Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 27 Dec 2004 20:28:15 -0500 (EST)
From:      "Jerry Bell" <jerry@syslog.org>
To:        estover@nativenerds.com
Cc:        freebsd-security@freebsd.org
Subject:   Re: Found security expliot in port phpBB 2.0.8  FreeBSD4.10
Message-ID:  <2990.24.98.86.57.1104197295.squirrel@24.98.86.57>
In-Reply-To: <34657.24.230.37.14.1104187002.squirrel@24.230.37.14>
References:  <34657.24.230.37.14.1104187002.squirrel@24.230.37.14>

next in thread | previous in thread | raw e-mail | index | archive | help
The update for phpbb came out a while ago, and it looks like the ports
were updated on 11/25/2004.  Have you tried updating the ports?  I think
this is already addressed.

On a side note, I'm suprised you didn't get hit by the worm (unless it
happened before the worm came out).  There is a new worm out now that
attacks some weak php programming, though it's not very widespread.  See
http://www.syslog.org/Article10.phtml for a little more detail.

I don't know if it's a worm or not, but I'm seeing people trying to attack
my site pretty frequently lately.

Best regards & happy holidays,

Jerry
http://www.syslog.org

> I think, there is a neat exploit in the phpbb2.0.8 because I found my home
> page defaced one dark morning. The patch for phpBB is here.
> http://www.phpbb.com/downloads.php
>
> The excerpt of the log is attached.
>
> I believe the link to the described exploit is here.
> http://secunia.com/advisories/13239
>
> The defacement braggen page is here filter to show the exploited FreeBSD
> machines that aneurysm.inc has defaced
> http://www.zone-h.org/en/defacements/filter/filter_defacer=aneurysm.inc/filter_system=FreeBSD/page=1/
> _______________________________________________
> freebsd-security@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to
> "freebsd-security-unsubscribe@freebsd.org"
>




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?2990.24.98.86.57.1104197295.squirrel>