<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Following the White Rabbit Blog : php</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/php/default.aspx</link><description>Tags: php</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>News Flash: phpBB Massive Hack</title><link>http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/2008/05/13/News-Flash_3A00_-phpBB-Massive-Hack.aspx</link><pubDate>Tue, 13 May 2008 15:42:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:77204</guid><dc:creator>Rafal Los</dc:creator><slash:comments>3</slash:comments><description>&lt;p&gt;ComputerWorld is running &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9084991&amp;amp;source=NLT_PM&amp;amp;nlid=8" title="ComputerWorld Article (phpBB Hacks)"&gt;an article&lt;/a&gt; from Paul Ferguson of TrendMicro claiming that there is a massive hack going on as you read this - via the phpBB bulletin-board software.&amp;nbsp; Truth be told, phpBB has been known to be bug-ridden over the years (simply Google &amp;quot;phpBB vulnerability&amp;quot; and you&amp;#39;ll get more than you wanted) but I believe that these have come to a boiling point now.&amp;nbsp; If it&amp;#39;s actually true, the number of site that was hacked stands at ~500,000, it would point to a massive problem within phpBB&amp;#39;s code which likley hasn&amp;#39;t been disclosed yet.&lt;/p&gt;
&lt;p&gt;What worries me is not that these sites are being hacked (because this is a &amp;quot;normal&amp;quot; occurrence these days) but that they&amp;#39;re increasingly effective.&amp;nbsp; While a half-million web sites being broken into isn&amp;#39;t something to sound the alarm over - and this is truly a sad commentary on the state of web security today - the precision and effectiveness of these types of attacks is scary.&amp;nbsp; Furthermore, the &amp;quot;drive-by&amp;quot; installations of malware, trojans and other unwanted stuff on your computer is the stuff that security managers worry about at night.&amp;nbsp; Just think of the amount of data that a half-million key loggers can pull?&amp;nbsp; Think of the potential fallout of having to re-load (because cleaning isn&amp;#39;t possible most of the time) every machine at your office... the possibility boggles the mind.&lt;/p&gt;
&lt;p&gt;What comes out in incidents like this, and sadly people still do not understand, is that an insecure web application/site does more than just possibly damage the host.&amp;nbsp; A vulnerable site leaves its visitors vulnerable, which sets off a chain of reactions that resonates back into the CISO&amp;#39;s office at any company that allows its users to browse the Internet.&amp;nbsp; More on this in a future post.&lt;/p&gt;
&lt;p&gt;While I know it&amp;#39;s rather un-common to have a php-facing application like this in an entierprise - it&amp;#39;s definitely not impossible so I felt like I needed to notify and warn you readers.&amp;nbsp; More as information comes in... if it comes in.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=77204" width="1" height="1"&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/phpBB/default.aspx">phpBB</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/hack/default.aspx">hack</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/rafal/archive/tags/php/default.aspx">php</category></item></channel></rss>