Punbb Isnt Very Safe

Discussion in 'Forum Management' started by Bohra, May 8, 2010.

  1. #1
    Ok guys ive noticed punbb isnt a very safe script and has exploits today i noticed two of my punbb forums have a stupid iframe added to all index.php and index.html files

    so take care if u use punbb
     
    Bohra, May 8, 2010 IP
  2. d3wlin

    d3wlin Well-Known Member

    Messages:
    1,075
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    100
    #2
    Thanks for letting others know. I have few PunBB-powered forums and all they are good.

    Also I haven't noticed any recent talks on PunBB official forums. Maybe it's something to do with your specific install, or host?
     
    d3wlin, May 11, 2010 IP
  3. .Razz

    .Razz Peon

    Messages:
    133
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #3
    I wouldn't really use PunBB in the first place, mainly because it's not that known.
     
    .Razz, May 11, 2010 IP
  4. Bohra

    Bohra Prominent Member

    Messages:
    12,573
    Likes Received:
    537
    Best Answers:
    0
    Trophy Points:
    310
    #4
    well both my installs were on big hosts startlogic and dreamhost ... maybe they have a vulnerability in the automatic mod install thing which is launced in the newer versions

    @Razz

    Punbb is not new and is pretty much known
     
    Bohra, May 11, 2010 IP
  5. Vekseid

    Vekseid Peon

    Messages:
    124
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Did you have a custom Dreamhost setup of some sort? I wouldn't necessarily blame PunBB first, though I do find it seriously lacking - not just in the feature department but also for the fact that its performance does not degrade 'gracefully' with added modules.
     
    Vekseid, May 13, 2010 IP
  6. Bohra

    Bohra Prominent Member

    Messages:
    12,573
    Likes Received:
    537
    Best Answers:
    0
    Trophy Points:
    310
    #6
    its not dreamhost fault coz it happened in 2 diffrent hosts
     
    Bohra, May 13, 2010 IP
  7. Vekseid

    Vekseid Peon

    Messages:
    124
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #7
    If you use your hosting password as your mysql password, it would be your fault. It's impossible to judge, since you haven't given much for details.
     
    Vekseid, May 14, 2010 IP
  8. Ephemeraboy

    Ephemeraboy Peon

    Messages:
    66
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    many admin added vulnerability code
    which they don't know....
    and maybe the thread starter do the same
     
    Ephemeraboy, May 15, 2010 IP
  9. Bohol

    Bohol Peon

    Messages:
    2,680
    Likes Received:
    75
    Best Answers:
    0
    Trophy Points:
    0
    #9
    why don't you use SMF instead? SMF is very safe and secure and it has many community members who are actively helping each other.
     
    Bohol, May 18, 2010 IP
  10. Bohra

    Bohra Prominent Member

    Messages:
    12,573
    Likes Received:
    537
    Best Answers:
    0
    Trophy Points:
    310
    #10
    Yea SMF is good but i wanted to use a light wieght software thats why i used punbb
     
    Bohra, May 18, 2010 IP