SECURITY WARNING!
Moderators: Krom, Lothar, Richard Cranium, KoolBear
- Wolf on Air
- DBB Admiral
- Posts: 1872
- Joined: Mon Dec 13, 1999 3:01 am
- Location: Stockholm, Sweden
- Contact:
SECURITY WARNING!
[Lothar is right - edited this out within minutes - I panicked, and forgot about the PM function]
- Krom
- DBB Database Master
- Posts: 16138
- Joined: Sun Nov 29, 1998 3:01 am
- Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
- Contact:
If its a big one, fix it, but otherwise theres not much point, this isnt even the latest version of phpbb so it lacks a number of security fixes that exist in 2.0.8a. Its too much of a pain to upgrade a BB with hacks installed anyway, you have to manually apply the updates one file at a time, or reinstall all the hacks everytime you upgrade.
- SSX-Thunderbird
- DBB Admiral
- Posts: 1275
- Joined: Sun Jun 03, 2001 2:01 am
- Location: Washington (the state, not the city)
Um... just so you know this security exploit -- which is present in 2.0.8 -- is not related to hacks in any way. It's a basic feature of phpBB and in order to be exploitable a generic PHP setting must be set a certain way.
Don't assume automatically that it has to do with the customizations in use on this BB. Technically, this entire layout is a "hack".
Don't assume automatically that it has to do with the customizations in use on this BB. Technically, this entire layout is a "hack".
- SSX-Thunderbird
- DBB Admiral
- Posts: 1275
- Joined: Sun Jun 03, 2001 2:01 am
- Location: Washington (the state, not the city)
I know damn well how the "hacks" are implemented. Core phpBB files = files as they come with phpBB.
The particular file affected by this exploit isn't modified by any of the customizations on this board, to the best of my knowledge. And the only reason that the code is susceptible to the vulnerability is because of an error on the part of the programmer who wrote the particular file. I'm assuming you know the details of the exploit, Krom.
The particular file affected by this exploit isn't modified by any of the customizations on this board, to the best of my knowledge. And the only reason that the code is susceptible to the vulnerability is because of an error on the part of the programmer who wrote the particular file. I'm assuming you know the details of the exploit, Krom.
-
- Defender of the Night
- Posts: 13477
- Joined: Thu Nov 05, 1998 12:01 pm
- Location: Olathe, KS
- Contact:
You realize that the only hacks that are installed are simple text edits....right? All thats required is to copy and paste the added lines (which are separated from everything else by comments) into notepad and re-add them after the upgrade. Its as simple as that.Lothar wrote:Isn't that why we don't have hacks installed?