You are not logged in.
- Topics: Active | Unanswered
Pages: 1
#1 2008-05-13 16:44:21
- hcgtv
- Member

- From: Charlotte, NC
- Registered: 2008-05-07
- Posts: 419
- Website
Half-million phpBB boards hijacked
Bert Garcia - When all you have is a keyboard
Offline
#2 2008-05-13 17:02:24
- Lamonte
- Member

- From: MO, USA
- Registered: 2008-05-12
- Posts: 244
- Website
Re: Half-million phpBB boards hijacked
Thats crazy, *goes to phpBB to see what they talking about*
Clean Script - Programming Starting at just $5 | Web Development Blog | Mysql 5 Tutorials & Articles
Clean Script Webforum Powered By Flux (not official until Flux is Final
)
Offline
#3 2008-05-13 17:03:18
- elbekko
- Former Developer

- From: Leuven, Belgium
- Registered: 2008-04-30
- Posts: 1,131
- Website
Re: Half-million phpBB boards hijacked
Only one word applies here: pwned.
Ben
SVN repository for my extensions - The thread
Quickmarks 0.5
“Question: How does a large software project get to be one year late? Answer: One day at a time!” - Fred Brooks
Offline
#4 2008-05-13 17:09:53
- Lamonte
- Member

- From: MO, USA
- Registered: 2008-05-12
- Posts: 244
- Website
Re: Half-million phpBB boards hijacked
LOL..no wonder they are stopping support for phpBB 2 ![]()
Clean Script - Programming Starting at just $5 | Web Development Blog | Mysql 5 Tutorials & Articles
Clean Script Webforum Powered By Flux (not official until Flux is Final
)
Offline
#5 2008-05-13 17:10:50
- Vovochka
- Member
- From: Ukraine
- Registered: 2008-05-10
- Posts: 165
- Website
Re: Half-million phpBB boards hijacked
LOL
By the way, few times I met thoughts that punbb is security unsafe, but there was no word about phpbb's defects
Another people tell about legendary phpbb's bugs.
For about 3 years I'm looking at punbb & phpbb. Well, punbb rocks! For sure! And 1.3 hook system is great, but can become source for vulnerability
Offline
#7 2008-05-13 17:19:13
- hcgtv
- Member

- From: Charlotte, NC
- Registered: 2008-05-07
- Posts: 419
- Website
Re: Half-million phpBB boards hijacked
And 1.3 hook system is great, but can become source for vulnerability
Yes it can, that's why it's a good idea for extensions to be passed through a screening process.
Bert Garcia - When all you have is a keyboard
Offline
#8 2008-05-13 19:08:19
- Lamonte
- Member

- From: MO, USA
- Registered: 2008-05-12
- Posts: 244
- Website
Re: Half-million phpBB boards hijacked
Vovochka wrote:And 1.3 hook system is great, but can become source for vulnerability
Yes it can, that's why it's a good idea for extensions to be passed through a screening process.
Naw, I don't think so since people can't spot bugs off the bat, but "Commercial" mods on the FluxBB site should have some sort of review, but still there is no way to tell if a mod has a vuln or not, and a screening process would take ages to double check over and over and over hence big scripts take few months just to get on the mod database.
Now you might understand what I mean.
Clean Script - Programming Starting at just $5 | Web Development Blog | Mysql 5 Tutorials & Articles
Clean Script Webforum Powered By Flux (not official until Flux is Final
)
Offline
#9 2008-05-13 20:11:35
- Dr.Jeckyl
- Member

