<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaBoard &#187; Project Management</title>
	<atom:link href="http://www.novaboard.net/category/project-management/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novaboard.net</link>
	<description>Open Source Forum Software</description>
	<lastBuildDate>Thu, 12 Aug 2010 18:09:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Website Downtime &#8211; August 2010</title>
		<link>http://www.novaboard.net/2010/08/website-downtime-august-2010/</link>
		<comments>http://www.novaboard.net/2010/08/website-downtime-august-2010/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 18:06:53 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Project Management]]></category>

		<guid isPermaLink="false">http://www.novaboard.net/?p=122</guid>
		<description><![CDATA[I would just like to start off by saying thanks to all those that reported that the website had gone down, and to reassure you that the hackers did not use NovaBoard to penetrate our server, it was a flaw in WordPress. Let me just say that again, it was a flaw in WordPress, not [...]]]></description>
			<content:encoded><![CDATA[<p>I would just like to start off by saying thanks to all those that reported that the website had gone down, and to reassure you that the hackers did <em>not</em> use NovaBoard to penetrate our server, it was a flaw in WordPress. Let me just say that again, it was a flaw in WordPress, <strong><em>not</em><span style="font-weight: normal;"> NovaBoard.</span></strong></p>
<p>A Spanish hacker, called T3ES, belonging to the Alboraaq hacking team, penetrated the WordPress installation through an unknown security flaw, and uploaded a PHP shell console, enabling him to further carry out malicious hacks throughout the site. This meant it also affected my own website, which is run on the same account.</p>
<p>I was informed of the hack within minutes, and immediately asked our host, TMDHosting, to restore the backup they say they keep of our sites. However, it took nearly two weeks to restore this backup, because of various issues with past backups, and also the fact that the hacked content was partially backed up. It had to be manually cleansed by technicians at our ISP, hence the delay.</p>
<p>During the downtime I sent a polite email to the hacker (who ever so kindly(!) left his email address) on the webpage. I received no reply.</p>
<p>I have since sent an email to both his domain registrar and hosting companies, asking for action to be taken, whether it be account suspension/deletion, or something else, since all the evidence is blatantly displayed on the site. I have yet to receive a response, but if any news comes through I will let you know.</p>
<p>So, we&#8217;re practically all up and running again now, the forums should be up shortly. We are also currently setting up a separate server to be partly used for backups, as well as a development area (e.g. maybe running Redmine etc). More details will follow.</p>
<p>Our host, TMDHosting, probably hate me for the amount of support tickets I opened demanding updates every day, if not twice a day, and asking this and that regarding the length of the time it was taking to restore the backups. After finally having the site back online, I just want to say that I am grateful for the work that the technicians and engineers did, as it isn&#8217;t a service that they normally carry out for free.</p>
<p>Thanks once again to those that got in touch, we appreciate the time you took to contact us, and we&#8217;re just sorry that we couldn&#8217;t get back online sooner.</p>
<p>If pages/posts/files are missing/corrupted, or if you notice something odd/strange with the website, such as a PHP shell, random text that doesn&#8217;t look as though it should be there, or just generally suspicious files/text, send an email to me, james@novaboard.net and I&#8217;ll look into it ASAP.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novaboard.net/2010/08/website-downtime-august-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Website Downtime</title>
		<link>http://www.novaboard.net/2010/04/website-downtime/</link>
		<comments>http://www.novaboard.net/2010/04/website-downtime/#comments</comments>
		<pubDate>Sat, 03 Apr 2010 20:10:19 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Project Management]]></category>

		<guid isPermaLink="false">http://www.novaboard.net/?p=103</guid>
		<description><![CDATA[You may find that NovaBoard is temporarily down over the next few days. We apologize in advance for the interruption, in the hope that it won&#8217;t last very long. All that is happening is some background maintenance.]]></description>
			<content:encoded><![CDATA[<p>You may find that NovaBoard is temporarily down over the next few days.</p>
<p>We apologize in advance for the interruption, in the hope that it won&#8217;t last very long.</p>
<p>All that is happening is some background maintenance.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novaboard.net/2010/04/website-downtime/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Website Downtime</title>
		<link>http://www.novaboard.net/2010/01/website-downtime-2/</link>
		<comments>http://www.novaboard.net/2010/01/website-downtime-2/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 17:37:55 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Project Management]]></category>

		<guid isPermaLink="false">http://www.novaboard.net/?p=49</guid>
		<description><![CDATA[Our hosts will be migrating our website to a new server between 06:00 AM and 08:00AM (GMT) on Sunday, January 17, 2010. Click here to see when that is in your time zone. The forum will be placed temporarily offline from late on Saturday to preserve the data that is in the database, and to ensure [...]]]></description>
			<content:encoded><![CDATA[<p>Our hosts will be migrating our website to a new server between 06:00 AM and 08:00AM (GMT) on Sunday, January 17, 2010. <a title="Convert Time" href="http://timeanddate.com/s/1j5h" target="_blank">Click here</a> to see when that is in your time zone.</p>
<p>The forum will be placed temporarily offline from late on Saturday to preserve the data that is in the database, and to ensure that posts etc aren&#8217;t lost during the transfer.</p>
<p>When we receive the &#8216;all clear&#8217; from our hosting company the forum will be reopened as usual.</p>
<p>If at any time you need urgent help regarding NovaBoard, you would usually be asked to email james@novaboard.net, but as the server could be down, for this time only, use the email address <a href="mailto:lake54@lake54.com?subject=NovaBoard">lake54@lake54.com</a></p>
<p>Thanks,</p>
<p>James<br />
Project Manager</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novaboard.net/2010/01/website-downtime-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Technical Difficulties</title>
		<link>http://www.novaboard.net/2010/01/technical-difficulties/</link>
		<comments>http://www.novaboard.net/2010/01/technical-difficulties/#comments</comments>
		<pubDate>Sun, 10 Jan 2010 17:41:07 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Project Management]]></category>

