use scripts or code from Boards and just mess till they get a hit.

Correct me if I'm wrong, but isn't this is an English speaking forum? You know, as opposed to a "I'm 2 culz to use proper gramarz" speaking forum?

KTBleeding 02-02-2009 04:35 PM

Quote:

Originally Posted by queenzeal (Post 1732066)
Correct me if I'm wrong, but isn't this is an English speaking forum? You know, as opposed to a "I'm 2 culz to use proper gramarz" speaking forum?

Says the guy who just posted, "isn't this is an English"..

Lighten up and pay attention, vB isn't released only in English speaking countries, there are many many different ethnicity based visitors on here who's native tongue is not the same as yours.

UncoderMom 02-02-2009 04:38 PM

Quote:

Originally Posted by KTBleeding (Post 1732082)
Says the guy who just posted, "isn't this is an English"..

Lighten up and pay attention, vB isn't released only in English speaking countries, there are many many different ethnicity based visitors on here who's native tongue is not the same as yours.

:up:

Sometimes I REALLY wish vb.org had the thanks button! LOL

lasto 02-02-2009 04:45 PM

Quote:

Originally Posted by queenzeal (Post 1732066)
Correct me if I'm wrong, but isn't this is an English speaking forum? You know, as opposed to a "I'm 2 culz to use proper gramarz" speaking forum?

why quote my post - as i do speak in english :)

02-02-2009 05:01 PM

Quote:

Originally Posted by lasto (Post 1732089)
why quote my post - as i do speak in english :)

The comment was intended to be somewhat sarcastic. Of course it's in English, just as "I'm 2 culz to use proper gramarz" is in English. The point is that it's just not very good English. Let me quote your post again:

Quote:

They not good enough - most of them use scripts or code from Boards and just mess till they get a hit.
Try They're. And what is the pronoun 'them' supposed to be referring to? And what does "just mess till they get a hit" mean?

Actually, when I first read that, I thought you were talking about phpBB users - that you were saying "most of them use scripts or code from Boards and just mess till they get a hit". I didn't have a clue what that meant and assumed that it was just belligerence towards phpBB on your part.

Rereading it, though, I think I may have misinterpreted it the first time. It looks what like what you, in point of fact, were referring to weren't phpBB users, but rather, script kiddies of the kind that conducted the attack. If that's correct, then I apologize - my condescension was due to my thinking you were being condescending to the victims - not to the attacker.

lasto 02-02-2009 05:10 PM

Quote:

Originally Posted by queenzeal (Post 1732115)
The comment was intended to be somewhat sarcastic. Of course it's in English, just as "I'm 2 culz to use proper gramarz" is in English. The point is that it's just not very good English. Let me quote your post again:


Try They're. And what is the pronoun 'them' supposed to be referring to? And what does "just mess till they get a hit" mean?

Actually, when I first read that, I thought you were talking about phpBB users - that you were saying "most of them use scripts or code from Boards and just mess till they get a hit". I didn't have a clue what that meant and assumed that it was just belligerence towards phpBB on your part.

Rereading it, though, I think I may have misinterpreted it the first time. It looks what like what you, in point of fact, were referring to weren't phpBB users, but rather, script kiddies of the kind that conducted the attack. If that's correct, then I apologize - my condescension was due to my thinking you were being condescending to the victims - not to the attacker.

I was referrin to the script kiddies who did the hacking not the actual PhpBB board.
I speak better english than i type it - thats for sure and thats all that matters :)

02-02-2009 05:25 PM

Quote:

Originally Posted by lasto (Post 1732126)
I was referrin to the script kiddies who did the hacking not the actual PhpBB board.
I speak better english than i type it - thats for sure and thats all that matters :)

Well, like I said, I apologize :)

Magnumutz 02-02-2009 05:40 PM

I think it's 1337 chat like language is what you're worried about queenzeal.

If someone's grammar isn't too good, it doesn't mean that they're 1337 script kiddies wannabes, but maybe not from an English speaking country, like myself.
If they are, then they should go to school more often.

Marco van Herwaarden 02-03-2009 06:16 AM

We do require posts are in english, we do not require that it is in perfect english with correct grammar. For most of our users English is not their first language.

TruthElixirX 02-03-2009 06:47 AM

Quote:

Originally Posted by Marco van Herwaarden (Post 1732769)
We do require posts are in english, we do not require that it is in perfect english with correct grammar. For most of our users English is not their first language.

Why can't we all speak 'merican? This is are country.

iAnj 02-03-2009 07:03 AM

Quote:

Originally Posted by KTBleeding (Post 1731782)
He claimed to be using phpbb, not phplist. So explain why he needs to panic and do a full backup immediately.. Or did you not read anything other than the title of this thread?

Or misread?
Don't assume i posted that for no reason and start trying to flame me.
Try being on topic


All times are GMT. The time now is 04:59 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01282 seconds
  • Memory Usage 1,838KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (24)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete