|
|
Hackers Hijack A Half-million Sites: Phpbb Forum Users Must Read | ||
Discussion by Saint_Michael with 10 Replies.
Last Update: March 14, 2009, 11:45 pm | |||
![]() |
|
|
As for how this process is done it is pretty simple:
QUOTE
Visitors to a hacked site are redirected through a series of servers, some clearly compromised themselves, until the last in the chain is reached; that server then pings the PC for any one of several vulnerabilities, including bugs in both Microsoft Corp. 's Internet Explorer and RealNetworks Inc. 's RealPlayer media player. If any of the vulnerabilities is present, the PC is exploited and malware is downloaded to it.So I if your one of those heavy forum modifiers you better want to make sure the holes and patches are fixed or your website will be constantly compromise and what not. So you may want to get a hold of phpbb support or check out hte forms to see what is up with this problem and finding out how it can be fixed.
SOURCE
And anyone who hacks to upload malicious software is really just a wussy. It's terrorism behind the safety of their closed doors.
QUOTE
That makes me glad that I am currently not running a forum because I generally would use PHPBB but I had 3.0 before. I guess I will have to switch to SMF or something else free unless I pay the $100 so I can purchase Invision. Good luck to all of those running PHPBB.OOps thats me lolz better go try fix it or get another forum =[
I also asked one of my friends to read through its code and there was nothing there he considered dangerous.
I do have MODs installed, but only simple ones that won't compromise the security of my site.
But as alwways there is also other possability and that is that they are not hacking those forums but merely using some service that is generating forums and subdomaines you knwo what I mean those free services that offer forum and subdomain. So what might have happened is that they have hacked some and such service and then changed code behind it so that some of the users would get redirected and voala you've got yourself several thousands slave computers. Easy doesn't it.
Good Luck everyone
But I will still prefer PHPBB against any other forum probably for some time in the future. Also I have it set up though there is no any activity it is good for experimenting. http://forum.zedsi.com
As mentioned in the report the attacks have affected only IIS, that is windows servers. So nowadays people who host projects or sites in OpenSource languages especially PHP, Java, Python or Ruby host only on Linux Servers, so this threat will have no impact on them.
But still it is always advisable that you keep your softwares updated and patched.
For months my computer at 70.113.62.18 has been under daily browser DNS attack, reversals of search, and statements with Xoftspy that your SITE is hijacked, and its placing Antispyware into quarantine lasted there only as long as it takes to run a new scan. Malwareadbytes could not block it and it is rated SEVERE RISK of the highest level meaning the hijackers were in control of redirects thru browser IEX8 completely. I also run Windows Defender, Regcure,Stopzilla and PC to simply block this controlling trojan malware preventing normal operations at my primary site of www.Carcommtelecom.Com Any assistance, ideas or information that will correct this problem will be greatly appreciated.
-question by J Carrington
So from that day till now i have my PhPBB2 forum stormed by spammers , by storming what i mean here is that they just create fake accounts in hundreds
I also tried blocking their IP address from cpanel. Still they come
Similar Topics:
Free Forum Hosting With No Annoying...
Phpbb Mods That You Should Get For ...
Trap17 And Forum Hosting Question
Srizbi Becomes World's Largest Botnet (0)
|
(4) Paypal Scam in French
|
Loading...
HOME 






