• NOW LIVE! Into the Woods--new character species, eerie monsters, and haunting villains to populate the woodlands of your D&D games.

Hey, Randomlingers...

randomling said:
The bad news: I still have no idea what really happened, though it looks like somebody just went into my web-hosting account and changed the HTML of all the index pages.

I found this on rpg.net:
From: "Jonathan Glass" - Find messages by this author
Date: Tue, 21 Dec 2004 14:13:11 -0500
Local: Tues, Dec 21 2004 11:13 am
Subject: RE: [Ring-of-Fire] Possible apache2/php 4.3.9 worm

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

Risk:

A new PHP worm is spreading, defacing web sites running
phpPBB. This worm overwrites all .php and .asp and .html files which
are writable to the user under which Apache is running, and replaces
their contents with "This site is defaced!!!" NeverEverNoSanity in
bold red.

Mitigation:

If you are running phpBB, please download the latest version
(2.0.11) or follow the workaround on the following site:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=248046


The 2.0.11 Version has been available since November 18, 2004. Here
is the release:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240636

Technical Information:

For more information on the worm, please see the following.

http://www.f-secure.com/weblog/
(quoted from f-secure.com)
 

log in or register to remove this ad

Thanks, Darkness. It looks like that's what we've been hit with here.

Does anybody happen to know if it affects the database or just goes in and affects files? I'm not sure, and I'd hate to think we'd lost posts or files, although it doesn't look like we have.
 

Our condolences, ladies and gents. I'm just glad to hear you didn't lose your site history.

Feel free to hang here as long as you need, though! :)
 

OMG. According to that one security site linked to above, tens of thousands of php boards have apparently been hacked. :eek:
randomling said:
Does anybody happen to know if it affects the database or just goes in and affects files? I'm not sure, and I'd hate to think we'd lost posts or files, although it doesn't look like we have.
I followed some links, to no avail. I then checked out another php board I know, the Forge. According to one of their admins, they too got hacked last night but lost nothing. Fingers crossed that the same is true for your site as well. :)
 

Darkness said:
OMG. According to that one security site linked to above, tens of thousands of php boards have apparently been hacked. :eek:
I followed some links, to no avail. I then checked out another php board I know, the Forge. According to one of their admins, they too got hacked last night but lost nothing. Fingers crossed that the same is true for your site as well. :)
Glad to know the Forge is all right. Looks like we should be OK too. In any case, I'll know within half an hour or so.

And thanks, Henry! Y'know, you should stop by, sometime. :)
 





rassin frassin SOB's... glad to hear you've gotten everything up allright again... i'll be back to visit sooner or later. ;)
 

Into the Woods

Remove ads

Top