Zacker Posted December 28, 2004 Report Posted December 28, 2004 I recommend that you upgrade to phpBB 2.0.11. Your current version makes it rather easy for both hackers and worms to infect your server. The highlight vulnerability, which exists in your forum version, allows worms to execute arbitary code on your server. You can test it yourself with this perl script: http://www.securiteam.com/exploits/6W00L0KC0I.html Quote
FrieChamp Posted December 28, 2004 Report Posted December 28, 2004 Yea a pm to the admins might have been smarter, thanks for the heads up though! Quote
OL Posted December 28, 2004 Report Posted December 28, 2004 iv been hearing about this although the code looks like it uses google and i remember reading that theyve fixed it so it cant do that Quote
D3adlode Posted December 28, 2004 Report Posted December 28, 2004 We had this guy over on RUST as well but I didn't realise the problem existed here. He seems to very dedicated towards his 'job', ta for the info again mate.. Quote
Zacker Posted December 28, 2004 Author Report Posted December 28, 2004 Correct, that code uses Google and they have prevented that now. The exploit however is still there. Google was used to find exploitable sites. You can do it manually by doing a search and then using highlight. Through the highlight you can make an SQL-injection. You can fix this by removing the url decoding(at the highlight html parsing) in viewtopic.php. Quote
Section_Ei8ht Posted December 29, 2004 Report Posted December 29, 2004 True. A design forum I hang out in was hacked a few weeks ago. Of course we found out the hacker and thus lets just say that reperations have been served... harshly... Quote
Thrik Posted December 29, 2004 Report Posted December 29, 2004 Hopefully Mikey backs this forum up! D: Quote
OL Posted December 29, 2004 Report Posted December 29, 2004 Hopefully Mikey *reads* this forum! D: Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.