		<guid isPermaLink="false">http://www.novaboard.net/?p=19</guid>
		<description><![CDATA[To all of our users: thanks for your extended patience. Over the last couple of weeks, we have had a period of extensive hacking attempts, and the other day, these turned into successful exploits. As some of you may have noticed, the site has experienced regular, short bursts of downtime. Some of these were caused [...]]]></description>
			<content:encoded><![CDATA[<p><strong>To all of our users: thanks for your extended patience.</strong></p>
<p>Over the last couple of weeks, we have had a period of extensive hacking attempts, and the other day, these turned into successful exploits. As some of you may have noticed, the site has experienced regular, short bursts of downtime. Some of these were caused by host server maintenance, whilst others, such as the other day when you were greeted by a blank screen upon login to the forum, were caused by hackers.</p>
<p><strong>The Blank Screen incident</strong></p>
<p>Hackers managed to exploit a weakness in an existing module (the Theme Editor), and insert a line of code which effectively cut off the database connection when any page on the site was accessed. We couldn&#8217;t work out what was causing the &#8216;whiteouts&#8217; at first, and after an entire reinstall, we pinpointed it down to the theme, as only some users were affected.</p>
<p>If you use the Theme Editor on your NovaBoard installation, please, for your own security, remove it until an update has been issued.</p>
<p><strong>The 500 Internal Error incident</strong></p>
<p>Hackers made attempts to bypass existing security measures, and succeeded in accessing directory listings. Whether this was from an FTP connection, or whether it was from another exploit, we simply don&#8217;t know, as the logs aren&#8217;t detailed enough. However, once they had secured access, they cleaned the contents of the directory where the forum was hosted, resulting in data loss.</p>
<p>Now, we did realise this fairly soon, and I began a support session with a technician at the hosting company. He assured me that he could restore an at worse case 48 hours old backup to the forum directory. Unfortunately, this was not the case. He restored a backup made weeks ago onto the entire server, resulting in a total mess of the directories. Now, I must stress, the hosting company is a fantastic one, and I use them for all my hosting needs, this is the first case of something like this happening. In a way, it&#8217;s helped highlight how much crap there was on the server, so, we&#8217;ve wiped it and started again (of course, this was after making multiple backups!!!)</p>
<p><strong>What&#8217;s happening now?</strong></p>
<p>Over the next few days, we&#8217;re rebuilding the site in a more efficient and secure fashion. You may already notice the new theme on the homepage, and we&#8217;re utilising the WordPress platform to provide you with more insight into the development process. Please, sign up and subscribe to receive the latest updates on the project!</p>
<p>You may experience 404 (not found) errors and other downtime period during the course of this rebuild period &#8211; please don&#8217;t be put off by this. All the project code and downloads are hosted on Google&#8217;s servers, and even if this site was to suffer a massive loss of data, and everything was somehow nuked off, the downloads will still, always be available at the Google Code project site - <a title="NovaBoard Google Code Project" href="http://code.google.com/p/novaboard" target="_blank">http://code.google.com/p/novaboard</a></p>
<p>Thanks for reading this post, and we hope to see you back here soon. If you ever need to get in touch with someone, whatever the reason, send an email to <a title="Send an email to james@novaboard.net" href="mailto:james@novaboard.net" target="_blank">james@novaboard.net</a></p>
<p>James Milligan<br />
<em>Project Manager<br />
NovaBoard</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novaboard.net/2010/01/technical-difficulties/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Website Plan</title>
		<link>http://www.novaboard.net/2010/01/website-plan/</link>
		<comments>http://www.novaboard.net/2010/01/website-plan/#comments</comments>
		<pubDate>Sun, 10 Jan 2010 17:05:01 +0000</pubDate>
		<dc:creator>James</dc:creator>
				<category><![CDATA[Project Management]]></category>

		<guid isPermaLink="false">http://www.novaboard.net/?p=15</guid>
		<description><![CDATA[- Front-end Blog Completed! The theme needs tweaking, but this is more of a long term goal. - Community Forum Restoration Completed! - Addon Area In progress!]]></description>
			<content:encoded><![CDATA[<p><span style="color: #339966;">- Front-end Blog</span><br />
Completed! The theme needs tweaking, but this is more of a long term goal.</p>
<p><span style="color: #339966;">- Community Forum Restoration</span><br />
Completed!</p>
<p><span style="color: #ff9900;">- Addon Area</span><br />
In progress!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novaboard.net/2010/01/website-plan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
