phpBB-TweakS
 
Advanced Search
   
 
Home Downloads FAQ Register FAQ Memberlist Usergroups Ranks
 
 

Please help us to develop!

 
It appears you are using a browser that is not based on Internet Explorer, this means you are not viewing the web as good as you should be. Other browsers might try to immitate Internet Explorer, but none can parse the web as it should like Internet Explorer can. So view the web as it was meant to be with Avant Browser!
         

phpBB-TweakS Forum Index Announcements Site Attacked
Display posts from previous:   
Half Thread Topic  Fully Thread Topic  Download Topic
      All times are GMT - 5 Hours  
Post new topic  Reply to topic

Fri Aug 18, 2006 3:28 pm
Author Message
aUsTiN
Webmaster
Webmaster


Usa Georgia

Joined: 05 Jan 2005
Posts: 3684
Words Posted: 144,671
Average Post: 39.27

Location: USA

Post subject: Site Attacked Reply with quote

As some of you might have already seen, at some point today a group of people found an exploit & decided to replace the index.php here. I'm not sure yet how they did it or why they did it even, but why does anyone bother to do it.

I have backups of everything, so if something else happens over the next few days while i try to figure it out, we can always back it up.

So maybe they will step up and let me know how they did it so we can try & safeguard from it in the future, but i doubt it.

aUsTiN & Staff
Post #1
      Back To Top  

Sat Aug 19, 2006 12:47 pm
Author Message
X
100 Club
100 Club


Mexico

Joined: 13 Jan 2005
Posts: 157
Words Posted: 22,097
Average Post: 140.75

Location: México

Post subject: Reply with quote

i heard time ago there was a big exploit for phpbb-security. And it was not the http_x thing, it was in some hack board called elhacker.net that are in spanish, im member there and one topic from their SMF board was that so i asked for the source but the told me source was a chat in an irc chat so there is notting posted or written. Its just a legend.

You know very well all constituton from PHPBB-security, do you think, and really do you think if there is some exploiy in phpbb-security hack atacks could replace index.php? Or the phpbb_security permissions and code are not enought to create an atack from that magnitude?

Also it could be a new exploit from the PHPBB2.0.21 versions (if you have it, if not from the previous version you have).

Or maybe a failre in server, chmod permissions and things like that. You can see this in your raw_log so you can define exactly what happened.

But if there is a bug in phpbb_security code this must be priority to fix because there will be no time to fix it before atackers publish the exploit and how to use it.

Greets.
Post #2
      Back To Top  

Sat Aug 19, 2006 3:42 pm
Author Message
aUsTiN
Webmaster
Webmaster


Usa Georgia

Joined: 05 Jan 2005
Posts: 3684
Words Posted: 144,671
Average Post: 39.27

Location: USA

Post subject: Reply with quote

There was an exploit in 1.0.1, which was discussed awhile ago & patched the same day.

No i dont use .21 so i doubt its that.

Also, one of the sites that was attacked did not have phpBB Security, did not have phpBB, as a matter of fact it had no files what so ever. Which leads me to believe they used some kind of brute force password cracker. But as of now im still not 100% sure.
Post #3
      Back To Top  

Sat Aug 19, 2006 6:33 pm
Author Message
X
100 Club
100 Club


Mexico

Joined: 13 Jan 2005
Posts: 157
Words Posted: 22,097
Average Post: 140.75

Location: México

Post subject: Reply with quote

aUsTiN wrote:


Also, one of the sites that was attacked did not have phpBB Security, did not have phpBB, as a matter of fact it had no files what so ever. Which leads me to believe they used some kind of brute force password cracker. But as of now im still not 100% sure.


Yep my same conclusion, latest versions of `phpbb had very great exploits, but also some of the oldest ones, but not for that magnitude of atack.
From phpbbsecurity im prettysure functions does not have power to give a list of chmod files or to write index.php File.

So it could be an FTp atack with a cracker, all FTPserver clients are creackeable except PureFTP, if you have PureFTP search for the atack origin in your raw_log and mistery could be solved.

Greets.
Post #4
      Back To Top  

Thu Aug 24, 2006 1:21 pm
Author Message
Cool foxyone Cool
Site Supporter
Site Supporter


Joined: 20 Nov 2005
Posts: 7
Words Posted: 385
Average Post: 55.00


Post subject: Reply with quote

the "group" that is doing alot of the attacks posts their exploits and alot of info regarding how they work etc

i found this after mine was attacked n the hackers left a trail

not sure if its wise to post the site so i`ll pm u the addy
Post #5
      Back To Top  

Thu Aug 24, 2006 2:18 pm
Author Message
aUsTiN
Webmaster
Webmaster


Usa Georgia

Joined: 05 Jan 2005
Posts: 3684
Words Posted: 144,671
Average Post: 39.27

Location: USA

Post subject: Reply with quote

The only thing with a PHP based vulnerability, as i said above one of my sites did not have any files, no html's, no php's, etc..

So i dont think the specific one you PM'ed me was my issue, however it could be an issue for others in the future.

To sum it up, make sure your host upgrades your PHP to the latest version.
Post #6
      Back To Top  

Thu Aug 24, 2006 4:50 pm
Author Message
Cool foxyone Cool
Site Supporter
Site Supporter


Joined: 20 Nov 2005
Posts: 7
Words Posted: 385
Average Post: 55.00


Post subject: Reply with quote

i didnt see ur site listed there, where as mine is , so i wasnt sure if it would help or not

but yes i think ur right about it being a problem for others in the future

sorry it wasnt any help and i hope u find out soon what the issue was

foxy
Post #7
      Back To Top  

Mon Oct 02, 2006 7:53 pm
Author Message
Cool foxyone Cool
Site Supporter
Site Supporter


Joined: 20 Nov 2005
Posts: 7
Words Posted: 385
Average Post: 55.00


Post subject: Reply with quote

i apologise for the double post

not sure if u found the answer to this issue or not
but my main forum was hacked 3 days ago ... i was actually on the forum as they was hacking ... so caught the ips 81.213.243.190
85.102.116.111

there was no sign of them on ip tracking anywhere on the forum they went in directly to admin/index.php

foxy
Post #8
      Back To Top  

Tue Oct 03, 2006 3:38 pm
Author Message
jsr
Support Team
Support Team


Joined: 06 Jan 2005
Posts: 407
Words Posted: 50,471
Average Post: 124.01


Post subject: Reply with quote

er that's why it's best to have the admin folder protected.
Post #9
      Back To Top  

 
         

Post new topic  Reply to topic

phpBB-TweakS Forum Index Announcements Site Attacked
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


      Back To Top  

Page 1 of 1
Jump to:  
 
Protected by phpBB Security © phpBB-TweakS
phpBB Security Has Blocked 3,235 Exploit Attempts.

· Archive · Sitemap: Index · Sitemap: Forums · Sitemap: Topics · Sitemap: Posts ·

:: [ Load Time: 2.8 Seconds ] :: [ 29 Queries ] :: [ 1,624 Page(s) Viewed Today ] ::
:: [ Todays Queries: 47,898 ] :: [ Highest Load: 1,396,429 Queries On May. 08, 2007 ] ::
:: [ SQL Load: 61% Time: 1.7 ] :: [ PHP Load: 39% Time: 1.1 ] :: [ Debug: On ] :: [ GZIP: Enabled ] ::
:: The server last rebooted 32 days, 23 hours, 15 minutes, 34 seconds ago. ::

The phpBB[Network]!
       
Powered by phpBB 2.0.* © 2001, 2002 phpBB Group
Avalanche style by What Is Real © 2004