Page 1 of 1

Pete! Upgrade PHPBB!!!

Posted: Tue Dec 07, 2004 2:10 am
by XMark
Yo, pete, I just noticed you're running phpbb 2.0.6 on this site. I know from personal experience that this version has a major security exploit that can give hackers access to all your website's data. I know because it happened to me (twice actually). The first time my homepage got defaced and the second time they installed some kind exploit on my system that did bad stuff that I don't really understand, but my web host suspended my account because of it.

So yeah, you gotta upgrade to 2.0.11 as soon as possible. Just a friendly warning :)

Posted: Tue Dec 07, 2004 11:35 am
by Z!re
I doubt there are any security holes in 2.0.6

Posted: Tue Dec 07, 2004 12:25 pm
by MystikShadows
That's what I was saying when I had a phpNuke website...the version I used was "known to be secure" and after 2 months...some brazilian hacking crew made sure I'd never use it again.....soooooooooo....I don't go by what I read anymore, I go by what I know and an find out..... :-)

Posted: Tue Dec 07, 2004 6:14 pm
by XMark
Z!re wrote:I doubt there are any security holes in 2.0.6
Tell that to the hackers that screwed up my site through PHPBB 2.0.6 twice.

Posted: Tue Dec 07, 2004 10:13 pm
by Z!re
Like I said, i doubt it was because of phpbb 2.0.6

More likely because you installed some crappy program which had a trojan or backdoor... or you were ust silly enough to use "god" or other stupid password.


Passwords are MD5 hashed in phpbb, so you can't get to them, all youca get is the info already available in each users profile.

Posted: Wed Dec 08, 2004 2:47 am
by XMark
Nope, I can't exactly install programs on my webspace considering that the server is over at Lunarpages. And my password is strong (long, alphanumeric, makes no logical sense whatsoever)

Here's the word from the developers themselves:
http://www.phpbb.com/phpBB/viewtopic.php?t=244451

Posted: Sat Dec 11, 2004 7:55 pm
by marinedalek
I also would strongly recommend upgrading to 2.0.11 - 2.0.6 is very dated and should have been upgraded ages ago to 2.0.7,8,9 and 10 before 11 even came out.