Forums

Unfortunately no one can be told what FluxBB is - you have to see it for yourself.

You are not logged in.

#1 2008-05-13 16:44:21

hcgtv
Member
From: Charlotte, NC
Registered: 2008-05-07
Posts: 419
Website

Half-million phpBB boards hijacked


Bert Garcia - When all you have is a keyboard

Offline

#2 2008-05-13 17:02:24

Lamonte
Member
From: MO, USA
Registered: 2008-05-12
Posts: 244
Website

Re: Half-million phpBB boards hijacked

Thats crazy, *goes to phpBB to see what they talking about*

Offline

#3 2008-05-13 17:03:18

elbekko
Former Developer
From: Leuven, Belgium
Registered: 2008-04-30
Posts: 1,131
Website

Re: Half-million phpBB boards hijacked

Only one word applies here: pwned.


Ben
SVN repository for my extensions - The thread
Quickmarks 0.5
“Question: How does a large software project get to be one year late? Answer: One day at a time!” - Fred Brooks

Offline

#4 2008-05-13 17:09:53

Lamonte
Member
From: MO, USA
Registered: 2008-05-12
Posts: 244
Website

Re: Half-million phpBB boards hijacked

LOL..no wonder they are stopping support for phpBB 2 tongue

Offline

#5 2008-05-13 17:10:50

Vovochka
Member
From: Ukraine
Registered: 2008-05-10
Posts: 165
Website

Re: Half-million phpBB boards hijacked

LOL
By the way, few times I met thoughts that punbb is security unsafe, but there was no word about phpbb's defects smile Another people tell about legendary phpbb's bugs.
For about 3 years I'm looking at punbb & phpbb. Well, punbb rocks! For sure! And 1.3 hook system is great, but can become source for vulnerability

Offline

#6 2008-05-13 17:18:56

Meow
Member
From: Taipei, Taiwan
Registered: 2008-05-10
Posts: 672
Website

Re: Half-million phpBB boards hijacked

Lamonte wrote:

LOL..no wonder they are stopping support for phpBB 2 tongue

I think lots of phpBB2 forums aren't the 2.0.23 version.


Enjoy the chosen furry artworks on Chita every day.

Offline

#7 2008-05-13 17:19:13

hcgtv
Member
From: Charlotte, NC
Registered: 2008-05-07
Posts: 419
Website

Re: Half-million phpBB boards hijacked

Vovochka wrote:

And 1.3 hook system is great, but can become source for vulnerability

Yes it can, that's why it's a good idea for extensions to be passed through a screening process.


Bert Garcia - When all you have is a keyboard

Offline

#8 2008-05-13 19:08:19

Lamonte
Member
From: MO, USA
Registered: 2008-05-12
Posts: 244
Website

Re: Half-million phpBB boards hijacked

hcgtv wrote:
Vovochka wrote:

And 1.3 hook system is great, but can become source for vulnerability

Yes it can, that's why it's a good idea for extensions to be passed through a screening process.

Naw, I don't think so since people can't spot bugs off the bat, but "Commercial" mods on the FluxBB site should have some sort of review, but still there is no way to tell if a mod has a vuln or not, and a screening process would take ages to double check over and over and over hence big scripts take few months just to get on the mod database.

Now you might understand what I mean.

Offline

#9 2008-05-13 20:11:35

Dr.Jeckyl
Member
From: :(){:|:&};:
Registered: 2008-04-30
Posts: 113
Website

Re: Half-million phpBB boards hijacked

Lamonte wrote:
hcgtv wrote:
Vovochka wrote:

And 1.3 hook system is great, but can become source for vulnerability

Yes it can, that's why it's a good idea for extensions to be passed through a screening process.

Naw, I don't think so since people can't spot bugs off the bat, but "Commercial" mods on the FluxBB site should have some sort of review, but still there is no way to tell if a mod has a vuln or not, and a screening process would take ages to double check over and over and over hence big scripts take few months just to get on the mod database.

Now you might understand what I mean.

I think the staff here could do it. They're pretty smart around here. tongue


GroundBranch
Want to learn more? Click me.

