AMD Hack Points to Widespread Web Forum Flaws, Attacks
Malicious hackers are increasingly targeting security vulnerabilities in open-source software that runs bulletin boards and online forums, according to Internet monitoring firm Netcraft.
The unpatched holes, in open-source software like phpBB, PostNuke, and Mambo are being used to take control of powerful servers for denial of service attacks and phishing scams. Poor deployment of security patches by administrators and the growing popularity of programs like phpBB are to blame, Netcraft said.
On Jan. 30, a bulletin board run by chip maker AMD was compromised by hackers and was used to distribute malicious code.
Those who visited the site, forums.amd.com, were prompted to download a file that exploited a recently patched vulnerability in Windows code used to process WMF (Windows Meta File) format image files, according to anti-virus firm F-Secure Inc. in Helsinki.