Joined: Dec 19, 2004 Posts: 3143 Location: Germany:Moderator German NukeSentinel Support
Posted:
Tue Feb 05, 2008 6:37 am
I was informed today thats better to change my data like password and e-mail address because the website was attacked through brute force or something like that and they said its possible that all passwords and e-mail addresses are stolen.
No, there isn´t a new security hole in phpBB.
Just curious how do I detect when my database is also abused beneed Nuke Sentinel bans.
Last edited by Susann on Tue Feb 05, 2008 2:17 pm; edited 1 time in total
Hmm.. its one of those things that you say, good luck. Hopefully no one had any sensitive information in their profiles. You'd probably want to disclose the security breach and have people reauthenticate. One way would be to reset all passwords randomly to temporary passwords and distribute via email.
I'm assuming they got your password hashes, in which case they can possibly forge user and admin cookies. Hard to detect these from valid ones, which is why changing the passwords first would be necessary.
Joined: Dec 19, 2004 Posts: 3143 Location: Germany:Moderator German NukeSentinel Support
Posted:
Tue Feb 05, 2008 3:11 pm
I believe such things happens often but the registered members are not always informed. Its the second time within several years that I was informed I have to change my data because of such things. Its a criminal conduct and alone with the stolen e-mail addresses they can make money.
View next topic View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum