phpBB hacker warning

Talk freely about the scene, the world of remixing, or anything off-topic unsuitable for the "Fun Forum".
Post Reply
User avatar
Matrix
Honorary Geek
Honorary Geek
Posts: 2014
Joined: 25/07/2003 - 18:27
Location: Uk
Contact:

phpBB hacker warning

Post by Matrix »

Back up your files, this was posted on the yabb boards today:

http://www.boardmod.org/yabb/YaBB.pl?bo ... 1103713201
Well everyone, here's yet another reason to be glad you're using YaBB instead of phpBB. A hacker has been searching for sites that contain the words "Powered by phpBB", and hacking into the sites using some sort of exploit that was included in certain versions of phpBB. They hacked the main site on who's server my site resides. Luckily, it appears that the hacker isn't extremely malicious, they are simply a jerk. All they did was add three files to our server, and didn't actually damage any of the site's content. They added index.htm, index.html and index.php, which all contained simply "IR4DEX OWNZ YOU". Since we currently use SSI, our index file was called index.shtml anyway, so all I had to do was delete the three new files, and everything went back to normal.
User avatar
merman
Forum Fish
Forum Fish
Posts: 1938
Joined: 24/01/2003 - 10:42
Location: Skegness, UK
Contact:

Post by merman »

This happened to the ZZAP! forum recently and they are trying to get a backup restored...
--Anyone want to remix my SIDs?--
merman1974 on Twitter, Steam and Xbox Live
User avatar
C64GLeN
Forum Admin
Forum Admin
Posts: 871
Joined: 26/11/2002 - 22:27
Location: Middlesbrough
Contact:

Post by C64GLeN »

Code: Select all

Powered by phpBB 2.0.3
I believe this version is at risk
User avatar
C64GLeN
Forum Admin
Forum Admin
Posts: 871
Joined: 26/11/2002 - 22:27
Location: Middlesbrough
Contact:

Post by C64GLeN »

User avatar
LMan
R64 Founder
R64 Founder
Posts: 4046
Joined: 21/11/2002 - 12:44
Contact:

Post by LMan »

Tom Detert told me about the exploit a few weeks ago, I've patched the part of code back then (which in return caused the "highlight" bug). :)
User avatar
Matrix
Honorary Geek
Honorary Geek
Posts: 2014
Joined: 25/07/2003 - 18:27
Location: Uk
Contact:

Post by Matrix »

ok, well, just a thought, long as ur ready i guess.....
tas
R64 Founder
R64 Founder
Posts: 2346
Joined: 27/11/2002 - 15:02
Location: Doncaster

Post by tas »

This happened to a footy forum i belong to aswell. Caused a few headaches but thats all.
User avatar
LMan
R64 Founder
R64 Founder
Posts: 4046
Joined: 21/11/2002 - 12:44
Contact:

Post by LMan »

Matrix wrote:ok, well, just a thought, long as ur ready i guess.....
Don't get me wrong, I appreciate any such reports/warnings. Thanks m8ey :)
User avatar
LMan
R64 Founder
R64 Founder
Posts: 4046
Joined: 21/11/2002 - 12:44
Contact:

Post by LMan »

I've upgraded phpbb to 2.0.11, just to make sure. :)
Post Reply