PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
Susann
Moderator


Joined: Dec 19, 2004
Posts: 3143
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Tue Feb 05, 2008 6:37 am Reply with quote Back to top

I was informed today thats better to change my data like password and e-mail address because the website was attacked through brute force or something like that and they said its possible that all passwords and e-mail addresses are stolen.
No, there isn´t a new security hole in phpBB.
Just curious how do I detect when my database is also abused beneed Nuke Sentinel bans.


Last edited by Susann on Tue Feb 05, 2008 2:17 pm; edited 1 time in total
View user's profile Send private message Visit poster's website
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Tue Feb 05, 2008 10:13 am Reply with quote Back to top

Hmm.. its one of those things that you say, good luck. Hopefully no one had any sensitive information in their profiles. You'd probably want to disclose the security breach and have people reauthenticate. One way would be to reset all passwords randomly to temporary passwords and distribute via email.

I'm assuming they got your password hashes, in which case they can possibly forge user and admin cookies. Hard to detect these from valid ones, which is why changing the passwords first would be necessary.
View user's profile Send private message Visit poster's website
Susann
Moderator


Joined: Dec 19, 2004
Posts: 3143
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Tue Feb 05, 2008 3:11 pm Reply with quote Back to top

I believe such things happens often but the registered members are not always informed. Its the second time within several years that I was informed I have to change my data because of such things. Its a criminal conduct and alone with the stolen e-mail addresses they can make money.
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum