[Year 12 Its] PHPBB help required

Barry Larkin larkin.barry.j at edumail.vic.gov.au
Mon Jul 10 10:46:33 EST 2006



Hi Guys

 

This is probably not the right place to put this, (Tech would be better) but
there is such expertise out there in the education world that someone may be
able to help.

 

A friend is running a forum which has been set up by a web host using PHPBB
software and it has been hacked now on two occasions.

What is being done is the insertion of html code in place of one of the
forum names last time, and a new forum name being added this time with the
code.

As soon as the page tries to display the name of the forum the html runs and
puts up a blank screen.

 

He and I have tried backing up the data and then getting in and wiping the
offending code before restoring the data but are finding errors due probably
to internal consistency checks back at the server. We can't get into the
admin management area as the code is run when the forum name comes up there
too.

Pretty sure the hacker does not have access to the admin password.

 

Does anyone have any ideas as to how to fix the problem, other than
reinstalling the most recent backup?

 

And does anyone know how the access can be stopped?

 

The forum is configured to disallow html code but I assume this is only in
messages. 

 

Barry Larkin



Important -
This email and any attachments may be confidential. If received in error, please contact us and delete all copies. Before opening or using attachments check them for viruses and defects. Regardless of any loss, damage or consequence, whether caused by the negligence of the sender or not, resulting directly or indirectly from the use of any attached files our liability is limited to resupplying any affected attachments. Any representations or opinions expressed are those of the individual sender, and not necessarily those of the Department of Education & Training..


More information about the is mailing list