Shafail Shafa

← All case studies

phpBB Server care · 2025 · Fiverr

A forum updated after a denial of service attack

A technical community board had been knocked over repeatedly and the owner had put it behind a CDN himself. It was still on an old version, which is the likely way in.

The objective

The owner reckoned the attacks were getting in through a vulnerability in an out-of-date phpBB, and wanted the version brought current along with anything else that would make the board harder to knock over.

The site went down again in the middle of the work and stayed down until he turned the attack mode on his CDN back on.

There were loose ends from earlier changes as well. Adverts were showing up inside the administration panel. The spam captcha had stopped accepting the version he'd configured. And a translation extension had stopped working around the time of an earlier update.

What I did

I updated phpBB to the current release once the site was reachable again.

I traced the adverts in the administration panel to the ad service attached at nameserver level, which injects into every page including ones no visitor ever sees, and told him which path to exclude.

I explained that the older captcha version isn't accepted by the provider anymore and that a current one has to be configured, instead of leaving him retrying a setting that can't work.

I replaced the obsolete translation extension with two maintained alternatives so he could choose, and said plainly that either one might stop working again, because both depend on a third-party service outside anyone's control.

And I checked the reported broken link on two browsers, couldn't reproduce it, and said so rather than changing something to look busy.

The result

The board runs on a current release behind the owner's own CDN setup. Six orders with this client across two years.

“Exceptional work once again. The only place to go for phpBB support. Throughly recommended.”

Fiverr client, United Kingdom, 2025