Previous Thread
Next Thread
Print Thread
Rate Thread
#35162 02/08/05 07:46 PM
Joined: Sep 2002
Posts: 553
UGN Super Poster
UGN Super Poster
Joined: Sep 2002
Posts: 553
The popular phpBB forum has been taken offline after hackers cracked into its server and defaced its website yesterday. The open source project's website was attacked using a vulnerability in a package called AWStats announced 17 January. The same exploit has also been used to attack several popular weblogs in recent days, Netcraft reports.

phpBB has been a target for attack before. In December 2004 malware authors created a worm that attacked web servers running the popular phpBB discussion forum software to deface vulnerable systems. The Santy worm hit thousands of sites.
SOURCE

Sponsored Links
▼ Sponsored Links ▼ ▲ Sponsored Links ▲
#35163 02/08/05 10:48 PM
Joined: Feb 2002
Posts: 7,203
Likes: 11
Community Owner
Community Owner
Joined: Feb 2002
Posts: 7,203
Likes: 11
I love the message on pnphpbb.com right now about them having their own server; last i checked they didn't heh...

Additionaly, the error with awstats was fixed in 6.3, their fault for not upgrading... Speaking of which, time for me to upgrade a few sites...

Also, from the AWStats homepage:
If you use AWStats with another version or with option AllowToUpdateStatsFromBrowser to 0, you are safe. If not, it is highly recommanded to update to 6.3 version that fix this security hole.

I don't even KNOW ANYONE who would like to allow their users to update their webstats at will... their own fault smirk


Donate to UGN Security here.
UGN Security, Back of the Web, and VNC Web Services Owner

Link Copied to Clipboard
Member Spotlight
None yet
Forum Statistics
Forums41
Topics33,840
Posts68,858
Members2,176
Most Online3,253
Jan 13th, 2020
Latest Postings
Top Posters
UGN Security 41,392
Gremelin 7,203
§intå× 3,255
SilentRage 1,273
Ice 1,146
pergesu 1,136
Infinite 1,041
jonconley 955
Girlie 908
unreal 860
Top Likes Received
Ghost 2
Girlie 1
unreal 1
Crime 1
Ice 1
Powered by UBB.threads™ PHP Forum Software 8.0.0