While we’re waiting for the DC guys to come in, I think it’s already 12:15PM Monday in HK, lets take a look at an unfortunate incident to the organization who programmed the base of our forum – phpBB.
It was hacked yesterday by someone who exploited the PHPlist (PHPlist is used to manage email lists) script on their servers and it did not take long to get access to everything once he/she was able to get in. The full story can be read here.
I don’t condone what this person has done. It is rather sad to know that almost all of the passwords of members and their emails have been leaked into spam lists. And worse, the full extent of this hack may not be known, if there were no transparency or if the phpBB group fails to notify members. The immediate implication is that many phpBB.com members may get their other logins compromised if they ever use a universal password. For example, the same password used on phpBB.com is used on their email. This is a tragic lesson but one we must all learn, make sure your passwords are fully random and have different passwords for different logins. If you’re not someone who can memorize 16 character passwords then at least use a few random passwords for the sites you go to, rather than a different one at each login.
Random passwords can be generated here.
I do hope that the phpBB group learns from this attack and updates their phpBB 3.x software to prevent any future hacking attempts. Our team’s condolences goes out to the phpBB community.