phpBB - update it now!
If you are running phpBB forums and haven't patched it recently you will want to do that now. I noticed that someone had exploited a vulnerability in my forum:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513
I have been watching them and am currently tracking them down and plan on taking action against them. Just a warning, patch your board if you haven't done so recently! I went ahead and upgraded the whole thing to 2.0.11 (via patch files).
Here a lot of snot nosed CeNsOrEd can be found:
http://forum.zone-h.org/search.php?sear ... ords=phpbb
And it would appear that at least for a while this site must have appeared here:
http://zone-h.com/defacements/onhold
Still tracking and decoding activity from at least as far back as 22 Nov which appears to be where the activity started. Almost all hits came out of Brazil from several different DSL connections:
200.117.34.137
200.138.70.151
200.161.250.232
200.162.208.31
200.162.230.113
200.175.26.138
200.175.84.82
200.181.213.251
200.199.131.221
200.199.184.227
200.199.25.195
200.203.110.179
200.203.166.61
200.203.35.32
200.206.164.44
200.207.114.17
200.216.15.58
200.217.33.71
200.96.22.32
201.0.73.35
201.0.73.83
201.13.224.52
201.9.182.192
203.81.192.58
211.157.36.9
81.192.249.104
I'm decoding the system() calls they made right now. I know a few tag files were dropped in my forum directory which wouldn't have been possible had I had set proper permissions on that directory, duh! Several other commands were run and information gathered. I even had to translate a little Portuguese! I'll get it all traced out. I can't believe I didn't notice it earlier. I had some indicators that I had ignored at the beginning. I'll look at my alerts a little more closely from now on.
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513
I have been watching them and am currently tracking them down and plan on taking action against them. Just a warning, patch your board if you haven't done so recently! I went ahead and upgraded the whole thing to 2.0.11 (via patch files).
Here a lot of snot nosed CeNsOrEd can be found:
http://forum.zone-h.org/search.php?sear ... ords=phpbb
And it would appear that at least for a while this site must have appeared here:
http://zone-h.com/defacements/onhold
Still tracking and decoding activity from at least as far back as 22 Nov which appears to be where the activity started. Almost all hits came out of Brazil from several different DSL connections:
200.117.34.137
200.138.70.151
200.161.250.232
200.162.208.31
200.162.230.113
200.175.26.138
200.175.84.82
200.181.213.251
200.199.131.221
200.199.184.227
200.199.25.195
200.203.110.179
200.203.166.61
200.203.35.32
200.206.164.44
200.207.114.17
200.216.15.58
200.217.33.71
200.96.22.32
201.0.73.35
201.0.73.83
201.13.224.52
201.9.182.192
203.81.192.58
211.157.36.9
81.192.249.104
I'm decoding the system() calls they made right now. I know a few tag files were dropped in my forum directory which wouldn't have been possible had I had set proper permissions on that directory, duh! Several other commands were run and information gathered. I even had to translate a little Portuguese! I'll get it all traced out. I can't believe I didn't notice it earlier. I had some indicators that I had ignored at the beginning. I'll look at my alerts a little more closely from now on.