+ Reply to Thread
Results 1 to 6 of 6

Thread: New Exploit for PHPBB (MUST READ IN)

  1. #1

    New Exploit for PHPBB (MUST READ IN)

    http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513

    i have personally tried to hack into my own server and it taken 5 mins to own myself.

    So I highly recommend ALL hosting provider to check theirselves against this.

    A easy way of doing it will be first updatedb
    then locate viewtopic.php and then do a manual patching.
    ----------------

    Sam Tam

  2. #2
    Indeed, I've been testing it too.. however if you don't allow access to exec, system, passthru, or backticks etc it'll obviously take some of the immediate damage away. (Bar the avatar exploit, and uid one).

    Chris
    Christopher Marks
    chris@reflex.net.uk
    Reflex
    Internet
    Company No. 05527976

    Any views expressed are my own, and not those of my company.

  3. #3
    Certified Standard Host
    I have made 917 posts
    7 posts within 6 months
    Contact Me, Company profile
    BurtyB is an unknown quantity at this point
    Err your still testing a 6 month old bug?
    Chris Burton Othello Technology Systems Ltd AS29527 Company#03894981 VAT#GB-782561410 Tel:0871 277 6875
    consultancy domains email forwarding resellers ecommerce colo rackspace ip transit secondary mx/dns dedicated servers backup/DR
    * OthelloHosts.net Linux and Windows High-Availability Professional Email / Web / Secure Hosting
    * OthelloVPS.net Managed Xen Enterprise Virtual Private Servers and Dedicated Servers
    # Currently buying web hosts and domain resellers - www.hostacquisitions.co.uk
    Views expressed in this post are my own and not Othello Technology Systems Ltd.

  4. #4
    When asked to, yes
    Christopher Marks
    chris@reflex.net.uk
    Reflex
    Internet
    Company No. 05527976

    Any views expressed are my own, and not those of my company.

  5. #5
    Hasn't this been patched, in the last 3 releases of phpBB?
    James Windsor // Chocks Away!
    (url-removed: need 20 posts)

  6. #6
    I believe it has been patched. You can join phpbb mailing list for the lates updates.
    http://www.phpbb.com/support/

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. Host your phpBB forum for FREE with Hartserver!
    By hartserver in forum Web Hosting and Related Offers
    Replies: 3
    Last Post: 16th March 2009, 06:53 PM
  2. Replies: 0
    Last Post: 9th October 2005, 10:29 AM
  3. phpBB forum (and free cash!)
    By seagull in forum General Chit Chat & Discussion
    Replies: 1
    Last Post: 4th June 2004, 11:32 PM
  4. Phpbb Forums
    By Schizophonic in forum Shared and Reseller Web Hosting
    Replies: 12
    Last Post: 5th January 2004, 02:14 PM
  5. Please read before posting here
    By richard in forum Request for products or services
    Replies: 0
    Last Post: 20th May 2003, 08:17 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Content Relevant URLs by vBSEO 3.5.0 RC2