hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Web Hosting : Phpbb Exploits?? Am I missing something
Reply

Web Hosting Discussions on all aspects of web hosting including past experiences (both negative and positive), choosing a host, questions and answers, and other related subjects. If your service is unavailable, please click here.
Forum Jump

Phpbb Exploits?? Am I missing something

Reply Post New Thread In Web Hosting Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 07-06-2005, 10:32 PM
ebizcraftsman ebizcraftsman is offline
WHT Addict
 
Join Date: Jun 2004
Location: Louisiana
Posts: 114

Phpbb Exploits?? Am I missing something


Hello,

I have read several posts about an exploit with the phpbb forums. Is there something new out there I need to know about. Also what kind of exploit.. Access to your server, Damage to forums??

Thanks and please let me know.

__________________
EbizCraftsman.com Hosting & Web Design
EbizCraftsman.com

Advertise your hosting company here!!

Reply With Quote


Sponsored Links
  #2  
Old 07-06-2005, 10:36 PM
ReasonSinger ReasonSinger is offline
Disabled
 
Join Date: May 2004
Posts: 97
Go to the source and read about the changes.

http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=302011

The latest one is another highlight bug that was inadequately addressed the first time around. Those types of exploits allow people to use the insecure version to grab remote files and execute them on the server. In our experience, UDP flooders and IRC junk is what is usually uploaded.

Reply With Quote
  #3  
Old 07-06-2005, 11:09 PM
BaselineAce BaselineAce is offline
Web Hosting Evangelist
 
Join Date: Aug 2004
Location: Southern NYS
Posts: 533
If you're aiming for a free forum, SMF is your man.

__________________
PacketAce
Because packets were meant to be delivered.
Premium Mzima Bandwith at Equinix - Secaucus, NJ


Reply With Quote
Sponsored Links
  #4  
Old 07-06-2005, 11:37 PM
Jalberts Jalberts is offline
Junior Guru Wannabe
 
Join Date: Mar 2003
Location: Oak Harbor, WA USA
Posts: 73
Do you have a link for SMF?

Thanks.

__________________
Jeff Alberts
www.infinite-realities.com
www.hdrpg.com

Reply With Quote
  #5  
Old 07-06-2005, 11:49 PM
neb1211 neb1211 is offline
WHT Addict
 
Join Date: Nov 2004
Location: Wisconsin
Posts: 148
I believe that the url is http://www.simplemachines.org

__________________
~ Nick

Reply With Quote
  #6  
Old 07-06-2005, 11:54 PM
Cirtex Cirtex is offline
WebHostingTalk Lover
 
Join Date: Mar 2003
Location: New York City
Posts: 7,393
Just keep your phpBB updated at all times.

__________________
█• CirtexHosting Providing Affordable and Quality Web Hosting & Reseller Hosting since 2003
█• LINUX based cPANEL/WHM Shared and Reseller Web Hosting with Fantastico
█• HostV VPS Premium Virtual Private Servers & Dedicated Servers powered by cPanel/WHM
█• We transfer your sites over quickly! I eat penguins for breakfast ...

Reply With Quote
  #7  
Old 07-06-2005, 11:55 PM
cartika-andrew cartika-andrew is offline
Web Hosting Master
 
Join Date: Oct 2003
Posts: 6,046
Quote:
Originally posted by BaselineAce
If you're aiming for a free forum, SMF is your man.
SMF is a great app - but - still a little problematic for my liking.

Migrating URL's causes all sorts of DB issues - and the DB cleanup utility doesnt always work too well (though overall, this is a pretty nice utility)

Also - I really dont like how there isnt an option to turn off error reporting to the DB - as somthing as simple as password hack attempts can fill up the DB with junk. We had a users DB jump from 5 MB to 300 MB - and really - there was no way to prevent this except to comment out the error reporting....

Having said all this - its a great app - growing strong - great templating features - and not nearly as well known or used as phpbb - which ultimately means less vulnerabilities are found

Reply With Quote
  #8  
Old 07-07-2005, 12:01 AM
catfished catfished is offline
Web Hosting Master
 
Join Date: Nov 2002
Location: Lakeport CA, Clear Lake
Posts: 1,856
Quote:
Originally posted by BaselineAce
If you're aiming for a free forum, SMF is your man.
Very true, SMF is the up and coming winner.

