Hacked?

This is an archive of the phpBB 2.0.x support forum. Support for phpBB2 has now ended.
Forum rules
Following phpBB2's EoL, this forum is now archived for reference purposes only.
Please see the following announcement for more information: viewtopic.php?f=14&t=1385785

Hacked?

Postby will727 » Mon Dec 20, 2004 1:56 pm

Hey, just thought someone might be able to help. Tried to access my forum today and got a strange message come up. Here is the forum address. Maybe some1 can help? Thanks

http://www.freedom-fighters.net/sigsource/index.php
will727
Registered User
 
Posts: 3
Joined: Mon Dec 20, 2004 1:53 pm

Postby fumbalah » Mon Dec 20, 2004 2:06 pm

Yea, you got hacked, Were you not running the latest version. Check your database to see if they got to it
User avatar
fumbalah
Registered User
 
Posts: 2000
Joined: Sat Jan 24, 2004 3:02 pm
Location: Lexington, Kentucky

Postby will727 » Mon Dec 20, 2004 2:46 pm

My friend host the forum for me and i host the website as he has more bandwidth than me. I'll contact him asasp and see if they got to the database. Thanks.
will727
Registered User
 
Posts: 3
Joined: Mon Dec 20, 2004 1:53 pm

Postby Steeldogs » Mon Dec 20, 2004 2:54 pm

Check your index.php page and see if they were just renamed and this new index page was put in it's place.
User avatar
Steeldogs
Registered User
 
Posts: 72
Joined: Sun Jul 18, 2004 3:45 pm
Location: Birmingham, Alabama

Postby Flyspray » Mon Dec 20, 2004 3:17 pm

I had the same thing happen, but I'm unable to even get to the site. I think my hosting company has pulled the plug and is conducting upgrades or taken preventative measures.
Flyspray
Registered User
 
Posts: 6
Joined: Fri Nov 05, 2004 7:53 pm

Postby will727 » Mon Dec 20, 2004 4:19 pm

thanks for the reponses guys. I still cant get in contact with the guy hosting my forum, but i'll let you no how i get on.
will727
Registered User
 
Posts: 3
Joined: Mon Dec 20, 2004 1:53 pm

Postby eureka345 » Mon Dec 20, 2004 4:44 pm

I've had the same thing happen too. So frustrating. I got the rest of my site working fine again, but not my forum.
eureka345
Registered User
 
Posts: 22
Joined: Thu Sep 04, 2003 11:31 pm

Postby Kirsty84 » Mon Dec 20, 2004 5:13 pm

Everytime i visit my forum: http://www.anistoncenter.com/jacf/ i get a message saying:

"This site has been defaced"

Can anyone help? I have no idea how to fix this. I'm running the site for somone else, and have no idea about anything technical.

Any help would be greatly apperciated. I'm in such a panic. Will everything at the forum be lost?
Kirsty84
Registered User
 
Posts: 2
Joined: Mon Dec 20, 2004 5:06 pm
Location: UK

Re: Hacked?

Postby Steeldogs » Mon Dec 20, 2004 5:36 pm

will727 wrote:Hey, just thought someone might be able to help. Tried to access my forum today and got a strange message come up. Here is the forum address. Maybe some1 can help? Thanks

http://www.freedom-fighters.net/sigsource/index.php


I see you got it back. How did you correct it. Kristy84 might could use the info
User avatar
Steeldogs
Registered User
 
Posts: 72
Joined: Sun Jul 18, 2004 3:45 pm
Location: Birmingham, Alabama

Postby Techie-Micheal » Mon Dec 20, 2004 6:03 pm

Kristy84: This appears to be an automated attack on the recent PHP (not phpBB) vulnerabilities. Make sure your host upgrades to the appropriate version of PHP.
"PHP?!?! What are you, sick?" - Professor when I said I wanted to write a forensics app in PHP
User avatar
Techie-Micheal
Consultant
 
Posts: 19220
Joined: Sun Oct 14, 2001 12:11 am
Location: ::1

Postby xcs-bat » Tue Dec 21, 2004 10:04 am

I don't think its a php problem, as my servers (aye several) got hacked and they have benn all running on the latest php version!

Any help would be apreciated!

thx!
xcs-bat
Registered User
 
Posts: 6
Joined: Fri Jul 16, 2004 1:42 pm

Postby marinedalek » Tue Dec 21, 2004 10:49 am

Just thought I'd add another site to the long list of those hacked by the NeverEverNoSanity worm. http://petesqbsite.com/ - it's not my site but it was one I visited often. Guess which phpBB version it was running... 2.0.6 - urk! How did other people restore their sites? Did you have to do a full file backup?
marinedalek
Registered User
 
Posts: 22
Joined: Sun Aug 01, 2004 11:06 am

Postby xcs-bat » Tue Dec 21, 2004 10:52 am

k got it

Its a security bug in phps unserialize() function. phpBB (and lots of other boards) are using it.

http://www.hardened-php.net/advisories/012004.txt

http://developers.slashdot.org/article. ... 17/1641212

there isnt a fix right now it seems, so I gota shut the boards on my servers down to protect my other customers :(
xcs-bat
Registered User
 
Posts: 6
Joined: Fri Jul 16, 2004 1:42 pm

Postby Druid_YGM » Tue Dec 21, 2004 11:39 am

Does that mean ANY version of phpbb software is vulnerable then ?
Druid_YGM
Registered User
 
Posts: 40
Joined: Tue Dec 21, 2004 9:24 am

Postby xcs-bat » Tue Dec 21, 2004 12:35 pm

seems like it :(

well the versions using the unserialize() function at least, and I guess thats every version.

Theres a workaround tough it seems. After installing it phpBB isnt using this function anymore. Havent confirmed it myself yet.

Will post the link after I tryed it.
xcs-bat
Registered User
 
Posts: 6
Joined: Fri Jul 16, 2004 1:42 pm

Next

Return to 2.0.x Support Forum

Who is online

Users browsing this forum: No registered users and 8 guests