Welcome to NeoOffice developer notes and announcements
NeoOffice
Developer notes and announcements
 
 

This website is an archive and is no longer active
NeoOffice announcements have moved to the NeoOffice News website


Support
· Forums
· NeoOffice Support
· NeoWiki


Announcements
· Twitter @NeoOffice


Downloads
· Download NeoOffice


  
NeoOffice :: View topic - Hackers took out phpbb
Hackers took out phpbb
 
   NeoOffice Forum Index -> Server Outages
View previous topic :: View next topic  
Author Message
OPENSTEP
The One
The One


Joined: May 25, 2003
Posts: 4752
Location: Santa Barbara, CA

PostPosted: Mon Aug 16, 2004 9:59 am    Post subject: Hackers took out phpbb

OK, so as per the norm, the day after I go away on vacation some silly hackers took down the phpbb system. I reverted back to the most recent backup of the entire db, so chances are that the august posts are gone.

I really have no clue why script kiddies love hacking this server. Go attack microsoft you asshats and leave the volunteers here alone. No one appreciates your 'skills' and you'll never be able to use them to find a real job...spend your time doing something productive instead.

ed
Back to top
JKT
The Anomaly
(earlier version)


Joined: Sep 18, 2003
Posts: 434
Location: London, UK

PostPosted: Mon Aug 16, 2004 10:40 am    Post subject: Re: Hackers took out phpbb

Perhaps they work for Microsoft! Very Happy Razz

Anyway shame to see it happen and also to lose all those posts, but glad it is back to something more normal... and welcome back from your hols. Cool

_________________
PBG4, 1.5GHz, SuperDrive, 1GB RAM, 128MB VRAM, 5400rpm 80GB HD, MacOS X 10.4.5

Please visit The Land Gallery at http://www.thelandgallery.com for nature-inspired British Fine Art
Back to top
Max_Barel
Oracle


Joined: May 31, 2003
Posts: 219
Location: French Alps

PostPosted: Mon Aug 16, 2004 1:24 pm    Post subject: Re: Hackers took out phpbb

JKT wrote:
Perhaps they work for Microsoft! Very Happy Razz

I also wondered by this though.
How many chance for it to be true? Or pure paranoïd mind?
Back to top
sardisson
Town Crier
Town Crier


Joined: Feb 01, 2004
Posts: 4588

PostPosted: Mon Aug 16, 2004 3:27 pm    Post subject:

Very Happy Very Happy Very Happy I was so happy to see a full, unhacked Trinity when I came back today. It's got me happier than the Krispy Kreme opening in Dupont Circle next week! (It's a Southern thing for those of you [y'all] not familiar Smile )

That having been said, I see that the version of phpBB running in the nuke module 2.0.4; the current version is 2.0.10 and apparently everything after 2.0.5 has been a release that fixes only security holes!

Dunno if the nuke module version has been updated to support 2.0.10, but perhaps it's something to look in to when you get the time....

Anyway, hope you had a good vacation, Ed. Thanks again for running this (and everything else OOo/Neo)!

Smokey
Back to top
OPENSTEP
The One
The One


Joined: May 25, 2003
Posts: 4752
Location: Santa Barbara, CA

PostPosted: Mon Aug 16, 2004 8:20 pm    Post subject:

Oh yeah, I had a great vacation...over 3k miles of driving but I got to spend multiple days camping and backpacking in Glacier, Yellowstone, the Tetons, beautiful drives through Wyoming, etc. It was actually the first time in over a year that it was over a week and a half between me turning on a computer Smile If I had, trinity would've been fixed near instantaneously Very Happy

I can go back and try to recover those posts, but yeah my first order of business will be to go through and look at the security patches again. The versions of things on the server are only partially indicative of what's actually here as I've done quite a bit of manual application of security patches without changing the version. I'll definitely check into the newer versions.

Still, this was the most destructive script kiddie yet. At least the other ones had the common decency to just smat their shout outs on pages. This one felt it necessary to delete things Evil or Very Mad

Deep down in my heart I hope someday he'll be rudely awoken from dreams of gingerbread houses by an otter masticating his nutsack while a wino mariachi band covers Rocketman through a pair of megaphones strapped to his skull.

ed
Back to top
jakeOSX
Ninja
Ninja


Joined: Aug 12, 2003
Posts: 1373

PostPosted: Tue Aug 17, 2004 5:58 am    Post subject:

glad you are back man. sounds like a good trip too.

let me know if you want me looking into things (other site choices, security updates, etc).

-j

_________________
http://jakeofalltrades.midatlantichorror.org
Back to top
OPENSTEP
The One
The One


Joined: May 25, 2003
Posts: 4752
Location: Santa Barbara, CA

PostPosted: Wed Aug 18, 2004 7:08 am    Post subject:

Oh dude, if you have time and can minimally keep track of security updates that'd be nifty! I still haven't put nukecops or the phpbb security sites on my "daily reading" list though I'll have to do that. This latest one was interesting since it was only affecting the phpbb portion...all past attacks went straight for the nuke.

I don't think switching systems would really help since we're going to have security problems with anything that's up. These days, once something is up people will try attacking it. I could restrict browser access to only let MacWWW through....

ed
Back to top
jakeOSX
Ninja
Ninja


Joined: Aug 12, 2003
Posts: 1373

PostPosted: Wed Aug 18, 2004 10:28 am    Post subject:

yeah, shouldn't be an issue, PM me or catch me on iChat.

-j
Back to top
Guest






PostPosted: Wed Sep 15, 2004 5:59 pm    Post subject:

sardisson wrote:
Very Happy Very Happy Very Happy I was so happy to see a full, unhacked Trinity when I came back today. It's got me happier than the Krispy Kreme opening in Dupont Circle next week! (It's a Southern thing for those of you [y'all] not familiar Smile )

That having been said, I see that the version of phpBB running in the nuke module 2.0.4; the current version is 2.0.10 and apparently everything after 2.0.5 has been a release that fixes only security holes!

Dunno if the nuke module version has been updated to support 2.0.10, but perhaps it's something to look in to when you get the time....

Anyway, hope you had a good vacation, Ed. Thanks again for running this (and everything else OOo/Neo)!

Smokey
Back to top
Display posts from previous:   
   NeoOffice Forum Index -> Server Outages All times are GMT - 7 Hours
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Powered by phpBB © 2001, 2005 phpBB Group

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © Planamesa Inc.
NeoOffice is a registered trademark of Planamesa Inc. and may not be used without permission.
PHP-Nuke Copyright © 2005 by Francisco Burzi. This is free software, and you may redistribute it under the GPL. PHP-Nuke comes with absolutely no warranty, for details, see the license.