I was very surprised when I logged in to my Warning! This site has been hacked. • Index page phpBB3 forum today. Every forum name had been replaced with "you have been hacked" and so on. The hacker seems to have used a moderator's user account (who does not have permissions to edit forum names) to change the details and then delete the log, removing all traces of him.
Now, what I want to ask is: how did the hacker do this, and how can I stop it from happening again? I am the only one (so I thought) with permissions to edit forums, and my password is complex.
Do you have an updated version? Is there any security flaws in the version you are running?
Do you have an easy to guess password?
Check for an updated version of phpbb that might be more secure?
Any chance did you write your password down somewhere?
He said that his password is very complex so I don't think it would be guessed or used a script to test a lit of passwords.
Make security holes in phpBB?
jQuery Selectors Tutorial - jQuery Striped Table tutorial - jQuery Events - jQuery Validation
Sorry if I don't post as often as I did, I'll try to get here as much as possible! I'm working my bum off to get this scholarship and other stuff!
What was your password. try again by using that password or use some smiler password as if you forgot password...it may be possible?? i am sure if your password were complexity you can't hacked.
Security leeks.
jQuery Selectors Tutorial - jQuery Striped Table tutorial - jQuery Events - jQuery Validation
Sorry if I don't post as often as I did, I'll try to get here as much as possible! I'm working my bum off to get this scholarship and other stuff!
Issue Fixed
OK, here was the problem. It is phpBB's permissions settings (I know how much you hate them John).
Basically, phpBB has separate permissions for groups, users, moderators, and individual forums. It gets so confusing. What happened was: I allowed a certain action for a member, but it ended up giving the user full admin permissions. He took advantage of this and edited the forum names/title.
The "hacker" turned out to be my good friend from school, playing a joke. Yawn.
Some friend he is... :?
There are currently 1 users browsing this thread. (0 members and 1 guests)
Bookmarks