|
|
It appears you are using a browser that is not based on Internet Explorer, this means you are not viewing the web as good as you should be. Other browsers might try to immitate Internet Explorer, but none can parse the web as it should like Internet Explorer can. So view the web as it was meant to be with Avant Browser!
|
| |
|
|
All times are GMT - 5 Hours
|
|
 |
Fri Aug 18, 2006 3:28 pm |
 |
Author |
Message |
aUsTiN Webmaster


Joined: 05 Jan 2005 Posts: 3684 Words Posted: 144,671 Average Post: 39.27 Location: USA
|
| Post subject: Site Attacked |
|
|
As some of you might have already seen, at some point today a group of people found an exploit & decided to replace the index.php here. I'm not sure yet how they did it or why they did it even, but why does anyone bother to do it.
I have backups of everything, so if something else happens over the next few days while i try to figure it out, we can always back it up.
So maybe they will step up and let me know how they did it so we can try & safeguard from it in the future, but i doubt it.
aUsTiN & Staff |
|
| Post #1 |
|
|
 |
Sat Aug 19, 2006 12:47 pm |
 |
Author |
Message |
X 100 Club


Joined: 13 Jan 2005 Posts: 157 Words Posted: 22,097 Average Post: 140.75 Location: México
|
| Post subject: |
|
|
i heard time ago there was a big exploit for phpbb-security. And it was not the http_x thing, it was in some hack board called elhacker.net that are in spanish, im member there and one topic from their SMF board was that so i asked for the source but the told me source was a chat in an irc chat so there is notting posted or written. Its just a legend.
You know very well all constituton from PHPBB-security, do you think, and really do you think if there is some exploiy in phpbb-security hack atacks could replace index.php? Or the phpbb_security permissions and code are not enought to create an atack from that magnitude?
Also it could be a new exploit from the PHPBB2.0.21 versions (if you have it, if not from the previous version you have).
Or maybe a failre in server, chmod permissions and things like that. You can see this in your raw_log so you can define exactly what happened.
But if there is a bug in phpbb_security code this must be priority to fix because there will be no time to fix it before atackers publish the exploit and how to use it.
Greets. |
|
| Post #2 |
|
|
 |
Sat Aug 19, 2006 3:42 pm |
 |
Author |
Message |
aUsTiN Webmaster


Joined: 05 Jan 2005 Posts: 3684 Words Posted: 144,671 Average Post: 39.27 Location: USA
|
| Post subject: |
|
|
There was an exploit in 1.0.1, which was discussed awhile ago & patched the same day.
No i dont use .21 so i doubt its that.
Also, one of the sites that was attacked did not have phpBB Security, did not have phpBB, as a matter of fact it had no files what so ever. Which leads me to believe they used some kind of brute force password cracker. But as of now im still not 100% sure. |
|
| Post #3 |
|
|
 |
Sat Aug 19, 2006 6:33 pm |
 |
Author |
Message |
X 100 Club


Joined: 13 Jan 2005 Posts: 157 Words Posted: 22,097 Average Post: 140.75 Location: México
|
| Post subject: |
|
|
| aUsTiN wrote: |
Also, one of the sites that was attacked did not have phpBB Security, did not have phpBB, as a matter of fact it had no files what so ever. Which leads me to believe they used some kind of brute force password cracker. But as of now im still not 100% sure. |
Yep my same conclusion, latest versions of `phpbb had very great exploits, but also some of the oldest ones, but not for that magnitude of atack.
From phpbbsecurity im prettysure functions does not have power to give a list of chmod files or to write index.php File.
So it could be an FTp atack with a cracker, all FTPserver clients are creackeable except PureFTP, if you have PureFTP search for the atack origin in your raw_log and mistery could be solved.
Greets. |
|
| Post #4 |
|
|
 |
Thu Aug 24, 2006 1:21 pm |
 |
Author |
Message |
foxyone  Site Supporter

Joined: 20 Nov 2005 Posts: 7 Words Posted: 385 Average Post: 55.00
|
| Post subject: |
|
|
the "group" that is doing alot of the attacks posts their exploits and alot of info regarding how they work etc
i found this after mine was attacked n the hackers left a trail
not sure if its wise to post the site so i`ll pm u the addy |
|
| Post #5 |
|
|
 |
Thu Aug 24, 2006 2:18 pm |
 |
Author |
Message |
aUsTiN Webmaster


Joined: 05 Jan 2005 Posts: 3684 Words Posted: 144,671 Average Post: 39.27 Location: USA
|
| Post subject: |
|
|
The only thing with a PHP based vulnerability, as i said above one of my sites did not have any files, no html's, no php's, etc..
So i dont think the specific one you PM'ed me was my issue, however it could be an issue for others in the future.
To sum it up, make sure your host upgrades your PHP to the latest version. |
|
| Post #6 |
|
|
 |
Thu Aug 24, 2006 4:50 pm |
 |
Author |
Message |
foxyone  Site Supporter

Joined: 20 Nov 2005 Posts: 7 Words Posted: 385 Average Post: 55.00
|
| Post subject: |
|
|
i didnt see ur site listed there, where as mine is , so i wasnt sure if it would help or not
but yes i think ur right about it being a problem for others in the future
sorry it wasnt any help and i hope u find out soon what the issue was
foxy |
|
| Post #7 |
|
|
 |
Mon Oct 02, 2006 7:53 pm |
 |
Author |
Message |
foxyone  Site Supporter

Joined: 20 Nov 2005 Posts: 7 Words Posted: 385 Average Post: 55.00
|
| Post subject: |
|
|
i apologise for the double post
not sure if u found the answer to this issue or not
but my main forum was hacked 3 days ago ... i was actually on the forum as they was hacking ... so caught the ips 81.213.243.190
85.102.116.111
there was no sign of them on ip tracking anywhere on the forum they went in directly to admin/index.php
foxy |
|
| Post #8 |
|
|
 |
Tue Oct 03, 2006 3:38 pm |
 |
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
Protected by phpBB Security © phpBB-TweakS phpBB Security Has Blocked 3,237 Exploit Attempts.
· Archive · Sitemap: Index · Sitemap: Forums · Sitemap: Topics · Sitemap: Posts ·
:: [ Load Time: 3 Seconds ] :: [ 30 Queries ] :: [ 4,401 Page(s) Viewed Today ] :: :: [ Todays Queries: 132,316 ] :: [ Highest Load: 1,396,429 Queries On May. 08, 2007 ] :: :: [ SQL Load: 64% Time: 1.9 ] :: [ PHP Load: 36% Time: 1.1 ] :: [ Debug: On ] :: [ GZIP: Enabled ] :: :: The server last rebooted 81 days, 8 hours, 37 minutes, 42 seconds ago. ::
|
|
|