
07-06-2005, 10:32 PM
|
|
WHT Addict
|
|
Join Date: Jun 2004
Location: Louisiana
Posts: 114
|
|
Phpbb Exploits?? Am I missing something
Hello,
I have read several posts about an exploit with the phpbb forums. Is there something new out there I need to know about. Also what kind of exploit.. Access to your server, Damage to forums??
Thanks and please let me know.
|

07-06-2005, 10:36 PM
|
|
Disabled
|
|
Join Date: May 2004
Posts: 97
|
|
Go to the source and read about the changes.
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=302011
The latest one is another highlight bug that was inadequately addressed the first time around. Those types of exploits allow people to use the insecure version to grab remote files and execute them on the server. In our experience, UDP flooders and IRC junk is what is usually uploaded.
|

07-06-2005, 11:09 PM
|
|
Web Hosting Evangelist
|
|
Join Date: Aug 2004
Location: Southern NYS
Posts: 533
|
|
If you're aiming for a free forum, SMF is your man.
__________________
PacketAce
Because packets were meant to be delivered.
Premium Mzima Bandwith at Equinix - Secaucus, NJ
|

07-06-2005, 11:37 PM
|
|
Junior Guru Wannabe
|
|
Join Date: Mar 2003
Location: Oak Harbor, WA USA
Posts: 73
|
|
Do you have a link for SMF?
Thanks.
|

07-06-2005, 11:49 PM
|
|
WHT Addict
|
|
Join Date: Nov 2004
Location: Wisconsin
Posts: 148
|
|
__________________
~ Nick
|

07-06-2005, 11:54 PM
|
|
WebHostingTalk Lover
|
|
Join Date: Mar 2003
Location: New York City
Posts: 7,393
|
|
Just keep your phpBB updated at all times.
__________________
█• CirtexHosting • Providing Affordable and Quality Web Hosting & Reseller Hosting since 2003
█• LINUX based cPANEL/WHM Shared and Reseller Web Hosting with Fantastico
█• HostV VPS • Premium Virtual Private Servers & Dedicated Servers powered by cPanel/WHM
█• We transfer your sites over quickly! • I eat penguins for breakfast ...
|

07-06-2005, 11:55 PM
|
|
Web Hosting Master
|
|
Join Date: Oct 2003
Posts: 6,046
|
|
Quote:
Originally posted by BaselineAce
If you're aiming for a free forum, SMF is your man.
|
SMF is a great app - but - still a little problematic for my liking.
Migrating URL's causes all sorts of DB issues - and the DB cleanup utility doesnt always work too well (though overall, this is a pretty nice utility)
Also - I really dont like how there isnt an option to turn off error reporting to the DB - as somthing as simple as password hack attempts can fill up the DB with junk. We had a users DB jump from 5 MB to 300 MB - and really - there was no way to prevent this except to comment out the error reporting....
Having said all this - its a great app - growing strong - great templating features - and not nearly as well known or used as phpbb - which ultimately means less vulnerabilities are found 
|

07-07-2005, 12:01 AM
|
|
Web Hosting Master
|
|
Join Date: Nov 2002
Location: Lakeport CA, Clear Lake
Posts: 1,856
|
|
Quote:
Originally posted by BaselineAce
If you're aiming for a free forum, SMF is your man.
|
Very true, SMF is the up and coming winner.
__________________
Everyone is entitled to MY opinion.
CatfishEd.com
|

07-07-2005, 07:58 AM
|
|
Web Hosting Guru
|
|
Join Date: Jan 2002
Posts: 310
|
|
Quote:
Originally posted by CartikaHosting
Also - I really dont like how there isnt an option to turn off error reporting to the DB - as somthing as simple as password hack attempts can fill up the DB with junk. We had a users DB jump from 5 MB to 300 MB - and really - there was no way to prevent this except to comment out the error reporting....
|
There is, it's in Edit Features & Options.
|

07-11-2005, 04:58 AM
|
|
Web Hosting Master
|
|
Join Date: Apr 2005
Posts: 681
|
|
|

07-11-2005, 05:06 AM
|
|
Newbie
|
|
Join Date: Jul 2005
Posts: 6
|
|
I'd reccomend just switch forums. Possibly INVISION if you liked the phpBB type panel.
|

07-11-2005, 11:41 AM
|
|
Junior Guru Wannabe
|
|
Join Date: Jul 2002
Posts: 74
|
|
yes phpbb is popular so its vulnerable and if you dont update every morning to make sure youre up to date, you are a target. ive had two forums hacked on phpbb and as much as i like it i wont use it again cause i dont have the time to keep it updated properly.
|

07-11-2005, 11:46 AM
|
|
Web Hosting Master
|
|
Join Date: Oct 2003
Posts: 6,046
|
|
Quote:
|
I'd reccomend just switch forums. Possibly INVISION if you liked the phpBB type panel.
|
As a policy, we avoid any application that defaults to p_connect ON.
Quote:
|
yes phpbb is popular so its vulnerable and if you dont update every morning to make sure youre up to date, you are a target. ive had two forums hacked on phpbb and as much as i like it i wont use it again cause i dont have the time to keep it updated properly.
|
We had a few sites compromised with these latest exploits - however, its not worth giving up on phpBB - excellent application, well supported, the community responds immediately to any exploits and issues patches.
On that note - suscribe to the phpBB mailing list and you will receive immediate notification of any updates/patches
|

07-11-2005, 11:47 AM
|
|
Performance Specialist
|
|
Join Date: Dec 2004
Location: New York, NY
Posts: 10,338
|
|
Quote:
Originally posted by Leetservs
I'd reccomend just switch forums. Possibly INVISION if you liked the phpBB type panel.
|
If you're talking about IPB 1.3, that actually has some vulnerabilites, too.
-GSV
__________________
MediaLayer, LLC - Lightning fast web hosting since 2005. Ask about our new pure SSD storage platform!
›› First and leading provider of LiteSpeed based hosting combined with enterprise grade hardware.
›› Free Account Migrations, Custom Solutions, and Servers in US, EU, and Asia
›› Our Application Hosting plans outperform the typical VPS. Ask us about special offers on yearly plans!
|

07-11-2005, 02:32 PM
|
|
Newbie
|
|
Join Date: Jan 2004
Posts: 12
|
|
i like PunBB. its very simple, and nice.
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
| Postbit Selector |
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|
| Login: |
|
|
| Advertisement: |
|
|
| Web Hosting News: |
|
|
|