Live data from Hacker News

Several of the web servers powering phpBB.com were compromised

phpbb.com

1–10 of 27 posts

Re: Several of the web servers powering phpBB.com were compromised

#2
Is it just me, or does anyone wish that compromise disclosures should be hosted somewhere other than the site that has been compromised? What if there's a persistent threat and their webserver is still hosed, injecting 0days into responses? Not that it's happening here - I still clicked it - but I was hesitant.

Re: Several of the web servers powering phpBB.com were compromised

#3
Other than the obvious, some things worry me.

> We have confirmed that initial entry was made via a team member's compromised login details and not as the result of a vulnerability in the phpBB software.

> The attackers were able to obtain access to the phpBB.com and area51 databases, meaning that user information, including hashed salted passwords, was compromised. Additionally, all logins on area51 between Dec. 12th and Dec. 15th were logged in plaintext. While the hashing algorithm utilized in phpBB will make it difficult to obtain those passwords, you should not take any chances.

A bit of clarification should be given. The staff's login information was stolen, allowing someone to get a dump of the database containing user info. What kind of login information was stolen? Is this an shell account, was an SSH key stolen, was this an admin panel account?

Secondly, "all logins [...] were logged in plaintext". Does this mean the username and password were logged, the password hashes and sessions? What actual information was plaintext to the user?

It's great that groups are willing to own up to these kinds of events, but without specific information, it's hard to understand how broad a compromise we're talking.

Re: Several of the web servers powering phpBB.com were compromised

#4
post #2

Is it just me, or does anyone wish that compromise disclosures should be hosted somewhere other than the site that has been compromised? What if there's a persistent threat and their webserver is still hosed, injecting 0days into responses? Not that it's happening here - I still clicked it - but I was hesitant.

You are right. We should even go further and reset the whole interweb each time there is a disclosure, or at least randomize the DNS records of the affected servers.

Re: Several of the web servers powering phpBB.com were compromised

#5
post #2

Is it just me, or does anyone wish that compromise disclosures should be hosted somewhere other than the site that has been compromised? What if there's a persistent threat and their webserver is still hosed, injecting 0days into responses? Not that it's happening here - I still clicked it - but I was hesitant.

It is the one site you know the users will come to. I would do the new web server at old address. Hacked machines should not be put back in service.

Re: Several of the web servers powering phpBB.com were compromised

#7
post #2

Is it just me, or does anyone wish that compromise disclosures should be hosted somewhere other than the site that has been compromised? What if there's a persistent threat and their webserver is still hosed, injecting 0days into responses? Not that it's happening here - I still clicked it - but I was hesitant.

It is the one site you know the users will come to. I would do the new web server at old address. Hacked machines should not be put back in service.

I think what you want is the "Full Disclosure" mailing list:

  http://nmap.org/mailman/listinfo/fulldisclosure

Re: Several of the web servers powering phpBB.com were compromised

#8
post #2

Is it just me, or does anyone wish that compromise disclosures should be hosted somewhere other than the site that has been compromised? What if there's a persistent threat and their webserver is still hosed, injecting 0days into responses? Not that it's happening here - I still clicked it - but I was hesitant.

I don't think there's much point in worrying about drive-by browser attacks. We all visit a lot of sites, and many sites are hacked without their owners knowing, but just serving malware/phishing/redirects for spam, ad networks, and injection into more popular sites.

If a browser 0day really did apply to my up-to-date version of firefox and really was a problem, well, I'd feel pretty screwed.

Post reply on HN