__________________
Everyone is entitled to MY opinion.
CatfishEd.com

Reply With Quote
  #9  
Old 07-07-2005, 07:58 AM
Scotty_B Scotty_B is offline
Web Hosting Guru
 
Join Date: Jan 2002
Posts: 310
Quote:
Originally posted by CartikaHosting
Also - I really dont like how there isnt an option to turn off error reporting to the DB - as somthing as simple as password hack attempts can fill up the DB with junk. We had a users DB jump from 5 MB to 300 MB - and really - there was no way to prevent this except to comment out the error reporting....
There is, it's in Edit Features & Options.

Reply With Quote
  #10  
Old 07-11-2005, 04:58 AM
Fulk Fulk is offline
Web Hosting Master
 
Join Date: Apr 2005
Posts: 681

Reply With Quote
  #11  
Old 07-11-2005, 05:06 AM
Leetservs Leetservs is offline
Newbie
 
Join Date: Jul 2005
Posts: 6
I'd reccomend just switch forums. Possibly INVISION if you liked the phpBB type panel.

Reply With Quote
  #12  
Old 07-11-2005, 11:41 AM
magick magick is offline
Junior Guru Wannabe
 
Join Date: Jul 2002
Posts: 74
yes phpbb is popular so its vulnerable and if you dont update every morning to make sure youre up to date, you are a target. ive had two forums hacked on phpbb and as much as i like it i wont use it again cause i dont have the time to keep it updated properly.

Reply With Quote
  #13  
Old 07-11-2005, 11:46 AM
cartika-andrew cartika-andrew is offline
Web Hosting Master
 
Join Date: Oct 2003
Posts: 6,046
Quote:
I'd reccomend just switch forums. Possibly INVISION if you liked the phpBB type panel.
As a policy, we avoid any application that defaults to p_connect ON.

Quote:
yes phpbb is popular so its vulnerable and if you dont update every morning to make sure youre up to date, you are a target. ive had two forums hacked on phpbb and as much as i like it i wont use it again cause i dont have the time to keep it updated properly.
We had a few sites compromised with these latest exploits - however, its not worth giving up on phpBB - excellent application, well supported, the community responds immediately to any exploits and issues patches.

On that note - suscribe to the phpBB mailing list and you will receive immediate notification of any updates/patches

Reply With Quote
  #14  
Old 07-11-2005, 11:47 AM
layer0 layer0 is offline
Performance Specialist
 
Join Date: Dec 2004
Location: New York, NY
Posts: 10,338
Quote:
Originally posted by Leetservs
I'd reccomend just switch forums. Possibly INVISION if you liked the phpBB type panel.
If you're talking about IPB 1.3, that actually has some vulnerabilites, too.

-GSV

__________________
MediaLayer, LLC - Lightning fast web hosting since 2005. Ask about our new pure SSD storage platform!
›› First and leading provider of LiteSpeed based hosting combined with enterprise grade hardware.
›› Free Account Migrations, Custom Solutions, and Servers in US, EU, and Asia
›› Our Application Hosting plans outperform the typical VPS. Ask us about special offers on yearly plans!

Reply With Quote
  #15  
Old 07-11-2005, 02:32 PM
SSilver2k2 SSilver2k2 is offline
Newbie
 
Join Date: Jan 2004
Posts: 12
i like PunBB. its very simple, and nice.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Whistleblower Site Cryptome Hacked, Infects PCs with Drive-By Exploits Web Hosting News 2012-02-14 14:48:24
Softaculous Launches AMPPS Installer Version 1.5 Web Hosting News 2012-01-26 16:52:40
Web Host Applied Innovations Deploys Corero Network Intrusion Prevention Systems Web Hosting News 2011-12-14 19:18:15
Dome9 Study Finds Cloud Vulnerable Without Secure Cloud Ports and Firewalls Web Hosting News 2011-11-02 15:37:19
Security Firm StillSecure Launches Penetration Testing Service Web Hosting News 2011-06-28 16:56:51


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?