Problem at phpbb.com for users

Is somebody flaming or causing problems? Is there a post that is too large for content? Moderators will check here often to discover problems quickly.
Post Reply
Matooba





Posts: 186
Joined: Thu Jan 05, 2006 2:51 am
Location: North East U.S.
Contact:

Problem at phpbb.com for users

Post by Matooba »

phpbb users email comprimised
For those who have an account at area51.phpBB.com and phpbb.com, please take notice
As you may already be aware from the message on phpBB.com or the topic in the #phpBB channel on Freenode, we have recently been attacked via a vulnerability in an outdated PHPList installation. The initial attack was performed well before a new version of the software was released or a patch provided. It is important to stress that no vulnerabilities have been found in the phpBB software itself.

We took area51.phpBB.com down along with phpBB.com to ensure integrity and prevent further damage. While we actively work to bring phpBB.com back online, we would also like to inform you of the damage that has been done.

If the password to your phpBB.com account is used anywhere else (especially with the same username), we strongly recommend that you change it. Using the same password across multiple sites is not security wise and should not be done under any circumstance. Additionally, you should change your password on phpBB.com, when it becomes available.

The attacker gained entry through the PHPList application and was able to dump a complete backup of the emails on file. He then used the same exploit to access the phpBB.com database. Both the email list from PHPlist and a copy of the phpBB.com users table were then posted publicly.
Read Original Post Here

Sorry didn't know where to post this, but thought it decremental to the site as most admins would have an account there for phpbb help and such with code.
Last edited by Matooba on Thu Feb 05, 2009 4:01 pm, edited 1 time in total.
Image
User avatar
Tural




Conceptionist Acolyte Bloodhound Recreator
Socialist Connoisseur Droplet Scorched Earth
Grunge

Posts: 15628
Joined: Thu Jun 16, 2005 3:44 pm
Location: Lincoln, NE
Contact:

Re: phpbb Users and Passwords Comprimised !!!! Please read

Post by Tural »

To clarify this, because when reading your post it sounded like this was a HM problem:
There is no vulnerability on Halomods, so users do not need to fret over their security here. The issue this is talking about is with an old phpBB modification that was used on the phpBB site.
Matooba





Posts: 186
Joined: Thu Jan 05, 2006 2:51 am
Location: North East U.S.
Contact:

Re: Problem at phpbb.com for users

Post by Matooba »

Changed the topic title to reflect post better. Good point Tural, sorry for inaccurately putting topic title.
Image
Post Reply