Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 3 of 3
  1. #1
    Member This forum account has been confirmed by cPanel staff to represent a vendor. Radio_Head's Avatar
    Join Date
    Feb 2002
    Posts
    2,064

    Default phpbb autoinstallation security problem

    Hello,

    the autoinstallation of phpbb 2.0.2 with cpanel has a security problem , in fact at the end of installation it mantains following
    files and dir

    update_to_202.php
    upgrade.php
    install.php
    contribs directory

    In fact the installation manual report this ;

    ========================
    8. Important (security related) post-Install tasks for all installation methods
    Once you have succssfully installed phpBB 2.0.2 you MUST ensure you remove install.php, upgrade.php and update_to_202.php files. Leaving these in place is a [b:0617a44257]very serious potential security issue[/b:0617a44257] which may lead to deletion or alteration of files, etc. [b:0617a44257]Additionally you MUST remove the contrib directory once you have utilised any files it contains[/b:0617a44257]. This directory may include files which though very useful, could compromise your board or account. Beyond these essential deletions you may also wish to delete the db/schemas and docs/ directories if you wish.
    With these files deleted you should proceed to the administration panel. Depending on how the installation completed you may have been directed there automatically. If not, login as the administrator you specified during install/upgrade and click the &Administration Panel& link at the bottom of any page. Ensure that details specified in General -& Configuration are correct!
    ========================


    Another good idea should be to provide 2.0.3 instead of 2.0.2 since it fixes some security problem on 2.0.2 .


    Thank you
    Stop SPAM & VIRUS :: ASSP Deluxe for cPanel http://www.grscripts.com
    █ ASSP Deluxe is supported by Fritz Borgstedt,ASSP main developer.

  2. #2
    Member This forum account has been confirmed by cPanel staff to represent a vendor. Radio_Head's Avatar
    Join Date
    Feb 2002
    Posts
    2,064

    Default

    Anyone interested ?
    Stop SPAM & VIRUS :: ASSP Deluxe for cPanel http://www.grscripts.com
    █ ASSP Deluxe is supported by Fritz Borgstedt,ASSP main developer.

  3. #3
    Member
    Join Date
    Sep 2001
    Location
    Spain
    Posts
    779

    Default

    Have you contacted Darkorb about this?

Similar Threads & Tags
Similar threads

  1. PHPBB security issues
    By Wallaby in forum cPanel and WHM Discussions
    Replies: 18
    Last Post: 07-04-2006, 04:40 AM
  2. phpBB updates/security
    By MikeHihn in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 04-18-2005, 12:58 PM
  3. Security vulnerability: phpBB
    By Planet_Master in forum cPanel and WHM Discussions
    Replies: 21
    Last Post: 11-19-2004, 06:46 PM
  4. phpbb autoinstallation is not working
    By Radio_Head in forum cPanel and WHM Discussions
    Replies: 46
    Last Post: 10-18-2004, 04:59 PM
  5. phpbb and php security problem
    By Radio_Head in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 07-19-2002, 03:07 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube