vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Community Lounge (https://vborg.vbsupport.ru/forumdisplay.php?f=13)
-   -   phpBB.com HACKED!! (https://vborg.vbsupport.ru/showthread.php?t=203848)

ChrisChristian 02-01-2009 05:19 PM

phpBB.com HACKED!!
 
Bad News for phpBB users:

So far, the phpbb.com remains offline.

*** Removed link and content of this post. We do not need to link to websites ran by hackers or list passwords of another site. ***

lasto 02-01-2009 05:39 PM

sad news indeed

ChrisChristian 02-01-2009 05:58 PM

It´s very unfortunate. I hope they get everything sorted.

UKBusinessLive 02-01-2009 06:37 PM

Well all i can say is that i hope they sort this out asap, Its a nightmare when something like this happens, it feels like you've been robbed. What was the whole point of this??, Very Sad indeed :(

UncoderMom 02-01-2009 06:42 PM

I hope they get it sorted too.

OMG, is that the hacker posting copies of its user database to rapid share????

Shazz 02-01-2009 06:52 PM

Just be fortunate that you don't have a phpbb forum, this would be good for jelsoft... More potential customers ;)

klaush 02-01-2009 06:53 PM

They used a security hole in phplist.

If anyone use this newsletter tool, here is the fix for this hole:

security update version 2.10.9
29 January 2009

We've released version 2.10.9 that fixes a local file include vulnerability.This vulnerability allows attackers to display the contents of files on the server, which can aid them to gain unauthorised access.

Everyone using any version up to this one is advised to upgrade as soon as possible. Any clients hosted by Tincan have already been patched or upgraded.

If you don't want to upgrade now, you can fix the vulnerability quickly by adding the following line to the top of the index file in the admin directory:

----------

if (isset($_REQUEST['_SERVER'])) { exit; }


http://www.phplist.com/?lid=274

Shelley_c 02-01-2009 06:53 PM

Quote:

Originally Posted by UncoderMom (Post 1731176)
I hope they get it sorted too.

OMG, is that the hacker posting copies of its user database to rapid share????

Looks like it and much more. Shame, people like this are full of beans until they are caught & prosecuted and blubber like little babies. Shame, I'm sure they will be back to business before long a little wiser in the process.

Winterworks 02-01-2009 06:55 PM

Quote:

Originally Posted by UncoderMom (Post 1731176)
I hope they get it sorted too.

OMG, is that the hacker posting copies of its user database to rapid share????

He did, but visit the link now and it's...

Quote:

This file is suspected to contain illegal content and has been blocked. After the file has been blocked for 7 days it will automatically be deleted, if the block is not removed by RapidShare. For this reason, a download of this file is currently not possible.

ChrisChristian 02-01-2009 06:57 PM

Info from AREA51 (phpbb dev forum):

Quote:

http://area51.phpbb.com/phpBB/styles...ost_target.gifby Erisar ? Today 5:27 am
phpBB.com is offline due to a security vulnerability in PHPList, a third party software being used on the site. The phpBB3 software is not responsible and is not compromised in any way. phpBB.com will be offline until the problem can be fixed. Support may continue as usual in the temporary support forum or on IRC (#phpBB on irc.freenode.net). We thank everyone for your patience and understanding. https://vborg.vbsupport.ru/external/2009/02/49.gif


All times are GMT. The time now is 07:52 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01164 seconds
  • Memory Usage 1,738KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (4)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete