<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
	<title>News Feed</title>
	<description>Annoucements</description>
	<link>http://forum.phpvms.net</link>
	<pubDate>Tue, 06 Dec 2016 02:10:28 +0000</pubDate>
	<ttl>720</ttl>
	<item>
		<title>Forum Compromised</title>
		<link>http://forum.phpvms.net/topic/24255-forum-compromised/</link>
		<description><![CDATA[The forum has lost about 36 hours of data due to an exploit that was present in the IPBoard system, it has since been patched. I think the attached Facebook thread involving Max Dyba will give you all the information needed to come to your own conclusion as to "why". The only word I can muster is disappointing. I attach it as a photo as I am sure the page will be edited in the near future.<br />
<br />
<a class='resized_img' rel='lightbox[127152]' id='ipb-attach-url-1756-0-11906100-1481660773' href="http://forum.phpvms.net/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=1756" title="Firefox_Screenshot_2016-12-06T02-01-09.397Z.png - Size: 852.04K, Downloads: 147"><img itemprop="image" src="http://forum.phpvms.net/uploads/monthly_12_2016/post-198-0-82918900-1480990141_thumb.png" id='ipb-attach-img-1756-0-11906100-1481660773' style='width:35;height:100' class='attach' width="35" height="100" alt="Firefox_Screenshot_2016-12-06T02-01-09.397Z.png" /></a>
<br />
<br />
This post was made shortly after the forum "went down".<br />
<br />
<a class='resized_img' rel='lightbox[127152]' id='ipb-attach-url-1758-0-13197400-1481660773' href="http://forum.phpvms.net/index.php?app=core&module=attach&section=attach&attach_rel_module=post&attach_id=1758" title="post5.PNG - Size: 34.95K, Downloads: 139"><img itemprop="image" src="http://forum.phpvms.net/uploads/monthly_12_2016/post-198-0-32245600-1480990398_thumb.png" id='ipb-attach-img-1758-0-13197400-1481660773' style='width:100;height:87' class='attach' width="100" height="87" alt="post5.PNG" /></a>
<br />
<br />
I wish the best for these guys but it is embarrassing to all of us when developers act this way.<br />
<br />
<span style='color: #ff0000'><strong class='bbc'>NOTE: Neither my host or I have been able to verify if any data was actually downloaded or not. I would suggest a password change both for the forum and the email you have associated with your profile.</strong></span><br />
<br />
<strong class='bbc'>Edit on 12-6-2016 @ 6:15pm EST - The view expressed here is not to be construed as the view of any one or anything else but myself. This is an opinion and also simply provides what I believe to be the facts presented to me, everyone can come to their own conclusion and do their own research if they so desire.</strong>]]></description>
		<pubDate>Tue, 06 Dec 2016 02:10:28 +0000</pubDate>
		<guid>http://forum.phpvms.net/topic/24255-forum-compromised/</guid>
	</item>
	<item>
		<title>Deleted Profiles</title>
		<link>http://forum.phpvms.net/topic/22632-deleted-profiles/</link>
		<description><![CDATA[I have had a few emails in regards to members profiles being deleted and hope this explains the why and how; there was over 33,000 users in the database, the vast majority were spam signups and it was just weighing on the speed of the forum. I deleted all the users that never posted anything in the forum, and that had no login activity on the site since January 1st, 2014. Meeting one condition or the other kept your profile in the system.<br />
<br />
No one that ever posted on the site was deleted and if you had logged in since January 1st, 2015 your profile was not deleted. I am sorry if you did not meet these conditions and now noticed your profile gone, but never posting and not logging in for 18 months tells me that you were not using it. You are welcome to sign up again for a new profile if you would like.]]></description>
		<pubDate>Thu, 16 Jul 2015 19:18:17 +0000</pubDate>
		<guid>http://forum.phpvms.net/topic/22632-deleted-profiles/</guid>
	</item>
	<item>
		<title>Database Corruption</title>
		<link>http://forum.phpvms.net/topic/22599-database-corruption/</link>
		<description><![CDATA[The forum was hacked just after a DDOS attack on the server Saturday night and I thought the database had just been deleted which I restored from a backup from June 28th. What I did not realize that in the process of destroying the forum database the InnoDB engine on the mySql server was corrupted as well, which in turn corrupted almost every InnoDB table on the server. Drive volumes were also damaged in the attack.<br />
<br />
With so many sites experiencing issues with database corruption I had no choice today but to rebuild the MySql server and restore all databases from the June 28th backup. This includes the forum and VACentral. Any data that was recorded between June 28th and today (July 6th) was lost in the process.<br />
<br />
David]]></description>
		<pubDate>Mon, 06 Jul 2015 17:40:57 +0000</pubDate>
		<guid>http://forum.phpvms.net/topic/22599-database-corruption/</guid>
	</item>
	<item>
		<title>Updated phpVMS License</title>
		<link>http://forum.phpvms.net/topic/21651-updated-phpvms-license/</link>
		<description><![CDATA[After thinking about it for some time, I have decided to change the license for phpVMS to the much simpler BSD 3-clause license. Development has pretty much stopped as my work schedule gives me almost no time for side-projects, so hopefully this fosters more forks and development, which I will be happy to merge back into the mainline branch(es).<br />
<br />
Nabeel]]></description>
		<pubDate>Thu, 25 Sep 2014 02:54:50 +0000</pubDate>
		<guid>http://forum.phpvms.net/topic/21651-updated-phpvms-license/</guid>
	</item>
	<item>
		<title>2.1.936 - Security Patch</title>
		<link>http://forum.phpvms.net/topic/16598-21936-security-patch/</link>
		<description><![CDATA[Hi all,<br />
<br />
I've updated the download to 2.1.936 - basically to null the file where I believe the exploit is coming from. I looked through the other files, and I think they look OK. <br />
<br />
Please update as soon as possible - really the only updated file was <strong class='bbc'>core/lib/php-ofc-library/ofc_upload_image.php</strong>. Instead of deleting it, I patched it, so then it will get patched on an upload.<br />
<br />
Sorry for all the trouble guys! Please be sure to look through your server and account very carefully - if you see something suspicious, delete it, or rename it to add a .txt extension so it can't be found, until you can verify if the file is safe or not.<br />
<br />
Thanks!]]></description>
		<pubDate>Mon, 30 Sep 2013 17:18:36 +0000</pubDate>
		<guid>http://forum.phpvms.net/topic/16598-21936-security-patch/</guid>
	</item>
</channel>
</rss>