Mortgages - Flights - Loans - Buy Anything On eBay - Credit Cards

PDA

View Full Version : so you think phpbb2 is so secure.....


Shoemoney
Jul 18th 2005, 8:52 am
If you search for "powered by phpbb" in google and click next it will tell you your infected by a virus =P

http://www.google.com/search?q=powered+by+phpbb&hl=en&lr=&rls=GGLG,GGLG:2005-20,GGLG:en&start=10&sa=N

Evidently the massive scanning for exploitable forums has triped googles alarms.

yay opensource

I, Brian
Jul 18th 2005, 9:03 am
This is from when the Santy worms were using autmated queries to search Google for phpbb's before last Christmas - so Google blocked off searches that santy was using, ie "Powered by phpbb":
http://www.platinax.co.uk/news/archives/2004/12/phpbb_worms_mul.html

[HC]D-Man
Jul 18th 2005, 9:06 am
Just keep your forum up-to-date, sign up for the phpbb newsletter, and update asap. You'll be safe from 99% of hackers, etc.

phpBB newsletter signup: http://www.phpbb.com/support/

Shoemoney
Jul 18th 2005, 9:10 am
D-Man']Just keep your forum up-to-date, sign up for the phpbb newsletter, and update asap. You'll be safe from 99% of hackers, etc.

phpBB newsletter signup: http://www.phpbb.com/support/

Hi-

posts like this make me want to scream... no offense to you ill tell you why if you care-

My phpbb2 forum has almost 200k users. it gets massive amounts of traffic. I am targeted constantly because of the weight and success of my site. I have been defaced 2 times since last january. Both times it was up for less then 5 minutes before I was paged and I fixed it and also pluged the hole.

The problem is when you are the initial or one of the initial targets for defacement there is no patch. YOU ARE THE ONE SUBMITING THE PATCH and information on how you were exploited. I have submited 5 patches so far this year to the phpbb2 group.

Everyday I study my logs and look for what people are trying to post to. I then test it on my devbox and see if there is infact a exploitable hole there.

Shoemoney
Jul 18th 2005, 9:13 am
This is from when the Santy worms were using autmated queries to search Google for phpbb's before last Christmas - so Google blocked off searches that santy was using, ie "Powered by phpbb":
http://www.platinax.co.uk/news/archives/2004/12/phpbb_worms_mul.html

ahh this should make everyone feel much safer then =P knowing google seems to think its still a problem

marcel
Jul 18th 2005, 10:53 am
Hi-

posts like this make me want to scream... no offense to you ill tell you why if you care-

My phpbb2 forum has almost 200k users. it gets massive amounts of traffic. I am targeted constantly because of the weight and success of my site. I have been defaced 2 times since last january. Both times it was up for less then 5 minutes before I was paged and I fixed it and also pluged the hole.

The problem is when you are the initial or one of the initial targets for defacement there is no patch. YOU ARE THE ONE SUBMITING THE PATCH and information on how you were exploited. I have submited 5 patches so far this year to the phpbb2 group.

Everyday I study my logs and look for what people are trying to post to. I then test it on my devbox and see if there is infact a exploitable hole there.


Shoebox - with 200K users you should probably upgrade to VB.

Shoemoney
Jul 18th 2005, 11:17 am
Shoebox - with 200K users you should probably upgrade to VB.

wow i never thought of that....

dvduval
Jul 18th 2005, 11:32 am
I've got 25 forums, and never been down for more than a few minutes.
ANY popular application is going to need security fixes.

marcel
Jul 18th 2005, 12:22 pm
wow i never thought of that....

Really !? WOW !

Windows-Update-Advisor
Dec 3rd 2005, 5:34 am
Shoebox - with 200K users you should probably upgrade to VB.

What is VB? Care to explain? Newbie here :p

mdvaldosta
Dec 3rd 2005, 5:38 am
It's a different forum software, vbulletin

piniyini
Dec 3rd 2005, 10:44 am
google isnt blocking the search anymore

Design Agent
Dec 3rd 2005, 10:59 am
Wow, someone loves you today shoemoney.. yet another one of your old threads..

Shoemoney
Dec 3rd 2005, 2:01 pm
yea considering I moved to vbullliten like a long long long time ago... even before the guy sugested it lol... phpbb died about the 150k user mark

eiso
Dec 3rd 2005, 2:17 pm
I would export your existing forum to vBulletin if i was you, it's a lot more secure and better, i have it since a week, i'm loving it.

marcel
Dec 3rd 2005, 4:59 pm
a competing forum - http://vbulletin.com

What is VB? Care to explain? Newbie here :p