Feb
08
2009
3

phpBB Weekly #097: Full Coverage of phpBB.com Outage and Cracked CAPTCHA

Audio clip: Adobe Flash Player (version 9 or above) is required to play this audio clip. Download the latest version here. You also need to have JavaScript enabled in your browser.

Download MP3 Episode (99.8 MB)

Episode Duration: 1:49:01
On This Episode: Douglas Bell (Fountain of Apples), David Lewis (Highway of Life), Phil Crumm (iWisdom), Josh Woody (A_Jelly_Doughnut), Ashley Pinner (NeoThermic), and Micheal Cottingham (Techie-Micheal)

Sponsor: Online meetings made easy. Try GotoMeeting FREE for 30 days! www.gotomeeting.com/techpodcasts/

The phpBB community suffered a double-whammy this week: a hack and crack of a PHPList vulnerability (NOT a phpBB vulnerability) led to an extended outage of phpBB.com since last Saturday, and the current phpBB3 CAPTCHA (as of 3.0.4) was formally cracked, causing a significant and sudden spike in spam registrations on boards starting around the middle of the week. In this special episode, David and Douglas are joined by Phil Crumm (iWisdom), Support Team Member; Josh Woody (A_Jelly_Doughnut), MOD Team Member; Ashley Pinner (NeoThermic), Styles Team Member; and Micheal Cottingham (Techie-Micheal), Security Expert and former team member.

During this episode, we learn a number of new details about the zero-day exploit that caused the phpBB.com outage, and that also explain the reasons why it has taken so long for the teams to clean up the damage and restore the site, as well as how herculean this task really is. We also discuss some of the details of the zero-day exploit in PHPList, and some of the coding practices in PHPList that allowed these kinds of security exploits to take place. Micheal also shares a bit of his expertise on security policy and gives us a bit of an outline for what phpBB will do and other websites should do to ensure that they stay secure and avoid these kinds of attacks.

However, the most critical repercussion from this attack as far as users are concerned is the security of their passwords, particularly if they have not logged into phpBB.com since before March 2007 (which was when phpBB.com was updated to phpBB3). Due to an inferior hashing technique used by phpBB2, user passwords that have not been changed or used on phpBB.com since the phpBB2 days have been brute-forced, read, and published publicly by the attacker. Interestingly enough, an analysis of the passwords have shown that the most popular passwords on the list will poor throwaway passwords such as “password” and “123456″. We discuss in great detail the importance of having a very secure, hard to guess/remember password, changing it frequently, and (if possible) using an encrypted password manager such as 1Password. Speaking of which, the teams highly recommend that if you share any of the passwords that you have used on any of the parts of phpBB.com (forum, wiki, code forge, etc.), you should change them just in case, as well as changing your phpBB.com password as soon as it comes back online.

We then chat about the cracking of the phpBB3 CAPTCHA, which has caused a stir over a massive spike in spam registrations on phpBB boards. Interestingly enough, the teams were actually pleasantly surprised that the CAPTCHA lasted as long as it did until it got cracked (nearly two years!); pretty good for a CAPTCHA generated by open-source, freely downloadable code for one of the most widely-used bulletin board platforms on the net. While phpBB 3.0.5 will include a new functionality that introduces an optional wave distortion to the CAPTCHA, 3.0.5 will not be ready to go out the door very soon due to obvious reasons, and a number of people, including some of us, think that it’s a bit hard on some people’s eyes (see example 1, example 2). A number of admins have utilized a number of other anti-spam MODs and tools which utilize other methods to fight off spambots. We discuss some of these various options and whether they would be appropriate as part of a future default phpBB installation or not. We also describe some of the other options that admins have available, such as altering activation settings or enabling the post queue (a new feature since 3.0.3) to sequester spam posts before they are publicly visible.

Additional Links Mentioned in This Episode:
phpBB.com Downtime and Server Compromise — Details
Lessons to Learn from the Downtime
StarTrekGuide Security Class forum
Spambots Topic on Area51
Spambots Topic on StarTrekGuide

There is no MOD of the Week, Style of the Week, or Poll Question of the Week this week, however to end the show on a lighter note, we did throw in a funny Easter Egg conversation about earthquakes during the closing music. :) We’ll hopefully have a more lighthearted episode during our special Valentine’s Day show next Saturday; we hope you’ll join us.

We highly encourage you to share this episode with any other phpBB administrators you know. A lot of relevant information, some of it exclusive, is presented in this episode that will be helpful to many phpBB administrators and users. Click on the ShareThis button below to spread the word about this episode on your social network, blog, or via e-mail. Thanks for listening, and thanks for your support of phpBB Weekly.

Nov
18
2007
3

phpBB Weekly #039

Audio clip: Adobe Flash Player (version 9 or above) is required to play this audio clip. Download the latest version here. You also need to have JavaScript enabled in your browser.

Download MP3 Episode (49.2 MB)

Episode Duration: 1:26:00
On This Episode: Douglas Bell (Fountain of Apples) and David Lewis (Highway of Life)

We were hoping that this episode of phpBB Weekly just might turn out to be a shorter show, but apparently it wasn’t going to happen. Nevertheless, it turned out to be a rather interesting and informative show that came bundled with a rather interesting and informative live audience.

phpBB3′s Permissions system is one of the most powerful and most comprehensive new features, but also one of the most intimidating, as Douglas can tell you from experience. We go through the basics of using phpBB3′s permissions system and also look at a number of common things that can confuse people about the system (like why no one can see the forum you just created or the difference between Yes, No, and Never). For more information on the Permissions system beyond what we’ve covered in this episode, check out the Flash tutorials on managing forums and on custom usergroups. You can also check out the Setting Permissions quick start guide, or the more detailed section on users and forum permissions.

Then, Douglas gives us a phpBB History Lesson, as we take a look back to the release of phpBB 2.0.11 which took place exactly three years ago on November 18, 2004. We look back at the highlighting exploit that caused that released and which caused the infamous Santy worm of December 2004 which defaced over 40,000 phpBB-based bulletin boards and hurt phpBB’s security reputation, and we look at some of the changes that the phpBB teams in response to the uproar. Josh W. (A_Jelly_Doughnut), one of the MOD Team members, also comes on briefly to look back at the Santy worm with us. Finally, we take a look at what has changed with security in phpBB3 and the various steps that have been taken by the teams in the last three years to ensure that nothing like this happens again.
Additional links mentioned:
howdark.com “exploits”
howdark.com exploits – follow up
phpBB 2.0.11 released – Critical update
phpBB 2.0.11 upgrade reminder
Netcraft: Santy Worm Spreads Through phpBB Forums

The MOD of the Week is User Shield for phpBB2 by Wo1f, and the Style of the Week is DAJ_Glass for phpBB2 by Krezno.

Tech Podcast Network phpBB Weekly is a proud member of the Tech Podcast Network. Check them out for other great technology podcasts.

Written by Douglas Bell in: Released Episodes | Tags: , , , , , , ,

Copyright © 2007-2010 phpBB Weekly, some rights reserved under a Creative Commons License. Website powered by WordPress. Theme: TheBuckmaker. Background: Vlad Gerasimov.
Click here to view full copyright/legal attributions.