Earlier quoted context omitted.
I'm pretty sure sendmail still wears that crown.
Unpatched Exim was giving it a pretty good run for a while.
Several of the web servers powering phpBB.com were compromised
21–27 of 27 posts
Re: Several of the web servers powering phpBB.com were compromised
#22Earlier quoted context omitted.
Unpatched Exim was giving it a pretty good run for a while.
Well well well. A sysadmin friend swears by exim as the safest mailserver software ever. I will enjoy ribbing him at the pub on Friday :)
The 9.3 one was world-destroying, nuke-from-orbit type bad.
"execute arbitrary code via an SMTP session" is not what you want to hear in a bug report.
Re: Several of the web servers powering phpBB.com were compromised
#23Earlier quoted context omitted.
Well well well. A sysadmin friend swears by exim as the safest mailserver software ever. I will enjoy ribbing him at the pub on Friday :)
Not a bad track record, but not flawless: http://www.cvedetails.com/vulnerability-list/vendor_id-10919... The 9.3 one was world-destroying, nuke-from-orbit type bad. "execute arbitrary code via an SMTP session" is not what you want to hear in a bug report.
I'm still impressed by qmail's track record: http://www.cvedetails.com/vulnerability-list/vendor_id-86/pr...
Re: Several of the web servers powering phpBB.com were compromised
#24Earlier quoted context omitted.
Not a bad track record, but not flawless: http://www.cvedetails.com/vulnerability-list/vendor_id-10919... The 9.3 one was world-destroying, nuke-from-orbit type bad. "execute arbitrary code via an SMTP session" is not what you want to hear in a bug report.
Yikes! I'm still impressed by qmail's track record: http://www.cvedetails.com/vulnerability-list/vendor_id-86/pr...
Re: Several of the web servers powering phpBB.com were compromised
#25Earlier quoted context omitted.
It is the one site you know the users will come to. I would do the new web server at old address. Hacked machines should not be put back in service.
I think what you want is the "Full Disclosure" mailing list: http://nmap.org/mailman/listinfo/fulldisclosure
Re: Several of the web servers powering phpBB.com were compromised
#26Earlier quoted context omitted.
Not a bad track record, but not flawless: http://www.cvedetails.com/vulnerability-list/vendor_id-10919... The 9.3 one was world-destroying, nuke-from-orbit type bad. "execute arbitrary code via an SMTP session" is not what you want to hear in a bug report.
Yikes! I'm still impressed by qmail's track record: http://www.cvedetails.com/vulnerability-list/vendor_id-86/pr...
Sadly qmail is a lesson of how you can be correct and completely wrong at the same time.
Imagine a completely secure operating system that only runs on 32-bit systems. Could you actually advocate using it in a serious production capacity?
Re: Several of the web servers powering phpBB.com were compromised
#27Other than the obvious, some things worry me. > We have confirmed that initial entry was made via a team member's compromised login details and not as the result of a vulnerability in the phpBB software. > The attackers were able to obtain access to the phpBB.com and area51 databases, meaning that user information, including hashed salted passwords, was compromised. Additionally, all logins on area51 between Dec. 12t…
I'm would assume the same thing was done on the phpbb.com servers.