We help IT Professionals succeed at work.

We've partnered with Certified Experts, Carl Webster and Richard Faulkner, to bring you a podcast all about Citrix Workspace, moving to the cloud, and analytics & intelligence. Episode 2 coming soon!Listen Now

x

MY PHP BB Forum is being hacked very frequently

abhishek376
abhishek376 asked
on
Medium Priority
585 Views
Last Modified: 2010-04-11
Im running a PHPBB Forum it is defaced frequently What sld i do  to stop these hackers ?? How are they able to hack ??
I want to know how we can stop that and How they are doing it ??
Comment
Watch Question

1. You need to upgrade to the latest version of PHPbb

2. You need to make sure your configuration files are protected properly and viewing access to sensitive files such as config.php is revoked to public.

3. You need to change your existing administration password as well as your MY SQL database password because at this point its probably compromised.

4. After you secure it, you will need to subscribe to phpbb mailing list and ensure you are notified of new releases of the message board.  When new release of the software is released make sure you test and upgrade to the latest version.

Since PHPBB is open source and widely used, hackers and script kiddies are constantly working towards in trying to find vulnerabilities to compromise it.

Follow these steps and you will be fine. If you need additional help, just let me know.

Thanks

- Martin

Author

Commented:
U asked me to secure everything , thats ok my question was that how to secure ?  My php BB forum is Latest 8.0 through i change my forum passwords regularly it is being defaced and abt sql i fing many logs of ips there and i suspect sql injection in to my site

How are they able to deface my site ??
Administrator
CERTIFIED EXPERT
Top Expert 2005
Commented:
I'm no php expert but this seems to fit for you:

How to Prevent your phpBB Forum from Exploits
http://www.siteground.com/phpbb-security.htm

Tolomir

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
Yes . PHPbb was vulnerable for SQL injection attacks.

8.0? HMM

Latest version is 2.0.21 last I checked.

http://www.phpbb2.de/dload.php?action=category&cat_id=2

Here is the latest patch file.


http://www.phpbb2.de/dload.php?action=file&file_id=824

Rich RumbleSecurity Samurai
CERTIFIED EXPERT
Top Expert 2006
Commented:
PHPbb has many flaws, you should reinstall the OS from scratch to ensure that there are no backdoors or trojans installed. Apply all the patches you can and read up in PHPbb security. There were 4 new ones last month alone:  http://www.frsirt.com/english/vendor/2713 http://secunia.com/search/?adv_search=1&s=1&search=phpbb&w=1&vuln_title=1&vuln_software_os=1&vuln_bodytext=1&vuln_cve=1&critical%5B%5D=0&impact%5B%5D=0&where%5B%5D=0
There isn't a patch for all of these, note also that not all versions are vulnerable to all these advisories.
You might also look to see if your IIS is fully patched, IIS6 is M$'s best yet, but Apache is better still, and runs on M$ and other OS's
If running IIS5 or less, run the URLScan and IISlockdown http://www.microsoft.com/technet/security/tools/locktool.mspx
-rich
> What sld i do  to stop these hackers ??
you cannot

> How are they able to hack ??
php and applications build with it are know to have countless vulnerabilities, unfortunatelly

> I want to know how we can stop ..
as said above; you cannot stop others

> .. that and How they are doing it ??
as it is a PHP-based web application, they are most likely using flaws there.
As said previously: reinstall your server from scratch, then replace your PHP application by something better.
It's very hard to configure a OS with a web server running PHP 'cause PHP applications have so much programming errors, you may have a look at: http://www.hardened-php.net/ but I guess that this is hard stuff for you to understand.
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.