4WebHelp
 FAQ  •  Search  •  User Groups  •  Forum Admins  •  Smilies List  •  Statistics  •  Rules   •  Login   •  Register
Toggle Navigation Menu

 Security problem with phpBB 2
Post New TopicReply to Topic
View Previous Topic Print this topic View Next Topic
Author Message
Daniel
Team Member



Joined: 06 Jan 2002
Posts: 2564

PostPosted: Mon Mar 18, 2002 8:28 pm (22 years, 1 month ago) Reply with QuoteBack to Top

Please read this topic at the phpBB Development Board: http://phpbb.sourceforge.net/phpBB2/viewtopic.php?t=9105

________________________________
Image
OfflineView User's ProfileFind all posts by DanielSend Personal Message
Justin
4WebHelp Addict
4WebHelp Addict


Joined: 07 Jan 2002
Posts: 1060

PostPosted: Mon Mar 18, 2002 9:02 pm (22 years, 1 month ago) Reply with QuoteBack to Top

Sounds nasty, I presume RC-4 will be out later, I am on RC-2, and wasn't planning on upgrading until the final version, but this pretty much changes that Sad
OfflineView User's ProfileFind all posts by JustinSend Personal MessageSend email
Daniel
Team Member



Joined: 06 Jan 2002
Posts: 2564

PostPosted: Tue Mar 19, 2002 7:11 am (22 years, 1 month ago) Reply with QuoteBack to Top

You could always make the recommended changes and not upgrade... That's what I did.

________________________________
Image
OfflineView User's ProfileFind all posts by DanielSend Personal Message
szo2
Junior WebHelper
Junior WebHelper


Joined: 10 Jan 2002
Posts: 18
Location: Hong Kong

PostPosted: Tue Mar 19, 2002 9:17 am (22 years, 1 month ago) Reply with QuoteBack to Top

Can't you just use .htaccess and deny all http access to the dir includes?
OfflineView User's ProfileFind all posts by szo2Send Personal MessageSend email
Daniel
Team Member



Joined: 06 Jan 2002
Posts: 2564

PostPosted: Tue Mar 19, 2002 5:22 pm (22 years, 1 month ago) Reply with QuoteBack to Top

I guess you could. I would still apply the recommended changes just in case though...

________________________________
Image
OfflineView User's ProfileFind all posts by DanielSend Personal Message
Justin
4WebHelp Addict
4WebHelp Addict


Joined: 07 Jan 2002
Posts: 1060

PostPosted: Tue Mar 19, 2002 6:26 pm (22 years, 1 month ago) Reply with QuoteBack to Top

Any rough ideas when they plan on releasing RC-4, I have a few clients that need a bulletin board installed, I was supposed to do it yesterday but I heard this so I told them to wait for RC-4 to come out then I would Install the script for them.

Only thing is I kinda hope it's soon or they get their script installs half price! Twisted Evil
OfflineView User's ProfileFind all posts by JustinSend Personal MessageSend email
Daniel
Team Member



Joined: 06 Jan 2002
Posts: 2564

PostPosted: Tue Mar 19, 2002 6:28 pm (22 years, 1 month ago) Reply with QuoteBack to Top

Why don't you just install it, and make the recommended changes? You could also use htaccess to protect the includes directory, as recommended above.

________________________________
Image
OfflineView User's ProfileFind all posts by DanielSend Personal Message
Justin
4WebHelp Addict
4WebHelp Addict


Joined: 07 Jan 2002
Posts: 1060

PostPosted: Tue Mar 19, 2002 6:43 pm (22 years, 1 month ago) Reply with QuoteBack to Top

The Customer is using Microsoft FrontPage based uploads, which requires the fact that we can't upload a .htaccess file, and the customer specifically requested that he wishess to wait until the RC-4 comes out, because there are rumours that there are a few more minor security flaws that will be fixed in the new release.

Just wish it would come out soon, was supposed to be last night!
OfflineView User's ProfileFind all posts by JustinSend Personal MessageSend email
Daniel
Team Member



Joined: 06 Jan 2002
Posts: 2564

PostPosted: Tue Mar 19, 2002 6:46 pm (22 years, 1 month ago) Reply with QuoteBack to Top

I wouldn't give the customer a discount for being late if they specifically requested you not install RC3...

________________________________
Image
OfflineView User's ProfileFind all posts by DanielSend Personal Message
Justin
4WebHelp Addict
4WebHelp Addict


Joined: 07 Jan 2002
Posts: 1060

PostPosted: Tue Mar 19, 2002 6:51 pm (22 years, 1 month ago) Reply with QuoteBack to Top

I wouldn't normally either, but as we're new, we have to build up a reputation, although when you have a large number of emails coming a day, it can get you down a bit. Good Customer services though, can do us no harm Smile.
OfflineView User's ProfileFind all posts by JustinSend Personal MessageSend email
Daniel
Team Member



Joined: 06 Jan 2002
Posts: 2564

PostPosted: Wed Mar 20, 2002 7:51 pm (22 years, 1 month ago) Reply with QuoteBack to Top

Seems like the phpBB Group forgot to patch up ONE file, prune.php (in the includes directory)... See http://phpbb.sourceforge.net/phpBB2/viewtopic.php?t=9252 . I've patched this board manually. Maybe we'll get an RC5? Smile

________________________________
Image
OfflineView User's ProfileFind all posts by DanielSend Personal Message
Display posts from previous:      
Post New TopicReply to Topic
View Previous Topic Print this topic View Next Topic


 Jump to:   




You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot edit your posts in this forum.
You cannot delete your posts in this forum.
You cannot vote in polls in this forum.


Page generation time: 0.383157 seconds :: 18 queries executed :: All Times are GMT
Powered by phpBB 2.0 © 2001, 2002 phpBB Group :: Based on an FI Theme