Avoid Phpbb! New Security Exploit!

Pages: 1, 2, 3
free web hosting

Read Latest Entries..: (Post #20) by Sten on Jun 13 2007, 06:50 AM. (Line Breaks Removed)
i never knew that phpbb wasnt very secure.I've just uploaded it for my site a couple of days ago.I'm NOT ever using SMF, i really hate smf.I might get rid of phpbb and use xmb, xmb is definately my favourite free forum around, i really love it.
Read the FIRST post of this Topic. - Express your Opinion! Contribute Knowledge :-).

Free Web Hosting > Computers & Tech > Software > Bulletin Board Systems > phpBB

Avoid Phpbb! New Security Exploit!

nightfox
I sure have learned my lesson of using phpBB on a site of mine that gets many hits. Apparently, the attacker used a SQL injection (my password is 7 characters and is VERY hard to crack) to gain admin access and deleted everything then left his mark.

I don't even know WHY phpBB is allowed to exist and WHY it's so popular... I'm NEVER going to use it again!

Keep away from it!

[N]F

Reply

pyost
dry.gif Nothing new on the horizon, unfortunatelly. It is well-known that phpBB is the BBS with most security issues. And with hundreds of cracking tutorials on-line, even a kid could get into phpBB. On the other hand, it would be hard, even for a pro, to crack SMF. In my opinion, it is the best free BBS when it comes to security. It might not be as good-looking and customizable (the number of mods) as phpBB, but it sure is more secure.

Reply

Mafamba Team
I don't fully understand.

Anyway if you're talking about a phpBB forum, there's no point you should use proboards.

Reply

FunDa
Isn't there any way to prevent these SQL injection attacks ?

BTW, what is an SQL injection attack ?

I'm using phpBB for my site and I loved the customizability. SMF seemed a little harder to use ( for me at least )

Isn't there any way we can make phpBB safer ???

Reply

Niru
Hope, the phpBB team will come up with a solution to avoid these SQL injection attacks!
I'm also using phpbb for my forum!
like it very much as it is the simplest forum and easy to maintain than any other bullettin boards!
I like the simple interface also! cool.gif

QUOTE(FunDa @ Sep 23 2006, 07:33 PM) *


BTW, what is an SQL injection attack ?


QUOTE
SQL injection is a security vulnerability that occurs in the database layer of an application. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed.

SQL injection is a technique used to take advantage of non-validated input vulnerabilities to pass SQL commands through a Web application for execution by a backend database. Attackers take advantage of the fact that programmers often chain together SQL commands with user-provided parameters, and can therefore embed SQL commands inside these parameters. The result is that the attacker can execute arbitrary SQL queries and/or commands on the backend database server through the Web application.


You can see more about that here, here and also here

How to avoid SQL Injection >> Read it here & here

 

 

 


Reply

Opethian
This is very alarming.

I've been deciding which setup to go to and this must be the third instance I've heard about phpBB getting SQL injhected (if that's a term being used now).

So I guess I'm left with SMF then. Is there any other free forum out there that's noteworthy that anyone here can recommend?

Reply

jlhaslip
Try phorum.org.

It is used as a forum by Larry Ullman, an author of php and mysql books, so I suspect that it is rather secure. Also, this was posted on the phorum site Main page, which leads me to think it just might be secure:
QUOTE
* There is no shortage of message boards that use MySQL. When the webmasters at mysql.com went looking for one to install, they chose Phorum.


Reply

Mark420
Bad luck Nightfox...I feel for you..must have been terrible to login and find your board contents gone ;((

Did you have a backup in anyway?

Reply

Quatrux
Because phpbb is so popular for a long time now, a lot of whom know the source code and know how it works, so if you know how it works, you can always mess it up, don't you? Eventually, I read that SMF is much more secure to exploits and sql injections, because it is coded differently than phpbb, but people who is used to use phpbb - they have difficulties of moving to other forums such as SMF or don't have enough income to buy IPB or vBulletin.. They defend phpbb and say that those sites which get successful attacks didn't configure it the way it needs to be configured + the server configuration is bad and etc. It would be best to create your own forum system, but it just takes time and why waste the time if somebody else wrote it? tongue.gif

There are more forum software written but not so popular, so they might be more secure, but with less features and modifications + skins. I myself wanted to use phpbb, but as it is so vulnerable to exploits, I never did it, but I think I will use Phorum, which is available for a long time, but new versions are available now and I hope it will suit my needs.. I just need a very customizable forum software written in php which would work with mysql database.

Reply

HM-BRazil Owner
oh ****! I ever used phpBB ... * gulp* well ... then i'll use phpbb 3 ; it's much more secure! biggrin.gif

BTW i don't like smf , don't have money for IPB or VB... :/

Reply

Latest Entries

Sten
ohmy.gif i never knew that phpbb wasnt very secure.
I've just uploaded it for my site a couple of days ago.
I'm NOT ever using SMF, i really hate smf.
I might get rid of phpbb and use xmb, xmb is definately my favourite free forum around, i really love it.

