Press about phpBB.com crack

ImageNews from out there about new technologies.

It will be updated when possible.

Press about phpBB.com crack

Postby Juanm on Wednesday February 11th, 2009 08h09:43

Some facts about the PHPList vulnerability and the phpbb.com hack

A few days ago phpbb.com was hacked through a super-globals-overwrite vulnerability in PHPList that was used by an attacker for a local file inclusion exploit. [--cut] From the explanation it seems that the PHP installation on phpbb.com was more or less a default one that was not hardened against attacks at all, but I will get into this later.

First I want to shed some light on the super-globals-overwrite vulnerability in PHPList that was wrongly attributed a local file inclusion vulnerability in so many places (including the PHPList announcement). [...]

------------------------------------

phpBB coughs up names, addresses, passwords

The website for one of the net's more popular bulletin board software packages has been taken offline following a security breach that gave an attacker full access to a database containing names, email, address, and hashed passwords for its entire user base. [...]

------------------------------------

Last phpBB.com temp homepage

Maintenance

We are sorry to report that we have been attacked through a 0-day-exploit in our PHPList installation (responsible for the mailing list about new releases). phpBB.com will remain unavailable while we work to recover. No vulnerabilities have been found in the phpBB software itself.

You can download phpBB here: http://www.ohloh.net/p/phpbb

You can get support at the temporary support forums or on IRC:
chat.freenode.net #phpbb

A more detailed explanation about the incident.

Press Contact: If you need to get in contact with the management, please email phpbb_press (at) marshalrusty (dot) com.

– the phpBB team


------------------------------------

From a topic:
Acyd Burn on Feb 08th, 2009 22:42:31 (UTC+1) wrote:At the moment everything is going quite smooth. Depending on the time we are able to work on it (we all have day jobs too ;)) i predict(!) 1-3 days. It will definitely not be an additional week. :)


As you can see, the prediction was right :D

(Note: all linkages to other site have been r3moved)
Juanm

Phpbb related: looking 4 a MOD? :: phpBB bugtracker :: phpBBsecurity tracker :: phpBB knowledge base

D-Off @ MobileReview wrote:who cares about WAP anymore? :)
Try google and search for content
User avatar
Juanm
Site developer
Site developer
 
Posts: 763
Joined: Thursday March 25th, 2004 21h45:21
Location: Behind YOU



Ad
Bot
 


Similar topics

Crack estivi ... i Gaucci in gabbia
Forum: Sport
Author: Juanm
Replies: 2
Cimmi crack
Forum: Sport
Author: Juanm
Replies: 0

Return to Tech news

Who is online

Users browsing this forum: No registered users and 1 guest

cron

Rate this site