NYCPHP Meetup

NYPHP.org

[nycphp-talk] Message Boards, Phorum

Oktay Altunergil nyphp at altunergil.com
Fri May 31 07:30:44 EDT 2002


Don't make it a bad forum :)

Oktay


PS: please note that they were hacked using an exploit that was discovered and fixed at an earlier release. I don't know if this means that they've fixed the exploit after the hack or if they hadn't applied their own security fixes. I sure hope it's the prior.

On Fri, 31 May 2002 10:51:51 -0400
Jim Musil <jim at nettmedia.com> wrote:

> 
> 
> From Phorum.org...
> 
> Phorum.org Hacked
> Category: Web Site News    Written by brianlmoon at 8:23pm on May 19, 2002
> 
> Yes, the phorum.org server was hacked using the known and fixed security
> bugs in Phorum 3.3.2a and before. The good news is that we did take some
> precautions and all that could be done is to delete the files in the web
> dir. The bad news is that the language files and our past poll results are
> gone. The irony is that I had a script ready to go that would backup all
> that stuff. I was waiting until tonight to put it in.
> 
> Current Phorum users should know that anybody should upgrade if at all
> possible. If you used the secure script or followed the install instructions
> to the letter, you are probably safe. All of the files used in this hack
> would be protected by the .htaccess files that the secure script creates.
> 
> If you have a language file, please upload it.
> 
> 
> 



More information about the talk mailing list