Code Newbie
News     Forums     Search     Members     Sign Up    

My Code Newbie
Username

Password

Articles/Snippets
ASP Classic
ASP.NET
C
C#
C++
HTML / CSS
Java
Javascript
Linux / BSD
Perl
PHP
Python
Ruby
SQL
VB 6
VB.NET

C.N. Friends
  Planet Rome

Link to Us!
Code Newbie
  Code Newbie
    forums

Go Back   Code Forums > Code Newbie > Lounge

Reply
 
LinkBack Thread Tools Display Modes
Old 12-07-2004, 05:16 AM   #1 (permalink)
sde
Moderator
 
sde's Avatar
 
Join Date: May 2002
Location: us.ca
Posts: 4,505
sde is on a distinguished road
another community hacked ...

another community i visit was hacked last night, and he's only suspect to some phpbb exploit to root the server.

anyone aware of a phpbb exploit?
__________________
Mike
sde is offline   Reply With Quote
Old 12-08-2004, 09:21 AM   #2 (permalink)
Admin
$_['Your_Mom'];
 
Admin's Avatar
 
Join Date: May 2002
Location: Santee
Posts: 627
Admin is on a distinguished road
rooted!?!?!??? wth!~? from phpbb??? whoa. i would imagine that would take multiple exploits to get root.

i haven't heard anythign about this, but i dont really follow phpbb...
__________________


Urban Clothing
Admin is offline   Reply With Quote
Old 12-08-2004, 07:53 PM   #3 (permalink)
idx
Senior Grasshopper
 
idx's Avatar
 
Join Date: Jun 2003
Location: FL
Posts: 317
idx is on a distinguished road
Yeah. Seems a bit of a stretch unless he's really ruled out everything else.

-r
idx is offline   Reply With Quote
Old 12-11-2004, 08:07 AM   #4 (permalink)
Admin
$_['Your_Mom'];
 
Admin's Avatar
 
Join Date: May 2002
Location: Santee
Posts: 627
Admin is on a distinguished road
something is going on....

http://www.phpbb.com/phpBB/viewtopic.php?t=240513
__________________


Urban Clothing
Admin is offline   Reply With Quote
Old 12-18-2004, 06:45 AM   #5 (permalink)
idx
Senior Grasshopper
 
idx's Avatar
 
Join Date: Jun 2003
Location: FL
Posts: 317
idx is on a distinguished road
http://www.hardened-php.net/advisories/012004.txt

Hm. Guess some PHP issues (unserialize) did cause problems with phpbb and several others..

-r
idx is offline   Reply With Quote
Old 12-21-2004, 08:57 AM   #6 (permalink)
sde
Moderator
 
sde's Avatar
 
Join Date: May 2002
Location: us.ca
Posts: 4,505
sde is on a distinguished road
check this out: http://mvnation.com/phpBB/

lol .. they are lucky the guy isn't that big of a jerk.
__________________
Mike
sde is offline   Reply With Quote
Old 12-21-2004, 02:00 PM   #7 (permalink)
Admin
$_['Your_Mom'];
 
Admin's Avatar
 
Join Date: May 2002
Location: Santee
Posts: 627
Admin is on a distinguished road
lolz
__________________


Urban Clothing
Admin is offline   Reply With Quote
Old 12-21-2004, 02:29 PM   #8 (permalink)
Belisarius
Java fanboy
 
Belisarius's Avatar
 
Join Date: Aug 2003
Posts: 1,166
Belisarius is on a distinguished road
Hope you've updated. I know you're not running phpBB here, but I don't think it would take much to alter it to go after vBulletin Board.
__________________
GitS
Belisarius is offline   Reply With Quote
Old 12-22-2004, 07:40 AM   #9 (permalink)
sde
Moderator
 
sde's Avatar
 
Join Date: May 2002
Location: us.ca
Posts: 4,505
sde is on a distinguished road
we are on the latest version of vbulletin. if vb was vulnerable to this, i think they would have released a patch right?
__________________
Mike
sde is offline   Reply With Quote
Old 12-22-2004, 07:46 AM   #10 (permalink)
Belisarius
Java fanboy
 
Belisarius's Avatar
 
Join Date: Aug 2003
Posts: 1,166
Belisarius is on a distinguished road
The problem is that while it targets phpBB, the exploit used is the PHP exploit. They're targeting phpBB, but vB is just as vulernable, I think.

It's sort of like your neighbor's house is broken into via a shattered window; your windows aren't any more secure, it's just that they didn't break into your house.
__________________
GitS
Belisarius is offline   Reply With Quote
Old 12-22-2004, 08:21 AM   #11 (permalink)
Admin
$_['Your_Mom'];
 
Admin's Avatar
 
Join Date: May 2002
Location: Santee
Posts: 627
Admin is on a distinguished road
PHP should be upgraded.
__________________


Urban Clothing
Admin is offline   Reply With Quote
Old 12-22-2004, 08:48 AM   #12 (permalink)
sde
Moderator
 
sde's Avatar
 
Join Date: May 2002
Location: us.ca
Posts: 4,505
sde is on a distinguished road
everything is re-compiling now. we'll be on 4.3.10 in a few minutes. thanks for the links B
__________________
Mike
sde is offline   Reply With Quote
Old 12-22-2004, 12:11 PM   #13 (permalink)
sde
Moderator
 
sde's Avatar
 
Join Date: May 2002
Location: us.ca
Posts: 4,505
sde is on a distinguished road
http://www.securityfocus.com/archive...3/2004-12-19/0

lots of details.
__________________
Mike
sde is offline   Reply With Quote
Old 12-22-2004, 12:13 PM   #14 (permalink)
sde
Moderator
 
sde's Avatar
 
Join Date: May 2002
Location: us.ca
Posts: 4,505
sde is on a distinguished road
so i would assume that the most likely culprit would be the upload exploit. what would someone upload to a higher directory that would compromise a system?
__________________
Mike
sde is offline   Reply With Quote
Old 12-22-2004, 12:42 PM   #15 (permalink)
Belisarius
Java fanboy
 
Belisarius's Avatar
 
Join Date: Aug 2003
Posts: 1,166
Belisarius is on a distinguished road
Hmmm, that's the only site that says only Windows is vulnerable. Has anyone verified that?
__________________
GitS
Belisarius is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Who hacked the voting system? The teacher sde Code Newbie News 0 05-03-2004 06:29 AM
SEO: #10 - MSN Search - Programmer Community sde Lounge 0 02-20-2004 07:45 AM


All times are GMT -8. The time now is 08:28 PM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC8





Copyright © 2000-2008, Milano Interactive
Web Hosting provided by Portal 360 Web Hosting