Several of the web servers powering phpBB.com were compromised
1–10 of 27 posts
Re: Several of the web servers powering phpBB.com were compromised
#2Re: Several of the web servers powering phpBB.com were compromised
#3> We have confirmed that initial entry was made via a team member's compromised login details and not as the result of a vulnerability in the phpBB software.
> The attackers were able to obtain access to the phpBB.com and area51 databases, meaning that user information, including hashed salted passwords, was compromised. Additionally, all logins on area51 between Dec. 12th and Dec. 15th were logged in plaintext. While the hashing algorithm utilized in phpBB will make it difficult to obtain those passwords, you should not take any chances.
A bit of clarification should be given. The staff's login information was stolen, allowing someone to get a dump of the database containing user info. What kind of login information was stolen? Is this an shell account, was an SSH key stolen, was this an admin panel account?
Secondly, "all logins [...] were logged in plaintext". Does this mean the username and password were logged, the password hashes and sessions? What actual information was plaintext to the user?
It's great that groups are willing to own up to these kinds of events, but without specific information, it's hard to understand how broad a compromise we're talking.
Re: Several of the web servers powering phpBB.com were compromised
#4Is it just me, or does anyone wish that compromise disclosures should be hosted somewhere other than the site that has been compromised? What if there's a persistent threat and their webserver is still hosed, injecting 0days into responses? Not that it's happening here - I still clicked it - but I was hesitant.
Re: Several of the web servers powering phpBB.com were compromised
#5Is it just me, or does anyone wish that compromise disclosures should be hosted somewhere other than the site that has been compromised? What if there's a persistent threat and their webserver is still hosed, injecting 0days into responses? Not that it's happening here - I still clicked it - but I was hesitant.
Re: Several of the web servers powering phpBB.com were compromised
#6Re: Several of the web servers powering phpBB.com were compromised
#7Is it just me, or does anyone wish that compromise disclosures should be hosted somewhere other than the site that has been compromised? What if there's a persistent threat and their webserver is still hosed, injecting 0days into responses? Not that it's happening here - I still clicked it - but I was hesitant.
It is the one site you know the users will come to. I would do the new web server at old address. Hacked machines should not be put back in service.
http://nmap.org/mailman/listinfo/fulldisclosureRe: Several of the web servers powering phpBB.com were compromised
#8Is it just me, or does anyone wish that compromise disclosures should be hosted somewhere other than the site that has been compromised? What if there's a persistent threat and their webserver is still hosed, injecting 0days into responses? Not that it's happening here - I still clicked it - but I was hesitant.
If a browser 0day really did apply to my up-to-date version of firefox and really was a problem, well, I'd feel pretty screwed.
Re: Several of the web servers powering phpBB.com were compromised
#9PhpBB, the gift that keeps on giving. Isn't phpBB one of the most compromised pieces of software installed?
Re: Several of the web servers powering phpBB.com were compromised
#10PhpBB, the gift that keeps on giving. Isn't phpBB one of the most compromised pieces of software installed?