Offline

#10 2008-05-13 20:44:15

Connor
Former Developer
Registered: 2008-04-27
Posts: 1,127

Re: Half-million phpBB boards hijacked

We are going to check code on extensions before hosting them here, although obviously some bugs will get through we can check for obvious security flaws.

Offline

#11 2008-05-13 21:15:52

Vovochka
Member
From: Ukraine
Registered: 2008-05-10
Posts: 165
Website

Re: Half-million phpBB boards hijacked

Connor wrote:

We are going to check code on extensions before hosting them here, although obviously some bugs will get through we can check for obvious security flaws.

Idea:
Make a quarantine place for mods. These mods can only be downloaded by people with eg 50 posts. And these people (NOT ONLY fluxbb developers) can discuss and give advices to mod writer.

Offline

#12 2008-05-13 21:19:07

Connor
Former Developer
Registered: 2008-04-27
Posts: 1,127

Re: Half-million phpBB boards hijacked

Vovochka wrote:
Connor wrote:

We are going to check code on extensions before hosting them here, although obviously some bugs will get through we can check for obvious security flaws.

Idea:
Make a quarantine place for mods. These mods can only be downloaded by people with eg 50 posts. And these people (NOT ONLY fluxbb developers) can discuss and give advices to mod writer.

We have something even better than that planned smile I think we'll explain our plans more soon.

Offline

#13 2008-05-14 06:42:25

Jérémie
Member
From: Paris, France
Registered: 2008-04-30
Posts: 627
Website

Re: Half-million phpBB boards hijacked

hcgtv wrote:
Vovochka wrote:

And 1.3 hook system is great, but can become source for vulnerability

Yes it can, that's why it's a good idea for extensions to be passed through a screening process.

Note: this issue is starting to get to Firefox (and other Mozilla addons).

I haven't heard yet of an extenstion creating voluntarily a security flaw, but there are several extenstion that gather data and send them to the addon creator for commercial use.

Some kind of screening is definitely a good idea.

It a lot of work, but it's quite helpful for the end-user.

Offline

#14 2008-05-14 11:19:51

Gotipe
Member
Registered: 2008-05-10
Posts: 181

Re: Half-million phpBB boards hijacked

Spooky, these h4xx0rs makes me feel uncomfortable now. tongue Some weeks ago, I watched Swedish television where they said some webpages had a changed code or something that made visitors automatically load down shit. Don't know details though, but sure enough was that the webpage owners did not know about it. :S One have to keep heads up.

Offline

#15 2008-05-14 11:23:40

Jérémie
Member
From: Paris, France
Registered: 2008-04-30
Posts: 627
Website

Re: Half-million phpBB boards hijacked

Gotipe wrote:

One have to keep heads up.

Easy: don't use IE.

Offline

#16 2008-05-14 13:55:46

sirena
Member
From: AU
Registered: 2008-05-10
Posts: 172

Re: Half-million phpBB boards hijacked

Jérémie wrote:

Easy: don't use IE.

Or Firefox. Or Opera either. Or Safari especially. All also have experienced a long list of vulns this year alone, especially when they are running all jazzed up to support Java, Flash, various BHO's and plug-ins, and extensions and widgets too.

I recommend sticking to Lynx smile

Offline

#17 2008-05-14 15:26:10

Pedro
Member
Registered: 2008-05-11
Posts: 104

Re: Half-million phpBB boards hijacked

wow... this discussion is one day old and nobody said yet: "don't use internet"

Seriously, punbb 1.2 has dozens of mods, i never heard about big security issued cause by them. The code was posted in the forums, discussed and eventually some would point some potential dangers. Sometimes the author or somebody else would come up with a fix, or a warn would be kept in big letters.

Also, it's recommended to the users not to blindly install dozens of extensions. A quick look at the code and other good sense principles are the best securty.
For example, installing an extension with 5000 lines of code, written by some guy that nowbody heard about and which the code has not been minimally tested... that's obviously different than installing an official extension which has been extensively tested and discussed.