Reply

WeaponX
The problem with phpBB is that they sort of have a bad reputation for keeping up to date with their security issues....at least from what I read from other phpBB users. SMF is usually really quick on the trigger and the patches are deployed and installed usually with just two clicks or so.

Reply

diyar
I would recommend you to stay with SMF because hardly anyone is using PhpBB 3 and we dont know if it has any security issues but i'm sure its going to be much safer than PhpBB2!!

I'll say stick with SMF cool.gif

Reply

tyƒoon™
So can you still do that same hack on phpBB3 or not?

i'm kinda dubble sided as to what software i should use for my new forums. I have both experiences with phpBB and SMF. I was considering phpBB3 now so my new forums. Does anyone want to back phpBB3 or still reccomend me to go for SMF?


Reply

diyar
It Happened to me as well biggrin.gif My phpbb forum site was hacked too!! I believe the security problem is sorted out in phpbb 3!!!

I would recommend people to avoid using phpbb 2 as well!!!

Regards

Reply


Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.

Pages: 1, 2, 3
Recent Queries:-
  1. "simplest forum" sql 5.0 - 203.79 hr back. (1)
  2. exploit shoutbox smf - 326.41 hr back. (1)
Similar Topics

Keywords : avoid, phpbb, security, exploit

  1. phpBB 3.0 Beta1 Released
    (3)
  2. Need Help, Install phpBB Shoutbox - Get Reward
    I'll reward you if you help me, I promise. (9)
    Hey guys and gals, I installed phpbb all by myself (not from the AstaHost
    Cpanel) on onther webhost. I installed it there because AstaHost has a pretty old version, (ok, the
    previous version). No I need help in installing a shoutbox on it, I am really pissed off with those
    shoutbox which you will have to manually install. I have been tring nearly 5 different shoutbox for
    phpbb and all keep saying some error, I had installed one of the shoutbox completely but in the end,
    when I tried shouting into it, it gave an error, now I am asking if anyone he....
  3. phpBB 2.0.19 Full Install DB Problems
    (1)
    Another phpBB question, I’m still really new to such things. I had an older version of phpBB on my
    site and never got around to fully implementing it. A newer version came out (2.0.19) so I decided
    to just delete the old version and install the latest version from scratch. I would have liked to
    used Fantastico from the Astahost control panel but the only version offered is 2.0.18 which I hear
    has some security flaws. I went to phpbb.com and downloaded the latest full package. I followed
    the instructions and got in installed to the point where you have to setup the d....
  4. Problem Installing A Premodded phpBB
    I think it's a problem with the server.. (6)
    Well I've installed this same premodded phpbb before many times on many other servers, and it
    works fine. I know it wasn't the phpbb premodded board itself because of this; however, I keep
    getting this error whenever I try to install it on this server: CODE Warning: mysql_connect():
    Host 'gamma.xisto.com' is not allowed to connect to this MySQL server in
    /home/vicious/public_html/metabbv4/db/mysql4.php on line 48 Warning: mysql_error(): supplied
    argument is not a valid MySQL-Link resource in /home/vicious/public_html/metabbv4/db/mysql4.php on
    line 3....
  5. Updating To phpBB 2.0.18
    (4)
    Has anyone updated to phpBB 2.0.18 yet? If so I would like to know the simplest way to do so. I
    found the update only files on the phpBB site but I not really sure if I have telnet access.....
  6. Is phpBB Jr Admin Mod Compatible With php-Nuke?
    (3)
    I'm using PHP-Nuke, with the ported version of phpBB, which comes as standard. I've just
    been installing some mods for phpBB, and they've all worked perfectly (I have had to make a few
    changes though - the "includes" folder is in a different place to that it should be). I needed my
    staff members to be able to modify other users' profiles, and someone reccommended Jr Admin, so
    I installed, and changed the paths for the "includes" folder, so that it ran properly. My side of
    it, the administration panel, works fine. But, my new Junior Admins have no way ....
  7. phpBB
    (3)
    hi, everyone here knows that there is a forum called phpBB. I like that free software, and there are
    many templates. it are all php scripts. Does somebody know how to install mods ?? you can find them
    on the internet but they say what you need to do with the standard-template. my template got
    antother script and what they say in the tect is not equal. What van i do....
  8. What Are Your Favorite Phpbb Hacks?
    No games (4)
    I'm working on a pre-moddified version of phpBB, and I need to know what people who use phpBB
    like, here is a list of the mods I have packaged. QUOTE -DHTML Slide Menu for ACP -Categories
    Hierarchy -Attachmod -Auto Group -phpBB Security MOD (prevents almost all of thos exploits that have
    been found lately) -Send PM On User Registration -Simply Merge Threads -Statistics Mod -Yellow
    Card I was also thinking either EZPortal, IM Portal, or the not as well known mxBB portal. And
