hacked the same way yesterday 18:06 french time.
I come here a bit late but send my info anyway :
I were running 1.2.6 and I now just applied all CodeXP patches ( thanks for your fast patches, CodeXP
some infos I gathered :
added data in db :
INSERT INTO `punbb_config` VALUES ('o_board_title','HACKED BY ALTAN');
INSERT INTO `punbb_config` VALUES ('o_board_desc','AÇIKLAR KAPANMADIKÇA BEN HEP BURDAYIM');
and :
INSERT INTO `punbb_users` VALUES (4,32000,'Mathusalem','7621e34ef49d97094c9d85248312414e6ca6dfc2','desktop@noos.fr',NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,0,NULL,NULL,NULL,1,1,0,1,1,1,1,1,1,'French','Mercury',0,NULL,1120570925,'84.96.34.102',1120570925,NULL,NULL,NULL);
INSERT INTO `punbb_users` VALUES (5,4,'coco','4d8ec4de1c6571dbfbd8a720dae4224cbc5488a1','flo-flo@yandex.ru',NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,0,NULL,NULL,NULL,1,1,0,1,1,1,1,1,1,'French','Mercury',0,NULL,1121349686,'83.157.145.200',1121361244,NULL,NULL,NULL);
INSERT INTO `punbb_users` VALUES (6,1,'123','8eb5e49487b969d8b89bf1c41a8cfd4bbb65b4d5','e_m_re@hotmail.com',NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,0,NULL,NULL,NULL,1,1,0,1,1,1,1,1,1,'French','Mercury',0,NULL,1124812372,'81.214.28.118',1124813177,NULL,NULL,NULL);
( 32000 group for me too but two other users were created after )
created in cache directory :
64 jui 22 06:20 cache_bans.php
3663 aoû 23 18:06 cache_config.php
418 aoû 23 18:05 cache_quickjump_1.php
418 aoû 23 18:05 cache_quickjump_2.php
418 aoû 23 18:05 cache_quickjump_3.php
418 aoû 23 18:05 cache_quickjump_4.php
418 aoû 23 18:05 cache_quickjump_5.php
418 aoû 23 18:05 cache_quickjump_6.php
530 jui 22 06:18 cache_ranks.php
60 jan 11 2005 .htaccess
63 jan 11 2005 index.html
those cache_quickjump things seem to be part of the exploit
installed plugins :
drwxr-xr-x 3 apache neonet 4096 jui 22 06:14 ./
drwxrwxr-x 12 apache neonet 4096 aoû 24 11:18 ../
-rw-r--r-- 1 apache neonet 5080 jan 26 2005 AMP_Example.php
-rw-rw-r-- 1 apache neonet 16942 fév 28 21:49 AMP_Global_topic.php
-rw-rw-r-- 1 apache neonet 4354 jui 22 06:11 AMP_Global_topic.zip
-rw-rw-r-- 1 apache neonet 6636 fév 7 2005 AP_Broadcast_Email.php
-rw-rw-r-- 1 apache neonet 2273 jui 22 06:11 AP_Broadcast_Email.zip
-rw-rw-r-- 1 apache neonet 4818 mai 12 23:57 AP_Clear_Cache.php
-rw-rw-r-- 1 apache neonet 1460 jui 22 06:11 AP_Clear_Cache.zip
-rw-rw-r-- 1 apache neonet 25359 avr 5 17:25 AP_DB_management.php
-rw-rw-r-- 1 apache neonet 8027 jui 22 06:11 AP_DB_management.zip
-rw-rw-r-- 1 apache neonet 5731 fév 22 2005 AP_Languages_and_styles.php
-rw-rw-r-- 1 apache neonet 2053 jui 22 06:11 AP_Languages_and_styles.zip
-rw-rw-r-- 1 apache neonet 5637 mai 24 16:01 AP_Merge_Forums.php
-rw-rw-r-- 1 apache neonet 1953 jui 22 06:11 AP_Merge_Forums.zip
drwxrwxr-x 3 apache neonet 4096 jan 15 2005 AP_News_Generator/
-rw-rw-r-- 1 apache neonet 7819 jan 26 2005 AP_News_Generator.php
-rw-rw-r-- 1 apache neonet 3145 jui 22 06:11 AP_News_Generator.zip
-rw-rw-r-- 1 apache neonet 12774 fév 28 21:20 AP_User_management.php
-rw-rw-r-- 1 apache neonet 4151 jui 22 06:11 AP_User_management.zip
-rw-rw-r-- 1 apache neonet 2961 fév 3 2005 AP_Version_Changer.php
-rw-rw-r-- 1 apache neonet 1546 jui 22 06:11 AP_Version_Changer.zip
-rw-r--r-- 1 apache neonet 63 jan 11 2005 index.html
I now refuse to host phpbb forums for I saw too much of this problems, and ask my users to prefer punbb, thank you all for this forum and fast reaction, this problem and fast answers keep me preferring punbb and human understandable well written code ( thank you clean coders )
Seems we need a 1.2.7 release soon nope ?
What about using http://punbb.org/forums/extern.php?acti … amp;fid=48 RSS Feed so any punbb admin sees new release immediatelyin a punbb ?
Another important ( but probably much more difficult to code one ;( would be to have online punbb upgrade like webmin does it ( searching for last version, downloading, verifying md5sum/gpg key if necessary, installing new version )
Last thing, on http://punbb.org/downloads.php I couldn't find md5sums for zip/gz files nor gnup sign ;(
Would you add them so anyone can verify md5 or pgp sign ?
Hopes my thoughts can help.
If you ever need hosting, mirror, rss feed bouncer . . . just ask me