Saying that the extension system is a security flaw gate doesn't really means much, it depends on the extensions, in the same way that having a fluxbb forum comes with more security issues than not having one. ( Potato logic )

As for the mais subject in this thread...
Yaix! That's brutal. I suspect phpbb became a huge messy amalgam of features funcionalities spread in the source code in a rather bizarre and obscure way. Unfortunately this news doesn't surprise me sad
phpbb definitely went the wrong way, version 3 didn't really measure up to all the ard time version 2 had put into their users.

Last edited by Pedro (2008-05-14 15:26:37)

Offline

#18 2008-05-14 16:35:03

Gotipe
Member
Registered: 2008-05-10
Posts: 181

Re: Half-million phpBB boards hijacked

No, I don't load down random things anyhow without knowing, ofc, tongue

Jérémie wrote:

Easy: don't use IE.

Then, I am doomed, sad

Offline

#19 2008-05-14 16:43:17

SuperMAG
Member
Registered: 2008-05-10
Posts: 707

Re: Half-million phpBB boards hijacked

Pedro wrote:

wow... this discussion is one day old and nobody said yet: "don't use internet"

Seriously, punbb 1.2 has dozens of mods, i never heard about big security issued cause by them. The code was posted in the forums, discussed and eventually some would point some potential dangers. Sometimes the author or somebody else would come up with a fix, or a warn would be kept in big letters.

Also, it's recommended to the users not to blindly install dozens of extensions. A quick look at the code and other good sense principles are the best securty.
For example, installing an extension with 5000 lines of code, written by some guy that nowbody heard about and which the code has not been minimally tested... that's obviously different than installing an official extension which has been extensively tested and discussed.

Saying that the extension system is a security flaw gate doesn't really means much, it depends on the extensions, in the same way that having a fluxbb forum comes with more security issues than not having one. ( Potato logic )

As for the mais subject in this thread...
Yaix! That's brutal. I suspect phpbb became a huge messy amalgam of features funcionalities spread in the source code in a rather bizarre and obscure way. Unfortunately this news doesn't surprise me sad
phpbb definitely went the wrong way, version 3 didn't really measure up to all the ard time version 2 had put into their users.

thats why the devs will review and check every extension before posting it to the download section ....

Offline

#20 2008-05-14 22:08:43

foxmask
Member
From: France
Registered: 2008-05-10
Posts: 20
Website

Re: Half-million phpBB boards hijacked

phpBB could enter in the guiness book with the record wink)))

Offline

#21 2008-05-14 22:24:00

Felix
Member
Registered: 2008-05-13
Posts: 352

Re: Half-million phpBB boards hijacked

Well, always remember: the more users a software has, the more things appear.
I guess phpBB is one of the most spread board software around and got partially modded very heavily... And many mods of phpBB are crap. They had no hooks and several mods had changes so deep in the phpBB Core that the software couldn't be updated anymore... So instead of deleting the mod and starting again from the bottom, they just let the board run...
And it runs and runs and runs... That is the good side on phpBB... Until the forum is hijacked. The bad side... not directly on phpBB but on the heavily modding. wink

Half a million got hijacked and I wonder how many millions are still running.

Offline

#22 2008-05-15 02:40:49

eric235u
Member
From: free software land
Registered: 2008-05-10
Posts: 68
Website

Re: Half-million phpBB boards hijacked

firefox + noscript = pretty secure surfing.

just for fun...

punbb exploits since 2005-03-29 = 5

phpbb exploits since 2005-04-02 = more than a hundred.

from http://milw0rm.com/search.php

tongue


healthfit-pro.com - information and software for fitness professionals

Offline

#23 2008-05-15 02:43:47

eric235u
Member
From: free software land
Registered: 2008-05-10
Posts: 68
Website

Re: Half-million phpBB boards hijacked

any thoughts of having a very low traffic email list for notifying users of known exploits and new version releases?  it seems like a good idea.

Last edited by eric235u (2008-05-15 02:44:12)


healthfit-pro.com - information and software for fitness professionals

Offline

#24 2008-05-15 03:05:12

Smartys
Former Developer
Registered: 2008-04-27
Posts: 3,135
Website

Re: Half-million phpBB boards hijacked

The point of the hotfix system is that everyone should automatically have the ability to roll out a fix quickly in those cases tongue

Offline

Board footer

Powered by FluxBB 1.5.0