Quote:
Originally Posted by UncoderMom
But wasnt it them that didnt update a know vulnerable version?
|
The attacker says that they first broke in on January 14th using a local file inclusion vulnerability. PHPlist fixed that vulnerability on January 29th:
http://www.phplist.com/?lid=274
Seriously, there isn't much phpbb.com could have done.
And as people have commented in the blog post, he's not much more than a script kiddie. Suggesting config files be encrypted? What's next? <sarcasm>Maybe he'll suggest everyone use ASP.NET because obviously ASP.NET never got anyone hacked.</sarcasm>