phpBB hacked, loads of passwords stolen!

Discussion in 'General Chat' started by Zhoog, Feb 10, 2009.

  1. #1
    Just came across this, which is some mayor news. phpBB got hacked over the course of a couple of weeks the hacker had secretly gained control of the system.

    All user email addresses, username and passwords have been stolen. All webmasters registered to tha forum should probably change their passwords if hey were using he same one.

    Read all about in phpbb:http://www.phpbb.com/community/viewtopic.php?f=14&t=1436615&sid=8866bc8d712770b22e0975676ba6368e
    And on the site of the hacker himself: http://hackedphpbb.blogspot.com/2009/01/place-holder.html

    Hope your not one of the webmasters that will have to get to work on their passwords.
     
    Zhoog, Feb 10, 2009 IP
  2. Zhoog

    Zhoog Peon

    Messages:
    237
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Oh shoot. I just saw the prior post on this subject be bumped to the first page. Sorry for this duplicate post guys!
     
    Zhoog, Feb 10, 2009 IP
  3. mrJorge

    mrJorge Peon

    Messages:
    89
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Yeah i heard about this on Wired, their site got defaced too. This means bad news for phpbb.
     
    mrJorge, Feb 10, 2009 IP
  4. successmindedgal

    successmindedgal Banned

    Messages:
    13
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Too bad for phpbb...:(
     
    successmindedgal, Feb 10, 2009 IP
  5. Zhoog

    Zhoog Peon

    Messages:
    237
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I think I was lucky, while running two phpBB forums I never registered on their support forums and never signed in fro theri newsletter. Just checked all my emails to be sure... Pfeew!

    I wander if they will try to get to the hacker?? If that doesn't work I hope they will try to by those email addresses back. Judging fro his blog post he kinda sounds like a reasonable guy that was just doing it for fun and to prove he could!
     
    Zhoog, Feb 10, 2009 IP
  6. KJThaDon

    KJThaDon Member

    Messages:
    37
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    41
    #6
    They where just running an 'outdated' email script. It wasn't the phpbb software that was vulnerable so to all those people thinking their sites are open to be hacked are wrong :)
     
    KJThaDon, Feb 10, 2009 IP
  7. dannywwww

    dannywwww Well-Known Member

    Messages:
    804
    Likes Received:
    18
    Best Answers:
    0
    Trophy Points:
    110
    #7
    Yup this is correct. They were running on a out dated version of "phplist" partly their own fault for trusting 3rdparty software, especially such a widely used software including a large user base.
     
    dannywwww, Feb 10, 2009 IP
  8. events

    events Active Member

    Messages:
    391
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    73
    #8
    phpbb.com is back up now
     
    events, Feb 10, 2009 IP
  9. levampire

    levampire Active Member

    Messages:
    2,463
    Likes Received:
    55
    Best Answers:
    0
    Trophy Points:
    90
    #9
    Thx for letting us know, Phew.
     
    levampire, Feb 10, 2009 IP