    Rules Management, Rating system , Quick Reply with Quote, Profile Control Panel, Pos....
  9. phpBB And Mambo Login
    Login problem for databases (2)
    I have a problem with the phpBB 1 and 2 forums that C Panel installed for me. I chose an admin name
    and password but when I try to access the administration panel... I get nowhere. It says I have to
    reauthenicate. When I do, It simply takes me back to the home page. This may be a part of a much
    larger problem for me, however; I am finding that in order to properly log in to any of the systems
    I've installed on the server, I HAVE to check the "remember me" box. If I do not check that box
    while I'm logging in, The login will fail and I will be taken right back to ....
  10. IPB To phpBB Conversion
    (6)
    hi i was wondering if anyone knew how to convert ipb 2.0 over to phpbb 2.013....
  11. Please Help With phpBB
    (3)
    I just install the new phpBB into my new forum, the thing is that there is a little phpBB logo at
    the top, i want to know how to get rid of that logo and instead but my own banner across the page.
    CAn some one help me with this problem. I want the top to have nothing but a banner, kind of like
    the top of astahost, but instead a little but taller and across the page, thanks or if it is not
    possible to insert a banner across, how do i replace the logo with my own logo? thanks....
  12. Installing phpBB 2.0.14
    The better how-to. (10)
    For me the instructions in the phpbb docs is far too complicated. And their is a much more easier
    way. Please note that the below process has only been tried on this hosting website, the process
    below may not be applicable for other hosts. 1) Download phpbb 2.0.14 into a folder on your
    computer (e.g. My Documents\Forums) 2) Extract all the files to that folder. 3) Rename the extracted
    'phpbb2' folder to 'Forums' (change it to what you want). 4) Login into your ftp
    account (ftp://yoursite.astahost.com) 5) Copy the 'Forums' folder (or your named f....
  13. About Phpbb
    (10)
    phpBB version 2 has been completely re-written since the first version. Version 2 focuses on a
    professional-quality modular design, high security, multiple-language interface, support for a
    multitude of databases servers and complete layout customisation, all with a low execution overhead.
    phpBB is based on PHP, the fastest growing server-side scripting language on the web, which results
    in one of the fastest, feature-rich bulletin board systems available anywhere. In addition, phpBB
    is open-source software so it has no fees, no subscriptions, and no restrictions on mo....
  14. Phpbb 2
    (7)
    Is the package for the preinstalled phpBB deleted? I have problems trying to install it. When I
    click on the install link, it just said that this feature is not approved by the site admin, need to
    get the admin to upgrade this feature... Is there some problem?....
  15. Error 406 - Problem In My Phpbb Forum
    Actually a problem with Apache (8)
    When I post the message in my forum contant the word "system" it can't work and said the HTTP
    error 406. I add three Mod : attach mod 2.3.11 , cash mod 2.2.2 , pay money mod 1.0.7 phpBB
    verison 2.0.12 my forum http://siuwing.astahost.com/testmod and then I also setup a model forum
    by cPanel , the error of posting also occur -> http://www.siuwing.astahost.com/testmod2/ the
    model forum havent adding any mod what is the problem ...? /sad.gif' border='0'
    style='vertical-align:middle' alt='sad.gif' /> ....
  16. Oi Phpbb Gurus! Help Needed
    (1)
    I have Categories hierarchy (2.0.10, beta I think) installed to my phpBB and is working fine but...
    To my taste the select forum element (aka Jump Box) looks crap with those lines. Here is a
    screenshot http://www.wargaiming.uni.cc/pics/select_sh.png and you'll know what I mean. I
    tried to search the template files and the actual script files but couldn't find where it is.
    What I would simply do is replace underscores with  's and it'd look neat. So my
    question is, where I can edit how the Jump Box looks? And remember this was for forum with c....
  17. Need Help With Setting Up A phpBB Board On My Site
    need help with this (11)
    Once I get my site up, I"m planning to link it to a phpBB board. I have no idea how to do this as
    this is my first time using a phpBB board. Can anyone shed some light onto this?....
  18. Favorite phpBB mod
    i have more than one :) (14)
    View sig in profile Mod Profile Control Panel MOD What do you guys like....

    1. Looking for avoid, phpbb, security, exploit






*SIMILAR VIDEOS*
Searching Video's for avoid, phpbb, security, exploit
advertisement




Avoid Phpbb! New Security Exploit!



 

 

 

 

ADD REPLY / Got an Opinion! a humble request :-) RAPID SEARCH! Free Hosting [X]
Express your Opinions, Thoughts or Contribute your information that might help someone here.
Ask your Doubts & Queries to get answers.. "Together, We enlight each other!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE