MY PHP BB Forum is being hacked very frequently

Im running a PHPBB Forum it is defaced frequently What sld i do  to stop these hackers ?? How are they able to hack ??
I want to know how we can stop that and How they are doing it ??
abhishek376Asked:
Who is Participating?
 
TolomirConnect With a Mentor AdministratorCommented:
I'm no php expert but this seems to fit for you:

How to Prevent your phpBB Forum from Exploits
http://www.siteground.com/phpbb-security.htm

Tolomir
0
 
elusivetechCommented:
1. You need to upgrade to the latest version of PHPbb

2. You need to make sure your configuration files are protected properly and viewing access to sensitive files such as config.php is revoked to public.

3. You need to change your existing administration password as well as your MY SQL database password because at this point its probably compromised.

4. After you secure it, you will need to subscribe to phpbb mailing list and ensure you are notified of new releases of the message board.  When new release of the software is released make sure you test and upgrade to the latest version.

Since PHPBB is open source and widely used, hackers and script kiddies are constantly working towards in trying to find vulnerabilities to compromise it.

Follow these steps and you will be fine. If you need additional help, just let me know.

Thanks

- Martin
0
 
abhishek376Author Commented:
U asked me to secure everything , thats ok my question was that how to secure ?  My php BB forum is Latest 8.0 through i change my forum passwords regularly it is being defaced and abt sql i fing many logs of ips there and i suspect sql injection in to my site

How are they able to deface my site ??
0
NEW Internet Security Report Now Available!

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out this quarters report on the threats that shook the industry in Q4 2017.

 
elusivetechConnect With a Mentor Commented:
Yes . PHPbb was vulnerable for SQL injection attacks.

8.0? HMM

Latest version is 2.0.21 last I checked.

http://www.phpbb2.de/dload.php?action=category&cat_id=2

Here is the latest patch file.


http://www.phpbb2.de/dload.php?action=file&file_id=824

0
 
Rich RumbleConnect With a Mentor Security SamuraiCommented:
PHPbb has many flaws, you should reinstall the OS from scratch to ensure that there are no backdoors or trojans installed. Apply all the patches you can and read up in PHPbb security. There were 4 new ones last month alone:  http://www.frsirt.com/english/vendor/2713 http://secunia.com/search/?adv_search=1&s=1&search=phpbb&w=1&vuln_title=1&vuln_software_os=1&vuln_bodytext=1&vuln_cve=1&critical%5B%5D=0&impact%5B%5D=0&where%5B%5D=0
There isn't a patch for all of these, note also that not all versions are vulnerable to all these advisories.
You might also look to see if your IIS is fully patched, IIS6 is M$'s best yet, but Apache is better still, and runs on M$ and other OS's
If running IIS5 or less, run the URLScan and IISlockdown http://www.microsoft.com/technet/security/tools/locktool.mspx
-rich
0
 
ahoffmannConnect With a Mentor Commented:
> What sld i do  to stop these hackers ??
you cannot

> How are they able to hack ??
php and applications build with it are know to have countless vulnerabilities, unfortunatelly

> I want to know how we can stop ..
as said above; you cannot stop others

> .. that and How they are doing it ??
as it is a PHP-based web application, they are most likely using flaws there.
As said previously: reinstall your server from scratch, then replace your PHP application by something better.
It's very hard to configure a OS with a web server running PHP 'cause PHP applications have so much programming errors, you may have a look at: http://www.hardened-php.net/ but I guess that this is hard stuff for you to understand.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.