SMF 1.1.6, 1.1.5, 1.1.4, 1.1.7 are severely insecure. MyBB has been secure since 1.2+, with minor XSS vulnerabilities (not exploits) in 1.3.X etc.. I was personally able to hack into a 1.1.7 using slight modifications to 1.1.6 exploits. Maybe, at some point in time, SMF use to be more secure, so I wouldn't insult the SMF team, they did a great job. But nowadays, MyBB is definitely more secure than SMF. Hopefully they will fix that. But I didn't notice any vulnerabilities in SMF 2.X I believe. So good job SMF team. Regardless, anyone claiming SMF is more secure, is seriously biased or is just in denial. I tried both SMF and MyBB, as I didn't know which one was better, I realized in another thread here, that MyBB is obviously better. But hey what do I care? Please go ahead use SMF, it's actually nice that less people use MyBB, less people develop hacks for it .
Please do hack this forum - http://www.egadforums.net/smf1/index.php With all due respect we do need some proof of concept. No hard feelings this is just a debate. And appears myBB forums on the latest version can be hacked - Look at RectangleMan's forum. http://www.webmasterforums.biz/index.php
Don't speak on what you don't know anything about. The site was hacked through one of my shared hosting accounts at Dreamhost where on one site I had an old insecure script. It had absolutely nothing to do with Mybb. A c99shell was uploaded and the account was compromised. Mybb 1.4.4 has no known published exploits.
Don't want to get involved in the mud-slinging, but I recently had an "issue" with an SMF forum where someone was able to inject js in to the template. This was the first and only problem in many years using SMF. Didn't have the time to backtrack to ascertain the source of the problem but it could have been due to an out of date plug-in. I have never had any issues with the few myBB forums I run in over 2 years.
RectangleMan its nice to see you bro. I love myBB and I use it, u know that too I've used SMF but I didn't like it, plus I had too much spam when I used SMF.
What about using phpBB? Is it any good. I came here looking for solutions on smf spam only to find there are major issues with the smf spam control. Gary
Yes but still imho a good topic. Here it is 20 months later and I don't feel any differently about MyBB vs SMF for security.