Web Develop Forum: phpBB Project Website Hacked - Web Develop Forum

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

phpBB Project Website Hacked

#1 User is offline   Sam Granger Icon

  • Administrator
  • PipPipPip
  • Group: Root Admin
  • Posts: 431
  • Joined: 22-October 08
  • Gender:Male

Posted 09 February 2009 - 10:55 PM

Usernames, e-mails and passwords of hundreds of thousands of accounts leaked on the Internet

The project website of one of the most popular open source bulletin boards, phpBB, has suffered a major security breach that has resulted in the exposure of 400,000 e-mail addresses. A hacker has obtained access to both the forum and mailing list databases by exploiting an unpatched vulnerability in the PHPlist newsletter software.

http://news.softpedi...ed-103772.shtml

They are talking about phpBB website but its about the mailing list, so if you are running phpbb watch out for some upgrades.
0

#2 User is offline   Diffraction Icon

  • Advanced Member
  • Icon
  • Group: Moderator
  • Posts: 279
  • Joined: 26-January 09
  • Gender:Male
  • Location:USA
  • Interests:Web Development, Reading, Writing, Computers in general...
  • Your specialities (detailed)::HTML 5
    CSS 3
    jQuery

Posted 09 February 2009 - 11:22 PM

Yeah, I heard about this earlier.

The hacker apparently started a blog here:

http://hackedphpbb.b...ace-holder.html

Stupid script kiddie angry.gif
Want to report something to a moderator? Use the 'report' button located on every post.
0

#3 User is offline   styyls Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 22
  • Joined: 05-February 09
  • Location:Orlando, FL

Posted 09 February 2009 - 11:56 PM

Who gains from this? Who loses from this? Those are the two biggest questions and the answers are obvious. This kid has no sense.

I feel bad for him when he goes to prison, with people who've murdered. I'm sure they're going to get a kick out of his crime, but he won't be laughing then.
My name is Chet. Please refer to me as such. =)
0

#4 User is offline   Jamie Icon

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 79
  • Joined: 18-January 09
  • Gender:Male

Posted 10 February 2009 - 12:10 AM

He wouldn't last here for 10 minutes, he'd get a warning from me every two minutes what with that poor grammar of his. tongue.gif
<a href="http://www.learntodesign.net" target="_blank">Learn to design</a> - Photoshop and other webdevelopment tutorials.
<a href="http://www.lucypinderwallpapers.com" target="_blank">Lucy Pinder Wallpapers</a> - Lucy Pinder Gallery
0

#5 User is offline   Salathe Icon

  • Advanced Member
  • Icon
  • Group: Moderator
  • Posts: 138
  • Joined: 15-January 09
  • Gender:Male
  • Location:Scotland

Posted 10 February 2009 - 12:20 AM

It just goes to show how using software written without best practices can open up a can of worms. At least going public will raise awareness of this particular issue.
salathe@php.net
0

#6 User is offline   Gaz Icon

  • Advanced Member
  • Icon
  • Group: Administrators
  • Posts: 178
  • Joined: 15-January 09
  • Gender:Male
  • Location:UK

Posted 10 February 2009 - 02:28 PM

Can't say I'm surprised: hasn't phpBB always been thought of as hacker-prone?
0

#7 User is offline   Diffraction Icon

  • Advanced Member
  • Icon
  • Group: Moderator
  • Posts: 279
  • Joined: 26-January 09
  • Gender:Male
  • Location:USA
  • Interests:Web Development, Reading, Writing, Computers in general...
  • Your specialities (detailed)::HTML 5
    CSS 3
    jQuery

Posted 10 February 2009 - 06:56 PM

It was NOT PHPBB that had the vulnerability, it was PHPList a mailing list software they were using.
Want to report something to a moderator? Use the 'report' button located on every post.
0

#8 User is offline   Will Roberts Icon

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 64
  • Joined: 23-October 08
  • Gender:Male
  • Location:Buckley, North Wales

Posted 11 February 2009 - 01:41 PM

Clever kid but annoying to say the least.
My Portfolio: <a href="http://www.imagelimited.co.uk" target="_blank">I.M.A.G.E</a>
Submit Your Site: <a href="http://www.keepittidy.co.uk" target="_blank">K.I.T</a>
CSS & XHTML Tutorials: <a href="http://www.fatbasturd.co.uk" target="_blank">FatBasturd</a>
SEO Services: <a href="http://www.firstplaceingoogle.com" target="_blank">Firstplaceingoogle.com</a>
0

#9 User is offline   thinglie Icon

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 41
  • Joined: 25-October 08
  • Gender:Male
  • Location:House

Posted 11 February 2009 - 07:05 PM

phpBB 3 is very secure compared with phpBB2. I would actually use that to set up a web forum instead of writing my own now. It's still got a pooey admin compared to IPB's, but you shouldn't have to use an Admin CP too often anyway.
<a href="http://www.gnu.org/" target="_blank"><img src="http://www.gnu.org/graphics/gnubanner-2.png" border="0" class="linked-sig-image" /></a>
<a href="http://www.fsf.org'" target="_blank">Free Software Foundation</a>
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users