- From: :(){:|:&};:
- Registered: 2008-04-30
- Posts: 113
- Website
Re: Half-million phpBB boards hijacked
hcgtv wrote:Vovochka wrote:And 1.3 hook system is great, but can become source for vulnerability
Yes it can, that's why it's a good idea for extensions to be passed through a screening process.
Naw, I don't think so since people can't spot bugs off the bat, but "Commercial" mods on the FluxBB site should have some sort of review, but still there is no way to tell if a mod has a vuln or not, and a screening process would take ages to double check over and over and over hence big scripts take few months just to get on the mod database.
Now you might understand what I mean.
I think the staff here could do it. They're pretty smart around here. ![]()
GroundBranch
Want to learn more? Click me.
Offline
#10 2008-05-13 20:44:15
- Connor
- Former Developer
- Registered: 2008-04-27
- Posts: 1,127
Re: Half-million phpBB boards hijacked
We are going to check code on extensions before hosting them here, although obviously some bugs will get through we can check for obvious security flaws.
Offline
#11 2008-05-13 21:15:52
- Vovochka
- Member
- From: Ukraine
- Registered: 2008-05-10
- Posts: 165
- Website
Re: Half-million phpBB boards hijacked
We are going to check code on extensions before hosting them here, although obviously some bugs will get through we can check for obvious security flaws.
Idea:
Make a quarantine place for mods. These mods can only be downloaded by people with eg 50 posts. And these people (NOT ONLY fluxbb developers) can discuss and give advices to mod writer.
Offline
#12 2008-05-13 21:19:07
- Connor
- Former Developer
- Registered: 2008-04-27
- Posts: 1,127
Re: Half-million phpBB boards hijacked
Connor wrote:We are going to check code on extensions before hosting them here, although obviously some bugs will get through we can check for obvious security flaws.
Idea:
Make a quarantine place for mods. These mods can only be downloaded by people with eg 50 posts. And these people (NOT ONLY fluxbb developers) can discuss and give advices to mod writer.
We have something even better than that planned
I think we'll explain our plans more soon.
Offline
#13 2008-05-14 06:42:25
- Jérémie
- Member

- From: Paris, France
- Registered: 2008-04-30
- Posts: 627
- Website
Re: Half-million phpBB boards hijacked
Vovochka wrote:And 1.3 hook system is great, but can become source for vulnerability
Yes it can, that's why it's a good idea for extensions to be passed through a screening process.
Note: this issue is starting to get to Firefox (and other Mozilla addons).
I haven't heard yet of an extenstion creating voluntarily a security flaw, but there are several extenstion that gather data and send them to the addon creator for commercial use.
Some kind of screening is definitely a good idea.
It a lot of work, but it's quite helpful for the end-user.
Offline
#14 2008-05-14 11:19:51
- Gotipe
- Member
- Registered: 2008-05-10
- Posts: 181
Re: Half-million phpBB boards hijacked
Spooky, these h4xx0rs makes me feel uncomfortable now.
Some weeks ago, I watched Swedish television where they said some webpages had a changed code or something that made visitors automatically load down shit. Don't know details though, but sure enough was that the webpage owners did not know about it. :S One have to keep heads up.
Offline
#15 2008-05-14 11:23:40
- Jérémie
- Member

- From: Paris, France
- Registered: 2008-04-30
- Posts: 627
- Website
Re: Half-million phpBB boards hijacked
One have to keep heads up.
Easy: don't use IE.
Offline
#16 2008-05-14 13:55:46
- sirena
- Member

