vnpenguin wrote:Hi all,
It's very sad to tell you that our forum (with latest release of PunBB) was hacked last week
Our backup server is compromised. We lossed db with md5 hashed-password. I dont know how they can login into our forum with admin control panel.
Anyone here could confirm me : MD5 hash is hackable ? Admin password in this case is 10 char length with letter + number + special char,...
If you tell me that MD5 hash is not hackable, so where is the cause of our accident ?
Thank you,
Have a look at the war-stories over at the AdminZone about people's forums being hacked, and how, for some possible ideas about the way your site may have been compromised:
http://www.theadminzone.com/forums/foru … y.php?f=24
Read a few of the 'my forum has been hacked' posts to see how others have also been affected using a variety of forum packages (not just pun), and the conclusions they drew.
There are lots and lots of ways your hack could have been done, in short.
Bottom line is: it may be very hard to tell sometimes exactly how the attack was done, esp. if you aren't able to do the forensics properly due to lack of access to logs, poor change management, no baselines etc. But while it can happen to anyone, you can take some steps to reduce the risk of it happening again.