Cotton Rohrscheib

The Cotton Club Blog & Podcast

  • Home
  • Bio
    • Resume
  • Blog
    • Faith & Family
    • Marketing & Tech
    • Farm & Business
    • Entertainment
    • Health & Wellness
    • Urban Farming
    • Weekend Projects
  • Media
    • Newsletter
    • Photo Galleries
    • Instagram Feed
    • Video Archives
    • Podcasts
    • Music Playlists
  • Books
  • Connect
    • Rohrscheib Capital
    • Disclaimer
    • Privacy Policy
You are here: Home / Marketing & Tech / Alleged phpBB Hack

Alleged phpBB Hack

February 6, 2009 by Cotton Rohrscheib 1 Comment

If you are unfortunate enough to have a bunch of PHPBB installations on your servers you should probably check out this post that my server admin passed along to me this morning. 

PHPBB has been risky business for a while in my opinion, we have weened most of our clients away from PHPBB over the years due to random defacements and new vulnerabilities that popup every time you turn around.  There are however some good alternatives to PHPBB on the market, and even some that are open-sourced.

A vulnerability in the PHPlist newsletter manager, which was publicly disclosed in mid-January but not fixed until two weeks later, allowed an attacker to access critical files on phpBB.com, the person claimed over the weekend.

In a post on Blogger on Saturday, a person who claims to have breached the Web site of open-source online community software phpBB gave a detailed account of how he did it. Using a vulnerability in PHPlist publicly disclosed on January 14, the attacker gained access to the password and configuration files for the server, according to the post. The attack occurred before the PHPlist developers issued a patch for the problem on January 29.

"So I login and see what I can come across, wow 400,000 registered emails, I’m sure that will go quick on the black market, sorry people but expect a lot of spam," the self-proclaimed attacker wrote.

The incident matches the description of the attack posted by administrators of phpBB.com on Monday.

"The attacker gained entry through the PHPList application and was able to dump a complete backup of the emails on file," the group stated. "He then used the same exploit to access the phpBB.com database. Both the email list from PHPlist and a copy of the phpBB.com users table were then posted publicly."

The attack is not the first time that an open-source project’s developers have faced a hacker. In 2002, the phpBB forum was taken offline after vandals defaced the site. In 2001, Apache and Sourceforge were both defaced by a group known as Fluffy Bunny, whose leader was arrested two years later. And, in 2003, the GNU Project acknowledged that hackers had access to their files servers for months.

The phpBB group recommended that members of the list that have reused their passwords on other Web site immediately change their credentials.

"Using the same password across multiple sites is not security wise and should not be done under any circumstance," the phpBB group said. "Additionally, you should change your password on phpBB.com, when it becomes available."

As of Thursday morning, the phpBB.com was still down for maintenance.

If you have tips or insights on this topic, please contact SecurityFocus.

Alleged attacker flaunts details of phpBB hack

Share this post on:

  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on X (Opens in new window) X
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Pinterest (Opens in new window) Pinterest

Related

About Cotton Rohrscheib

The Cotton Club is a monthly podcast hosted by me, Cotton Rohrscheib. I'm a 52 year old entrepreneur w/ ADHD, OCD (and now AARP) that refuses to grow up as I grow old. I have collaborated and invested in hundreds of projects throughout my career in multiple industries such as; technology, healthcare, and agriculture. I also have 25 years experience in the marketing industry as a co-founder of an award-winning advertising agency. I will undoubtedly cover a wide variety of topics on my podcast while sharing some really crazy stories and situations that I've been fortunate to witness firsthand. I also have a book coming out in 2025 titled, "Mistakes were Made"

Please Drop Your Questions or CommentsCancel reply

Let’s Connect

  • Email
  • Facebook
  • Instagram
  • LinkedIn
  • Twitter

Recent Updates

  • EP:032 – Cotton Rohrscheib & Diana DeHart
  • Challenges & Opportunities Going into 2025
  • Find us at the 2025 Arkansas Women in Agriculture Conference in Hot Springs, Arkansas
  • Be Sure to Checkout FBN’s Farmers First™  Crop Nutrition & Adjuvant Lineup for 2025
  • What we all need in Dark Times…

Blog Categories

  • Blog (419)
  • Entertainment (376)
  • Faith & Family (147)
  • Farm & Business (288)
  • Health & Wellness (33)
  • Marketing & Tech (584)
  • Podcasts (31)
  • Urban Farming (20)
  • Weekend Projects (1)

Listen & Subscribe

Blog Archives

Join the Cotton Club!

 

Content Copyright: 2001-2025
Cotton Rohrscheib | Rohrscheib Capital