Live data from Hacker News

Several of the web servers powering phpBB.com were compromised

phpbb.com

21–27 of 27 posts

Re: Several of the web servers powering phpBB.com were compromised

#21

Earlier quoted context omitted.

I'm pretty sure sendmail still wears that crown.

Unpatched Exim was giving it a pretty good run for a while.

Well well well. A sysadmin friend swears by exim as the safest mailserver software ever. I will enjoy ribbing him at the pub on Friday :)

Re: Several of the web servers powering phpBB.com were compromised

#22
post #21

Earlier quoted context omitted.

Unpatched Exim was giving it a pretty good run for a while.

Well well well. A sysadmin friend swears by exim as the safest mailserver software ever. I will enjoy ribbing him at the pub on Friday :)

Not a bad track record, but not flawless: http://www.cvedetails.com/vulnerability-list/vendor_id-10919...

The 9.3 one was world-destroying, nuke-from-orbit type bad.

"execute arbitrary code via an SMTP session" is not what you want to hear in a bug report.

Re: Several of the web servers powering phpBB.com were compromised

#23
post #21

Earlier quoted context omitted.

Well well well. A sysadmin friend swears by exim as the safest mailserver software ever. I will enjoy ribbing him at the pub on Friday :)

Not a bad track record, but not flawless: http://www.cvedetails.com/vulnerability-list/vendor_id-10919... The 9.3 one was world-destroying, nuke-from-orbit type bad. "execute arbitrary code via an SMTP session" is not what you want to hear in a bug report.

Yikes!

I'm still impressed by qmail's track record: http://www.cvedetails.com/vulnerability-list/vendor_id-86/pr...

Re: Several of the web servers powering phpBB.com were compromised

#24
post #23

Earlier quoted context omitted.

Not a bad track record, but not flawless: http://www.cvedetails.com/vulnerability-list/vendor_id-10919... The 9.3 one was world-destroying, nuke-from-orbit type bad. "execute arbitrary code via an SMTP session" is not what you want to hear in a bug report.

Yikes! I'm still impressed by qmail's track record: http://www.cvedetails.com/vulnerability-list/vendor_id-86/pr...

Just wait. Evidence suggests it is impossible to send mail without also providing remote code execution as a service.

Re: Several of the web servers powering phpBB.com were compromised

#25

Earlier quoted context omitted.

It is the one site you know the users will come to. I would do the new web server at old address. Hacked machines should not be put back in service.

I think what you want is the "Full Disclosure" mailing list: http://nmap.org/mailman/listinfo/fulldisclosure

I'm pretty sure the affected people will visit the original site, and I'm not sure they will visit the site you mention.

Re: Several of the web servers powering phpBB.com were compromised

#26
post #23

Earlier quoted context omitted.

Not a bad track record, but not flawless: http://www.cvedetails.com/vulnerability-list/vendor_id-10919... The 9.3 one was world-destroying, nuke-from-orbit type bad. "execute arbitrary code via an SMTP session" is not what you want to hear in a bug report.

Yikes! I'm still impressed by qmail's track record: http://www.cvedetails.com/vulnerability-list/vendor_id-86/pr...

As good as qmail is, the official release is so far behind the times it's ridiculous. The unofficial patches, made unofficial by a stubborn refusal on the part of the author to merge them in, have fixed most of these issues, but then what's the point of using qmail if you have to use the untrusted version?

Sadly qmail is a lesson of how you can be correct and completely wrong at the same time.

Imagine a completely secure operating system that only runs on 32-bit systems. Could you actually advocate using it in a serious production capacity?

Re: Several of the web servers powering phpBB.com were compromised

#27
post #3

Other than the obvious, some things worry me. > We have confirmed that initial entry was made via a team member's compromised login details and not as the result of a vulnerability in the phpBB software. > The attackers were able to obtain access to the phpBB.com and area51 databases, meaning that user information, including hashed salted passwords, was compromised. Additionally, all logins on area51 between Dec. 12t…

Here is an email I received from phpbbhelp.org: > Hello everyone, > > On September 9th, an attacker was able to gain unauthorized access to the server hosting phpbbhelp.org. This remained unnoticed until late yesterday. The individual (might be individuals) responsible is the same one taking credit for the Tapatalk, phpBB.com, and Ars Technica breaches. > > A keylogger was added to the login page, and if your username is on the following list, the plaintext password you used on phpbbhelp.org is likely in their hands. > List: [removed] > We have to assume that the database was likewise dumped and that everyone's email addresses and hashed passwords are likewise in the wild. > > Please change any password that you may have used on phpbbhelp.org since September. > > If I have any further information, I will provide it. USF will remain offline until after we have restored phpBB.com and I have some time to go through it. > > > > - Yuriy Rusko

I'm would assume the same thing was done on the phpbb.com servers.

Post reply on HN