Page 1 of 1

Yikes.....

Posted: Tue Jan 10, 2006 9:15 pm
by micah
Guess I need to keep on top of phpBB upgrades!

As far as I can tell, the only thing that happened during the hack was that someone was able to change some fields in the database to display their own HTML on top of what should be there.

Let me know if you see anything else fishy!

Posted: Tue Jan 10, 2006 10:47 pm
by Petrapraise
It happened as I was online. I email Michael to get ahold of you. I did a search on the internet and saw that hack on other forums before.

Scenario

Posted: Wed Jan 11, 2006 9:25 am
by Michael
Yep... PetraPraise was the eagle eye. In fact, it's kind of surprising that you, and Micah, and I all happened to be handy at the same time! I was sitting next to the laptop, which coincidentally had my email program running on it even though I wasn't really working on email (I was watching Wallace and Gromit with Cat and Mikey... hehe, those guys crack me up! Wallace and Gromit do, I mean), and I heard it ding and looked at what had come in, and then I emailed Micah, and he happened to be handy too because he replied within minutes and I guess got to work making things right again.

You know, I don't know that this little message board is such a big deal in God's grand scheme of things, but I have to think that there was more than coincidence in that unlikely stream of events all falling into place like that. :)

The whole "hacked" think has me spooked now, though... I'm going to bring the installation of my board at http://TALK.petratulsa.org up to date today, even though the hack that happened here shouldn't happen there (I'm a few revisions further down the road already).

Posted: Wed Jan 11, 2006 9:40 am
by Shell
Sad this person didn't have anything better to do with their time. :P

It was weird.

Posted: Wed Jan 11, 2006 10:37 pm
by micah
Yeah. And I need to get to applying the updates, but I've been really busy lately!!!

I also wonder if there might be better software for forums, as in more maintainable. I really don't like the way phpBB is set up in some ways. An upgrade to fix a security hole should be super-simple; with phpBB it involves being sure it doesn't overwrite some of your files. And some upgrades require other post-upgrade work as well.

Don't know how people would respond to starting over again, should I decide other software might fit the bill better....

Posted: Thu Jan 12, 2006 8:50 am
by calicowriter
Micah: Just my two cents, but given the timing, I don't think now would be a good time to have folks start over with a new forum. Maybe in six months or so, but with Petra's retirement, some no-so-frequent or new posters might not bother with a new registration, etc.

Posted: Thu Jan 12, 2006 10:30 am
by sue d.
You know, I don't know that this little message board is such a big deal in God's grand scheme of things, but I have to think that there was more than coincidence in that unlikely stream of events all falling into place like that
Ah... don't make God too small!

He cares about ALL the dumb little details of our lives... including this message board.

I mean, really, it's more than just a message board - look how many friendships and close relationships have formed because of it. Look how much we teach each other by our posts, learn from and pray for each other - all because of a little message board.