1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

My phpbb3 forum got hacked ..

Discussion in 'Security' started by seolion, Aug 4, 2008.

  1. #1
    Please check indiaforums.info/index.php its redirecting to whitehackerz.org

    Its not a javascript redirect or something is what I feel.

    Anybody have any idea how to restore my site back?

    Thanks in advance..
     
    seolion, Aug 4, 2008 IP
  2. glitto

    glitto Notable Member

    Messages:
    2,839
    Likes Received:
    185
    Best Answers:
    0
    Trophy Points:
    205
    #2
    O yes, your indiaforums opened up for few seconds but immediately it redirected to the hackers site.

    I don't know how to restore it, I would suggest you to contact your hosting provider and ask for help. They must have best answer for that.

    Good luck
     
    glitto, Aug 4, 2008 IP
  3. Mega B

    Mega B Well-Known Member

    Messages:
    3,454
    Likes Received:
    66
    Best Answers:
    1
    Trophy Points:
    190
    #3
    Can anything be added to a phpBB Forum to make them safe from major problems like this ????
     
    Mega B, Aug 4, 2008 IP
  4. glitto

    glitto Notable Member

    Messages:
    2,839
    Likes Received:
    185
    Best Answers:
    0
    Trophy Points:
    205
    #4
    I don't know but after seeing this forum hacked I am very worried about my own phpbb3 forum :(

    I would go to the phpbb community and see if there is any MOD or anything that can be used to make the forums more secure.
     
    glitto, Aug 4, 2008 IP
  5. qprojects

    qprojects Peon

    Messages:
    1,901
    Likes Received:
    103
    Best Answers:
    0
    Trophy Points:
    0
    #5
    There's a meta redirect in the content of all your pages.
     
    qprojects, Aug 4, 2008 IP
    seolion likes this.
  6. EGS

    EGS Notable Member

    Messages:
    6,078
    Likes Received:
    438
    Best Answers:
    0
    Trophy Points:
    290
    #6
    You should use MyBB - it's like a free vBulletin. ;)
     
    EGS, Aug 4, 2008 IP
  7. glitto

    glitto Notable Member

    Messages:
    2,839
    Likes Received:
    185
    Best Answers:
    0
    Trophy Points:
    205
    #7
    If this meta redirect code is found on ALL pages of your site then I guess the hacker has put this code either on "overall_header.html" or "overall_footer.html" file.

    Please check these files.
     
    glitto, Aug 4, 2008 IP
  8. Whitey

    Whitey Active Member

    Messages:
    1,386
    Likes Received:
    14
    Best Answers:
    0
    Trophy Points:
    80
    #8
    Like other people said, check those files. Also check your access logs to see what's been going on. :)
     
    Whitey, Aug 4, 2008 IP
  9. seolion

    seolion Active Member

    Messages:
    1,495
    Likes Received:
    97
    Best Answers:
    0
    Trophy Points:
    90
    #9
    No files were updated ..
    The meta refresh was from one of the phpbb tables.. i removed it.. still its present in some other sections too..
     
    seolion, Aug 4, 2008 IP
  10. glitto

    glitto Notable Member

    Messages:
    2,839
    Likes Received:
    185
    Best Answers:
    0
    Trophy Points:
    205
    #10
    Did you try asking in phpbb community?

    if not, go for it. They can help you better.
     
    glitto, Aug 4, 2008 IP
  11. seolion

    seolion Active Member

    Messages:
    1,495
    Likes Received:
    97
    Best Answers:
    0
    Trophy Points:
    90
    #11
    I posted in PHPBB support forums too.. But the reply is that I should upgrade to latest version..

    By the way, as usual I was checking the visitor stats at statcounter, and saw 2 referrals from --http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,7723443/

    Thats how I came to know about the attack..

    A lesson learnt..
     
    seolion, Aug 4, 2008 IP
  12. C.Whyte

    C.Whyte Peon

    Messages:
    802
    Likes Received:
    18
    Best Answers:
    0
    Trophy Points:
    0
    #12
    you are more than likely going to have to go through all your phpbb pages that are labeled "index.html" or "index.php" and remove the redirects... they usually hit everywhere.

    A nice trick to making sure you got it all off is to use norton and turn the security up to max... it will display an error warning if the spyware is still on your site.
     
    C.Whyte, Aug 4, 2008 IP
  13. glitto

    glitto Notable Member

    Messages:
    2,839
    Likes Received:
    185
    Best Answers:
    0
    Trophy Points:
    205
    #13
    What version you were using?

    Just for others to know that old versions are no more secure.
     
    glitto, Aug 4, 2008 IP
  14. abercrombie

    abercrombie Peon

    Messages:
    654
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #14
    my PHPBB3 got hacked a week ago and some hacker installed a phishing bank site. hostgator erased it quick after only about 20 hits. told me to increase my password strength. i also went ahead and password protected the admin folder in cpanel. only thing that was relayed to me was the hacker exploited a valid script.
     
    abercrombie, Aug 4, 2008 IP
  15. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #15
    Can you change the name from index.php to something else? Can you take away all the links to BB3? i mean the hackers must look for something?
     
    TheSyndicate, Aug 4, 2008 IP
  16. LaZyBuM™

    LaZyBuM™ Peon

    Messages:
    183
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #16
    Examins the htaccess files, and reinstall the templates too. Becasue they can edit your template and add the html/javascript to redirect your page!
     
    LaZyBuM™, Aug 5, 2008 IP
  17. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #17
    right thats a good tip, diffrent template can be open to attacks.
     
    TheSyndicate, Aug 5, 2008 IP
  18. SteveWh

    SteveWh Member

    Messages:
    74
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    48
    #18
    Browse this list of known vulnerabilities and see if anything mentioned applies to your site: http://secunia.com/search/?search=phpbb&w=0

    You might be able to use .htaccess and php.ini to better protect it, but you have to be careful not to disable anything that phpbb needs to function properly.

    If a bad plug-in or module is the problem, the fix would be to remove it, the opposite of adding something.

    That was a good reply from them. It's important to have the latest version of all scripts. The latest version might have fixed the exact problem that allowed your site to get hit.

    One thing they look for is old versions with known vulnerabilities that they can exploit.
     
    SteveWh, Aug 6, 2008 IP
  19. Mega B

    Mega B Well-Known Member

    Messages:
    3,454
    Likes Received:
    66
    Best Answers:
    1
    Trophy Points:
    190
    #19
    SteveWh thanks for suggestions on Security on phpBB.
     
    Mega B, Aug 6, 2008 IP
  20. tendulkar2

    tendulkar2 Banned

    Messages:
    2,617
    Likes Received:
    69
    Best Answers:
    0
    Trophy Points:
    0
    #20
    I also have a Phpbb forum related to Indian celebs....
    I also experienced a similar problem few months back.. If your site is new one, just remove the software and install it again and put a complex password. and download,install any mods,etc from only phpbb.com . Don't download from other sites.. it will be fine.
     
    tendulkar2, Aug 6, 2008 IP