- From: AU
- Registered: 2008-05-10
- Posts: 172
Re: Half-million phpBB boards hijacked
Easy: don't use IE.
Or Firefox. Or Opera either. Or Safari especially. All also have experienced a long list of vulns this year alone, especially when they are running all jazzed up to support Java, Flash, various BHO's and plug-ins, and extensions and widgets too.
I recommend sticking to Lynx ![]()
Offline
#17 2008-05-14 15:26:10
- Pedro
- Member
- Registered: 2008-05-11
- Posts: 104
Re: Half-million phpBB boards hijacked
wow... this discussion is one day old and nobody said yet: "don't use internet"
Seriously, punbb 1.2 has dozens of mods, i never heard about big security issued cause by them. The code was posted in the forums, discussed and eventually some would point some potential dangers. Sometimes the author or somebody else would come up with a fix, or a warn would be kept in big letters.
Also, it's recommended to the users not to blindly install dozens of extensions. A quick look at the code and other good sense principles are the best securty.
For example, installing an extension with 5000 lines of code, written by some guy that nowbody heard about and which the code has not been minimally tested... that's obviously different than installing an official extension which has been extensively tested and discussed.
Saying that the extension system is a security flaw gate doesn't really means much, it depends on the extensions, in the same way that having a fluxbb forum comes with more security issues than not having one. ( Potato logic )
As for the mais subject in this thread...
Yaix! That's brutal. I suspect phpbb became a huge messy amalgam of features funcionalities spread in the source code in a rather bizarre and obscure way. Unfortunately this news doesn't surprise me ![]()
phpbb definitely went the wrong way, version 3 didn't really measure up to all the ard time version 2 had put into their users.
Last edited by Pedro (2008-05-14 15:26:37)
Offline
#18 2008-05-14 16:35:03
- Gotipe
- Member
- Registered: 2008-05-10
- Posts: 181
Re: Half-million phpBB boards hijacked
No, I don't load down random things anyhow without knowing, ofc, ![]()
Easy: don't use IE.
Then, I am doomed, ![]()
Offline
#19 2008-05-14 16:43:17
- SuperMAG
- Member
- Registered: 2008-05-10
- Posts: 707
Re: Half-million phpBB boards hijacked
wow... this discussion is one day old and nobody said yet: "don't use internet"
Seriously, punbb 1.2 has dozens of mods, i never heard about big security issued cause by them. The code was posted in the forums, discussed and eventually some would point some potential dangers. Sometimes the author or somebody else would come up with a fix, or a warn would be kept in big letters.
Also, it's recommended to the users not to blindly install dozens of extensions. A quick look at the code and other good sense principles are the best securty.
For example, installing an extension with 5000 lines of code, written by some guy that nowbody heard about and which the code has not been minimally tested... that's obviously different than installing an official extension which has been extensively tested and discussed.Saying that the extension system is a security flaw gate doesn't really means much, it depends on the extensions, in the same way that having a fluxbb forum comes with more security issues than not having one. ( Potato logic )
As for the mais subject in this thread...
Yaix! That's brutal. I suspect phpbb became a huge messy amalgam of features funcionalities spread in the source code in a rather bizarre and obscure way. Unfortunately this news doesn't surprise me
phpbb definitely went the wrong way, version 3 didn't really measure up to all the ard time version 2 had put into their users.
thats why the devs will review and check every extension before posting it to the download section ....
Offline
#20 2008-05-14 22:08:43
- foxmask
- Member

- From: France
- Registered: 2008-05-10
- Posts: 20
- Website
Re: Half-million phpBB boards hijacked
phpBB could enter in the guiness book with the record
)))
Offline
#21 2008-05-14 22:24:00
- Felix
- Member
- Registered: 2008-05-13
- Posts: 352
Re: Half-million phpBB boards hijacked
Well, always remember: the more users a software has, the more things appear.
I guess phpBB is one of the most spread board software around and got partially modded very heavily... And many mods of phpBB are crap. They had no hooks and several mods had changes so deep in the phpBB Core that the software couldn't be updated anymore... So instead of deleting the mod and starting again from the bottom, they just let the board run...
And it runs and runs and runs... That is the good side on phpBB... Until the forum is hijacked. The bad side... not directly on phpBB but on the heavily modding. ![]()
Half a million got hijacked and I wonder how many millions are still running.
Offline
#22 2008-05-15 02:40:49
- eric235u
- Member

- From: free software land
- Registered: 2008-05-10
- Posts: 68
- Website
Re: Half-million phpBB boards hijacked
firefox + noscript = pretty secure surfing.
just for fun...
punbb exploits since 2005-03-29 = 5
phpbb exploits since 2005-04-02 = more than a hundred.
from http://milw0rm.com/search.php
![]()
healthfit-pro.com - information and software for fitness professionals
Offline
#23 2008-05-15 02:43:47
- eric235u
- Member

- From: free software land
- Registered: 2008-05-10
- Posts: 68
- Website
Re: Half-million phpBB boards hijacked
any thoughts of having a very low traffic email list for notifying users of known exploits and new version releases? it seems like a good idea.
Last edited by eric235u (2008-05-15 02:44:12)
healthfit-pro.com - information and software for fitness professionals
Offline
#24 2008-05-15 03:05:12
- Smartys
- Former Developer
- Registered: 2008-04-27
- Posts: 3,135
- Website
Re: Half-million phpBB boards hijacked
The point of the hotfix system is that everyone should automatically have the ability to roll out a fix quickly in those cases ![]()
Offline
Pages: 1
