phpBB Forum Down After Defacement 49
kv9 writes "The phpBB forum has been closed down after the host was cracked into, apparently because of an AWStats hole. Several blogs have been attacked using the same method. Commentary on Netcraft, The Reg and SecurityFocus"
Re:Meanwhile (Score:5, Informative)
It says they write more careful--or less widespread--perl.
The awstats exploit that was used here makes use of poorly written perl that failed to validate user input. Of course, had you read the article, you would know that.
Re:Meanwhile (Score:1)
As an IT professional, it puts me in a constant state of amazement when I hear about yet another buffer overrun.
Re:Lies, damn lies, pure fud (Score:1)
Okay, smartarse, show me just ONE SENTENCE in his post where he made any comment that implys that Perl is given to buffer overflows.
No, tell you what, I'll save you the trouble:
Since you appear to be unable to parse this perf
Re:Lies, damn lies, pure fud (Score:1)
Re:Meanwhile (Score:4, Insightful)
Re:Meanwhile (Score:1)
Course, I shouldn't really knock it - I'm not a programmer (I just make things go).
Re:Meanwhile (Score:2, Informative)
OT But... (Score:2)
Not phpBB -- Just their server. (Score:5, Informative)
Worms then.... (Score:1, Interesting)
its always interested me, from the time my works php site was over run via a googling worm.
And how you always hear that it takes xhrs after a flaw is found, for someone to start using it.
[tt] Learn how to patch! (Score:1)
Re:They had it coming (Score:1, Insightful)
Many vulnerable AWStats sites on google (Score:2, Informative)
AWStats is a very popular tool, google returns likely 4,490 users. This could be as bad as one of the old ISS vulnerabilities. With any luck, the publicity generated by incidents like this one will be a warning to those still running vulnerable version.
Re:Many vulnerable AWStats sites on google (Score:1)
What's wrong with the International Space Station?
The new 'underbelly' of IT.... (Score:1)
I'm not sure what the answer is, but with the diversity in my network I could spend a whole day each week looking for issues on the services I run...
Re:The new 'underbelly' of IT.... (Score:2)
How long (Score:1)
What? (Score:1)
Fucking Rediculious (Score:2)
*shakes head* (Score:2, Insightful)
It's actually throwing a bad light on perl developers (and I am one, so I'm not flaming here) that they can't even be bothered reading even the _summary_ and see it was the perl function open() in AWstats that got used to exploit the server, not a php script.
Personally, I code in perl and php. I use whichever's right for the task, and like 'em both.
Oh, and I co