My phpbb3 forum got hacked ..

Discussion in 'Security' started by seolion, Aug 4, 2008.

  1. invisible

    invisible Banned

    Messages:
    2,031
    Likes Received:
    95
    Best Answers:
    0
    Trophy Points:
    0
    #21
    Same thing happened with me. Actually what they do is they make a forum and put the redirect code there. Once you openn the forum it opens a little and when it have to load the forum the hacker makes you get redirected.. I wasn't able to solve it using ACP also

    Finally restored 1 day old backup and secured everything using my own code..
     
    invisible, Aug 10, 2008 IP
  2. glitto

    glitto Notable Member

    Messages:
    2,839
    Likes Received:
    185
    Best Answers:
    0
    Trophy Points:
    205
    #22
    Will you guys please share your tips to make a phpbb forum more secure?

    Me too running a phpbb forum so it will help me very much.

    Should we keep changing our cPanel & ACP password in every few days to avoid the risk of being hacked?
     
    glitto, Aug 10, 2008 IP
  3. Dude111

    Dude111 Guest

    Messages:
    1,153
    Likes Received:
    21
    Best Answers:
    0
    Trophy Points:
    0
    #23
    Dude111, Aug 10, 2008 IP
  4. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #24
    I guess since it open source easy to hack. Same as wordpress i have no closed all my open holes and have "eofuef8we90f8w09efiweoifjwe0fwe[ jfiowefjwefuwefwe fwejfweofwefewf-wefwe" as a password
     
    TheSyndicate, Aug 11, 2008 IP
  5. abercrombie

    abercrombie Peon

    Messages:
    654
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #25
    it's more PHPBB than Cpanel though protect your Cpanel as best you can. use the password protect directories feature in CP to password protect the admin folder of PHPBB. i think PHPBB is easy to hack because the hacker can browse the member list and find out who the admins are thus having one piece of the puzzle which is the username. all they have to do is run a brute force attack to get the password. if it's a long complex password then it'll be hard to break. mine was only 8 characters with only numbers and letters when mine got hacked so i increased the complexity. other forums like VBulletin and Invision Power have lock out features after invalid attempts which help keep out the hackers. Plus within Invision your login ID can be different from your display handle.
     
    abercrombie, Aug 11, 2008 IP
  6. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #26
    Right the admin or the mods have to have more complex passwords then the normal users i never thought about that actully but thats right.
     
    TheSyndicate, Aug 12, 2008 IP
  7. vBPoint.Com

    vBPoint.Com Peon

    Messages:
    365
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #27
    1st : Check your files.
    2nd: Use meta kernel htt trace. (Will show you what changes have been made)
    3rd : Upgrade your forum.
    4rth : Use Sentinel Hacker protection to protect from further hackings to your forum.

    Any more help , just drop a pm.
     
    vBPoint.Com, Aug 12, 2008 IP
  8. lachlan438

    lachlan438 Peon

    Messages:
    74
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #28
    man that must suck I hope to got this dose not happen to me I'm using phpbb 3.0.1 at the moment I have not upgraded becuse one of my mods is not compatible at the moment!
     
    lachlan438, Aug 12, 2008 IP
  9. roynston

    roynston Banned

    Messages:
    378
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #29
    I wont recommend Phpbb , it has so many security loop holes, and can be easly hacked through XSS vulnerability.
    USE SMF or go for VB
     
    roynston, Aug 12, 2008 IP
  10. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #30
    WHat is

    Use meta kernel htt trace?

    and

    Sentinel Hacker protection?

    How to get it how to use it?
     
    TheSyndicate, Aug 18, 2008 IP
  11. William[ws]

    William[ws] Peon

    Messages:
    47
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #31
    APACHE MODSECURITY FTW!!!

    using that module with some custom rulesets for apache is the best way IMO....
     
    William[ws], Aug 18, 2008 IP
  12. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #32
    That did not make me much smarter but thanks
     
    TheSyndicate, Aug 21, 2008 IP
  13. magicworld11

    magicworld11 Well-Known Member

    Messages:
    1,310
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    105
    #33
    The same hacker was hacked my forum which was PHPBB. There is major security issue in phpbb and this is the reason you will find all popular forums running on IPB and VB
     
    magicworld11, Aug 23, 2008 IP
  14. TheSyndicate

    TheSyndicate Prominent Member

    Messages:
    5,410
    Likes Received:
    289
    Best Answers:
    0
    Trophy Points:
    365
    #34
    really? So you think after that many updates they still have a problem? Tells us how your forum was hacked
     
    TheSyndicate, Aug 23, 2008 IP
  15. seolion

    seolion Active Member

    Messages:
    1,495
    Likes Received:
    97
    Best Answers:
    0
    Trophy Points:
    90
    #35
    Sorry for digging an old thread. I migrated my PHPBB forum to MyBB, now even there is no single spam registration which used to happen in PHPBB. I migrated all my forums to MyBB and they are running fine.
    Its time to say bye bye to PHPBB, will not rethink on my decision untill guys at PHPBB take it bit more seriously.
     
    seolion, Apr 19, 2009 IP
  16. Mega B

    Mega B Well-Known Member

    Messages:
    3,454
    Likes Received:
    66
    Best Answers:
    1
    Trophy Points:
    190
    #36
    @seolion did you transfer all your phpBB database over to MyBB or did you have to start again as you have mentioned spam on a phpBB Forum can be a nightmare ??? Thanks
     
    Mega B, Apr 20, 2009 IP
  17. seolion

    seolion Active Member

    Messages:
    1,495
    Likes Received:
    97
    Best Answers:
    0
    Trophy Points:
    90
    #37
    I used a converter to transfer users and threads from phpbb tables to mybb tables. As far as the forum is concerned, it is just a software change, rest are all retained.
     
    seolion, Apr 20, 2009 IP
  18. MayurGondaliya

    MayurGondaliya Well-Known Member

    Messages:
    1,233
    Likes Received:
    38
    Best Answers:
    0
    Trophy Points:
    170
    #38
    If you are using any template then restore that template to the default one. Your template might have been hacked and hacker may have injected some redirection rule.

    Also check the .htaccess file if there is any suspicious redirect rules setup.
     
    MayurGondaliya, Apr 20, 2009 IP
  19. Mega B

    Mega B Well-Known Member

    Messages:
    3,454
    Likes Received:
    66
    Best Answers:
    1
    Trophy Points:
    190
    #39
    As the VB forum platform seems to be the most secure against attacks is it possible to transfer all the data from phpBB to a new VB forum and if this is possible how is it done please ???? Thanks
     
    Mega B, Apr 20, 2009 IP
  20. Betimii

    Betimii Active Member

    Messages:
    283
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    55
    #40
    run :) Vbulletin and never will be hacked :D
     
    Betimii, Apr 20, 2009 IP