Really sad to hear about this problem.
Hopefully everything will be back again ....
[Discussion] Downtime and Server Compromise
Forum rules
Discussion of general topics related to the new release and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
Discussion of general topics related to the new release and its place in the world. Don't discuss new features, report bugs, ask for support, et cetera. Don't use this to spam for other boards or attack those boards!
-
- Registered User
- Posts: 29
- Joined: Thu May 22, 2008 2:46 am
Re: [Discussion] Downtime and Server Compromise
idiotnesia wuz here
- Gofer01
- Registered User
- Posts: 3
- Joined: Mon Feb 02, 2009 6:07 am
- Location: ALBuquerque, NM. USA
- Contact:
Re: [Discussion] Downtime and Server Compromise
What kind of database does phpBB forum software uses
Re: [Discussion] Downtime and Server Compromise
So I have it straight in my own mind...
Someone got into the Database and saw not only our logins and passwords, but also knows our Email addresses, If we signed up for further correspondence from PhPBB?
This issue only applies to the PhPBB site, not our individual forums.. and we have no issues with the software we are currently running our boards on, IF we've kept it updated?
Is my understanding of this correct?
Thanks..
Someone got into the Database and saw not only our logins and passwords, but also knows our Email addresses, If we signed up for further correspondence from PhPBB?
This issue only applies to the PhPBB site, not our individual forums.. and we have no issues with the software we are currently running our boards on, IF we've kept it updated?
Is my understanding of this correct?
Thanks..
Re: [Discussion] Downtime and Server Compromise
As has been said there is nothing wrong with the phpbb software that you use for your individual forums
-
- Registered User
- Posts: 19
- Joined: Fri Jan 06, 2006 9:29 pm
Re: [Discussion] Downtime and Server Compromise
I'm sorry for you guys, for all the work that has been maliciously put upon you, which also slows down valuable projects of thousands of other people.
That's a lot of bad Karma for the originator - I wonder how anybody could like to be responsible for such an unholy mess?
Keep up the good work which empowers so many people to communicate and to help each other!
That's a lot of bad Karma for the originator - I wonder how anybody could like to be responsible for such an unholy mess?
Keep up the good work which empowers so many people to communicate and to help each other!
Re: [Discussion] Downtime and Server Compromise
I'm sure someone has already pm'd you guys this link. This is the guy who is taking credit for the hack. Not sure if it is legit though.
*Thanks, but we are aware of it*
*Thanks, but we are aware of it*
Last edited by ckwalsh on Mon Feb 02, 2009 8:00 am, edited 2 times in total.
Reason: Removed link
Reason: Removed link
- onehundredandtwo
- Registered User
- Posts: 33
- Joined: Mon Feb 02, 2009 6:55 am
Re: [Discussion] Downtime and Server Compromise
Not the passwords. Passwords are encrypted by one of the phpBB files and the hacker would have to know the hash key to get in. The hash key is in one of the phpBB files (includes/functions.php I think, not exactly sure) but I'm guessing the hacker only took control over either the filesystem or the database.Shamisen wrote:Someone got into the Database and saw not only our logins and passwords, but also knows our Email addresses, If we signed up for further correspondence from PhPBB?
Need help preventing spam? Read Preventing spam in phpBB 3.0.6 and above
Re: [Discussion] Downtime and Server Compromise
That is crap! I cannot believe that at all.. Wow.. Guys, man.. If I had any money at all, I would donate it to you guys just to make this halfway worthwhile..
You guys work way to hard to be treated like this!
I'm so sorry!!!!
You guys work way to hard to be treated like this!
I'm so sorry!!!!
-
- Registered User
- Posts: 12
- Joined: Sun Oct 29, 2006 2:24 am
Re: [Discussion] Downtime and Server Compromise
If, by any chance, my host uses phplist in order to have a mailing list, then it appears that I potentially have a problem...
I cannot be sure though, cause I've never used mailing lists...
Anyways, this is really a shame...
I hope you guys get the site back online soon...
I cannot be sure though, cause I've never used mailing lists...
Anyways, this is really a shame...
I hope you guys get the site back online soon...
Re: [Discussion] Downtime and Server Compromise
Guys the thing is not to get all in a state over this, your individual forums will be OK, there is no known problem with the current phpBB software.
If you are concerned then change your passwords etc.
Also please try not bother the phpBB staff team with question then have already been covered in this thread, as you can imagine they have a lot of work on there hands right now.
Remember don't get in a state and don't panic as this is what the attacker wants, don't let him/her win
Lets all stand united and give the phpBB team our full support
If you are concerned then change your passwords etc.
Also please try not bother the phpBB staff team with question then have already been covered in this thread, as you can imagine they have a lot of work on there hands right now.
Remember don't get in a state and don't panic as this is what the attacker wants, don't let him/her win
Lets all stand united and give the phpBB team our full support