[Discussion] Downtime and Server Compromise

Discussion of general topics related to the new version and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Forum rules
Discussion of general topics related to the new release and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Post Reply
idiotnesia
Registered User
Posts: 29
Joined: Thu May 22, 2008 2:46 am

Re: [Discussion] Downtime and Server Compromise

Post by idiotnesia »

Really sad to hear about this problem. :(

Hopefully everything will be back again ....
idiotnesia wuz here
User avatar
Gofer01
Registered User
Posts: 3
Joined: Mon Feb 02, 2009 6:07 am
Location: ALBuquerque, NM. USA
Contact:

Re: [Discussion] Downtime and Server Compromise

Post by Gofer01 »

What kind of database does phpBB forum software uses :?:
Shamisen
Registered User
Posts: 1
Joined: Mon Feb 02, 2009 6:27 am

Re: [Discussion] Downtime and Server Compromise

Post by Shamisen »

So I have it straight in my own mind...
Someone got into the Database and saw not only our logins and passwords, but also knows our Email addresses, If we signed up for further correspondence from PhPBB?
This issue only applies to the PhPBB site, not our individual forums.. and we have no issues with the software we are currently running our boards on, IF we've kept it updated?

Is my understanding of this correct?

Thanks..
Keith W
Registered User
Posts: 10
Joined: Tue Feb 28, 2006 3:56 pm

Re: [Discussion] Downtime and Server Compromise

Post by Keith W »

As has been said there is nothing wrong with the phpbb software that you use for your individual forums
globetrotting
Registered User
Posts: 18
Joined: Fri Jan 06, 2006 9:29 pm

Re: [Discussion] Downtime and Server Compromise

Post by globetrotting »

I'm sorry for you guys, for all the work that has been maliciously put upon you, which also slows down valuable projects of thousands of other people. :(
That's a lot of bad Karma for the originator - I wonder how anybody could like to be responsible for such an unholy mess?
Keep up the good work which empowers so many people to communicate and to help each other!
jdsingle
Registered User
Posts: 1
Joined: Mon Feb 02, 2009 6:59 am

Re: [Discussion] Downtime and Server Compromise

Post by jdsingle »

I'm sure someone has already pm'd you guys this link. This is the guy who is taking credit for the hack. Not sure if it is legit though.

*Thanks, but we are aware of it*
Last edited by ckwalsh on Mon Feb 02, 2009 8:00 am, edited 2 times in total.
Reason: Removed link
User avatar
onehundredandtwo
Registered User
Posts: 33
Joined: Mon Feb 02, 2009 6:55 am

Re: [Discussion] Downtime and Server Compromise

Post by onehundredandtwo »

Shamisen wrote:Someone got into the Database and saw not only our logins and passwords, but also knows our Email addresses, If we signed up for further correspondence from PhPBB?
Not the passwords. Passwords are encrypted by one of the phpBB files and the hacker would have to know the hash key to get in. The hash key is in one of the phpBB files (includes/functions.php I think, not exactly sure) but I'm guessing the hacker only took control over either the filesystem or the database.
Need help preventing spam? Read Preventing spam in phpBB 3.0.6 and above
Mudjosh
Registered User
Posts: 3
Joined: Mon Feb 02, 2009 8:13 am

Re: [Discussion] Downtime and Server Compromise

Post by Mudjosh »

That is crap! I cannot believe that at all.. Wow.. Guys, man.. If I had any money at all, I would donate it to you guys just to make this halfway worthwhile..

You guys work way to hard to be treated like this! :evil:

I'm so sorry!!!!
Chrizathens
Registered User
Posts: 12
Joined: Sun Oct 29, 2006 2:24 am

Re: [Discussion] Downtime and Server Compromise

Post by Chrizathens »

If, by any chance, my host uses phplist in order to have a mailing list, then it appears that I potentially have a problem...
I cannot be sure though, cause I've never used mailing lists...
Anyways, this is really a shame... :(
I hope you guys get the site back online soon...
Keith W
Registered User
Posts: 10
Joined: Tue Feb 28, 2006 3:56 pm

Re: [Discussion] Downtime and Server Compromise

Post by Keith W »

Guys the thing is not to get all in a state over this, your individual forums will be OK, there is no known problem with the current phpBB software.

If you are concerned then change your passwords etc.

Also please try not bother the phpBB staff team with question then have already been covered in this thread, as you can imagine they have a lot of work on there hands right now.

Remember don't get in a state and don't panic as this is what the attacker wants, don't let him/her win

Lets all stand united and give the phpBB team our full support
Post Reply