|
| |||||||
![]() | Welcome to iWEBTOOL Talk, where you talk about
webmaster-related stuff.
1 Register
2 Browse the board
3 Discuss whatever may interest you! | |||||||||||||
![]() |
| | Thread Tools | Search this Thread | Display Modes |
| | #1 |
| Retired Member Join Date: Dec 2005
Posts: 139
![]() | http://www.issociate.de/board/post/3...eing_prepared_ Says a mass hacking of phpBB forums may be about to happen... A bot has registered on thousands of phpBB boards around the web. The danger is that all phpBB has to do is announce a new vulnerability and BOOM - thousands hacked with one POST command button from a malicious user. What fun, eh? ![]() -Matt
__________________ Retired Moderator/Member/Friend/Helper - it was great working with all of you! |
| |
|
| |||||||
| | #2 |
| Member Contributor | compuXP, it's all about configuring. When you're buying commercial forum script (vBulletin, IPB) - you're getting all "out-of-the-box" but you spend money. When you're working with free phpBB - please, be so kind to configure it properly. Nothing is free in this world :rolleyes: |
| |
| | #3 |
| Registered Member Join Date: Dec 2005
Posts: 1,543
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | If i had the bot under my command, i woudn't be awaiting any bugs on phpBB. I'll be too busy spamming forums :p Just out of curiosity.. is anything like this happening for vbulletin :rolleyes:?
__________________ Wanna thank someone? Give 'em a rep. More info. |
| |
| | #4 |
| Retired Member Join Date: Dec 2005
Posts: 139
![]() | No, nothing like this is happening for other forum software. Even if you configure your forum, it doesn't change its security much. Also, phpBB is out of the box software, too, but the paid ones just happen to be powers of times better. Also, SMF is pretty safe. (Then again, I'm very biased FOR smf)
__________________ Retired Moderator/Member/Friend/Helper - it was great working with all of you! |
| |
| | #5 |
| Member Contributor | compuXP, kenni, let me do not agree with you. CAPTCHA check on registering will stop bots (well, I heard about bots that can pass it, but it can also be configured to level up security). You can deny posting without registering and almost all bots will fail on your phpBB copy. Also, you can deny access from known spammer IP subzones. And one more is flood-deny: you can set up an extension which will not let user make posts faster than entered time value (usually 1 minute). All this consumes time, I understand. But if you have more time than money - phpBB is your choice. |
| |
| | #6 |
| Junior Member Join Date: Mar 2006 Location: Somewhere in Asia
Posts: 66
![]() | Not the first time. Google still bans the word PHPBB because of the last exploit. PHPBB is nice but yes, it is not very secure! |
| |
| | #7 |
| Retired Member Join Date: Dec 2005
Posts: 139
![]() | Still, your forum software's insecurity should not force you to have to go to the trouble of banning IPs, etc. A good forum software should be secure and that's all there is to it.
__________________ Retired Moderator/Member/Friend/Helper - it was great working with all of you! |
| |
| | #8 |
| Junior Member Join Date: Apr 2006
Posts: 77
![]() | i think phpb is a free servise and wise one i have it one for my free website www.webdir.mobstop.com |
| |
| | #9 |
| Junior Member | Seems i have to worry now about my forum ![]() But i have email activation option so i dont think that the Bot can register now ![]() ![]() ![]() |
| |
| | #10 |
| Retired Member Join Date: Dec 2005
Posts: 139
![]() | Bots can activate via email; it's pretty easy. It signs up at a forum then checks the email a few seconds later. The latest message with the phrase "activate" or "activation" in it, usually, contains a link. In PHPBB, this is the first link in the email (or second, can't remember). It follows the link and viola.
__________________ Retired Moderator/Member/Friend/Helper - it was great working with all of you! |
| |
| | #11 |
| Junior Member | omg thats dangerous Shall i keep image verification on now? |
| |
| | #12 |
| Retired Member Join Date: Dec 2005
Posts: 139
![]() | Yes, yes, keep it on. Better yet, switch to SMF.
__________________ Retired Moderator/Member/Friend/Helper - it was great working with all of you! |
| |
| | #13 |
| wo0h0o | Your right, the bot IS caple of registering at phpbb forums. just take a look --> http://www.google.com/search?hl=com&q=FuntKlakow Personalized Results 1 - 10 of about 363,000 for FuntKlakow |
| |
| | #14 |
| Junior Member Join Date: Apr 2006
Posts: 12
![]() | I had this phantom user register on one of my forums, i simply deleted the user, banned the ip address and banned the email address.
__________________ www.quickwhois.co.uk |
| |
| | #15 |
| Permanently Banned Contributor | I don't think anyone would ever want to hack your phpbb plus if you configure your security setting properly will able to protect your phpbb. Plus you got to be very experience at hacking to able to hack Phbb. or you could go with another kind of forum the one that is free like simple machine or the one that cost money. It depends.
__________________ Albert Tai Submit your links to Webz.in Rep people on this forum if they helped you |
| |
(Threads which have no activity for more than 30 days are automatically closed.) |
| Quick Reply | ||
|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Need Backlinks For I Hate Forumer | ForumZClub | Advertise your website | 2 | 10-24-2006 01:05 PM |
| phpbb issue | UnKnown | Programming | 2 | 09-24-2006 03:12 PM |
| Getting Banned for no reason? | xpertcoder | Adsense | 19 | 07-10-2006 10:24 PM |
| Damn! Dropped out of the Index.. FOR NO REASON! | Jamneely | 2 | 06-20-2006 07:34 AM | |
| For those of you who don't hate the RIAA, you should start... | monkeyjump | Webmaster News | 3 | 12-18-2005 04:57 PM |