Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 9 of 9

This is a discussion on my phpBB hacked! in the Open Discussion & Chit-chat forum
http://www.snipeme.com/board/viewtopic.php?p=4597&#4597 Very Interesting. So apparently phpBB 2.0.10 is extremely easy to hack. Well, in return for the dude showing me this, I'm posting here to ...

  1. #1
    JPC Guru
    Join Date
    Jan 2004
    Location
    I'm right behind you....
    Posts
    389

    my phpBB hacked!

    http://www.snipeme.com/board/viewtopic.php?p=4597&#4597

    Very Interesting. So apparently phpBB 2.0.10 is extremely easy to hack. Well, in return for the dude showing me this, I'm posting here to let everyone who uses phpBB know about this. I'm not particularly concerned about since I do frequent backups and any mass deletion of my forum would be a waste of time for any hacker.

    At least this guy appears to be one of the "good guys" and not some stupid script kiddie.

  2. #2
    || $name ne 'R.Stiltskin'
    Join Date
    Jun 2003
    Location
    Tejas
    Posts
    2,438
    Just curious... how much of a hassle would it be to upgrade? Wouldn't that be easier than worrying about being "known-hack vulnerable" and responding every time the same haxor visits? Backing up your site may very well be easy but it still means that it could come down at an inconvenient time.

    Granted, the next version won't be hack-proof either, but why let the script-kiddie dictate your site maintenance schedule?

    Incidently, I don't use the software so maybe it is more trouble than it's worth to update. It just strikes me as curious.

  3. #3
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Um...

    Maybe you missed this:
    phpBB 2.0.11 Upgrade Reminder
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  4. #4
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by Spathiphyllum
    Incidently, I don't use the software so maybe it is more trouble than it's worth to update. It just strikes me as curious.
    Piece of cake...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  5. #5
    JPC Guru
    Join Date
    Jan 2004
    Location
    I'm right behind you....
    Posts
    389
    You're right Vin, I did miss that. I'll be upgrading asap now. Thanks!

  6. #6
    JPC Member
    Join Date
    Nov 2003
    Posts
    4
    Last edited by ChanceR; 12-22-2004 at 03:52 AM.

  7. #7
    Darth Admin (aka Jag) JPC-Greg's Avatar
    Join Date
    Sep 1998
    Posts
    5,201
    Vin, ill borrow your post for a news and updates notice on this.
    Greg L. | Chief Executive Officer
    JaguarPC.com

    Helpful Links
    Knowledge Base | Network Status

    Need a Manager?
    (pm) | (email) David, Customer Service Manager
    (pm) | (email) Zach, Community Liason, Sales manager
    (pm) | (email) Masood, Chief Technical Officer
    (pm) | (email) Les, Chief Operations Officer

  8. #8
    Darth Admin (aka Jag) JPC-Greg's Avatar
    Join Date
    Sep 1998
    Posts
    5,201
    nevermind, les beat me to it
    Greg L. | Chief Executive Officer
    JaguarPC.com

    Helpful Links
    Knowledge Base | Network Status

    Need a Manager?
    (pm) | (email) David, Customer Service Manager
    (pm) | (email) Zach, Community Liason, Sales manager
    (pm) | (email) Masood, Chief Technical Officer
    (pm) | (email) Les, Chief Operations Officer

  9. #9
    BNX
    BNX is offline
    JPC Member
    Join Date
    Jul 2004
    Location
    Eugene, Oregon
    Posts
    49
    I dont think this deserves its own thread, but here it is here, I had my phpnuke portal hacked recently. And I suspect the user used SQL Injection and set himself as god admin. Hes gone now, but I was hoping someone knew of a security patch for this?

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •