[advanced search]
 

Go Back   NamePros.com > Discussion > Web Design & Development > Programming

Programming PHP, Perl, Ruby on Rails, AJAX, HTML, XHTML, CSS, JavaScript, MySQL and any other coding topics.


Closed Thread
 
LinkBack Thread Tools
Old 11-19-2004, 03:36 PM   #1 (permalink)
Senior Member
 
Peter's Avatar
 
Join Date: Nov 2003
Location: Scotland
Posts: 4,900
0.60 NP$ (Donate)

Peter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond repute

Child Abuse Save The Children Save The Children Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009
phpBB EXPLOIT fix ASAP

Think this is the best place for this but anyway a bug was found a while back in phpBB and should be fixed ASAP.

The bug itself is to do with the highlighting system all detasils on how to do the fix is located at http://www.phpbb.com/phpBB/viewtopic.php?t=240513 (just 1 file edit)
__________________
Manage your portfolio using my new Domain Portfolio Management script.
Securing Your Domain Name From Theft
Peter is offline  
Old 11-19-2004, 03:47 PM   #2 (permalink)
Account Suspended
 
Join Date: Nov 2004
Posts: 59
160.00 NP$ (Donate)

Question? is an unknown quantity at this point


i didnt know phpBB worked off ASP i thought it was php some one help!!!! im being seriouse lol
Question? is offline  
Old 11-19-2004, 07:36 PM   #3 (permalink)
Senior Member
 
Peter's Avatar
 
Join Date: Nov 2003
Location: Scotland
Posts: 4,900
0.60 NP$ (Donate)

Peter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond repute

Child Abuse Save The Children Save The Children Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009
please please tell me where you say im being serious you are not being serious hehe

But on a serious note this looks like a major bug that can cause someone to execute malicious code on the server which could basically do anything included dropping a database or deleting files on the server (in fact the person who discovered this bug had files deleted on their server and was accused of doing it themselves by their ISP).
__________________
Manage your portfolio using my new Domain Portfolio Management script.
Securing Your Domain Name From Theft
Peter is offline  
Old 11-21-2004, 03:07 PM   #4 (permalink)
NamePros Regular
 
DuffMan's Avatar
 
Join Date: Jul 2003
Location: Maryland, USA
Posts: 603
77.00 NP$ (Donate)

DuffMan has a spectacular aura aboutDuffMan has a spectacular aura about


Wow, this is a huge surprise, especially after the dev team said the exploits were fake. Anyone know if this bug affects all versions of phpBB? (I'm running an early 2.0.x on one of my sites.)
__________________
Eric AKA DuffMan
[HG Interactive]
[ ShoutPro]
DuffMan is offline  
Old 11-21-2004, 11:09 PM   #5 (permalink)
Senior Member
 
Peter's Avatar
 
Join Date: Nov 2003
Location: Scotland
Posts: 4,900
0.60 NP$ (Donate)

Peter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond repute

Child Abuse Save The Children Save The Children Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009
yes it does,
__________________
Manage your portfolio using my new Domain Portfolio Management script.
Securing Your Domain Name From Theft
Peter is offline  
Old 11-21-2004, 11:54 PM   #6 (permalink)
Ultima Ratio Regum
 
Redleg's Avatar
 
Join Date: Sep 2003
Location: Up North
Posts: 2,083
71.00 NP$ (Donate)

Redleg is a splendid one to beholdRedleg is a splendid one to beholdRedleg is a splendid one to beholdRedleg is a splendid one to beholdRedleg is a splendid one to beholdRedleg is a splendid one to behold


Quote:
Originally Posted by DuffMan
Wow, this is a huge surprise, especially after the dev team said the exploits were fake. Anyone know if this bug affects all versions of phpBB? (I'm running an early 2.0.x on one of my sites.)
You should upgrade to v2.0.11 ASAP.

Read this thread about it:
http://www.namepros.com/website-development/56586-phpbb-2-0-11-released-critical.html#post369274
__________________
|Internet, Games, Computer Talk|IP Whois + Geolocation|Geolocate your IP|
|Dynamic Forum Sigs|2,900+ Free Flash Games|

<meta name="Jedi Mind Trick" content="Buy my domains, you will!">
VoIPUSA.com-MyBlogging.com-ArrivingSoon.com-Nano.tv- Technology.ws-Ammo.us-Racing.cc-Privacy.ws
Redleg is offline  
Old 11-22-2004, 09:03 AM   #7 (permalink)
québécois libre
 
peaudecastor's Avatar
 
Join Date: Oct 2003
Location: Trois-Rivieres, Québec
Posts: 563
353.91 NP$ (Donate)

peaudecastor is just really nicepeaudecastor is just really nicepeaudecastor is just really nicepeaudecastor is just really nice


Thanks a lot.

Mass-mailed my webhosting user and fixed my own.

Cheers,
Matt
peaudecastor is offline  
Old 11-24-2004, 02:06 PM   #8 (permalink)
NamePros Regular
 
DuffMan's Avatar
 
Join Date: Jul 2003
Location: Maryland, USA
Posts: 603
77.00 NP$ (Donate)

DuffMan has a spectacular aura aboutDuffMan has a spectacular aura about


Weird, I just upgraded and when I try to login or go to the admin panel I get sent to microsoft.com. What's up with that?

EDIT: Looks like it sends me to Microsoft.com after I login or logout, and when I try to access the admin panel when not logged in. I've checked my settings and they're fine.
__________________
Eric AKA DuffMan
[HG Interactive]
[ ShoutPro]

Last edited by DuffMan; 11-24-2004 at 02:10 PM.
DuffMan is offline  
Old 11-24-2004, 11:33 PM   #9 (permalink)
Senior Member
 
Peter's Avatar
 
Join Date: Nov 2003
Location: Scotland
Posts: 4,900
0.60 NP$ (Donate)

Peter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond reputePeter has a reputation beyond repute

Child Abuse Save The Children Save The Children Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009
are you sure it only happens on your forum, check your pc with an antivirus etc.

I very much doubt the update would cause this unless you did not download it from the official site.
__________________
Manage your portfolio using my new Domain Portfolio Management script.
Securing Your Domain Name From Theft
Peter is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Site Sponsors
Advertise your business at NamePros

All times are GMT -7. The time now is 04:26 PM.


Powered by: vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
Template-Modifications by TMS
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85