Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 22
  1. #1
    Member Planet_Master's Avatar
    Join Date
    Apr 2002
    Location
    New Yorker
    Posts
    260

    Exclamation Security vulnerability: phpBB

    SQL injection in phpBB

    Description:
    The remote host is running a version of phpBB older than 2.0.7. There is a flaw in the remote software which may allow anyone to inject arbitrary SQL commands, which may in turn be used to gain administrative access on the remote host or to obtain the MD5 hash of the password of any user.

    Solution : Upgrade to the latest version of this software
    Risk Factor : Serious

    Had problems on my server with customers using old versions of this software, good thing I caught the problem quickly and had them all update their boards. Suggest you ask your customers to do the same if running versions older then 2.0.7
    Vision Plateau Web Services - Total Control Hosting
    http://www.visionplateau.com

  2. #2
    Member
    Join Date
    Oct 2003
    Location
    127.0.0.1
    Posts
    34

    Default

    yay, something for me to exploit...
    /me goes off and hacks many many many webhosts... *evil laugh*
    [N/A] Server Administrator.
    Development team of [N/A].
    Certified professional in [N/A] by [N/A].

  3. #3
    Member
    Join Date
    Oct 2003
    Location
    Nirvana
    Posts
    184

    Default

    There is no 2.0.7, 2.0.6 is the latest...
    http://www.lifelesspeople.com/ The revolution has begun! Pay by Post™ Webhosting is here!

  4. #4
    Member Planet_Master's Avatar
    Join Date
    Apr 2002
    Location
    New Yorker
    Posts
    260

    Default

    2.0.6 has been updated with the fixes just redownload this version and overwrite your files. Make sure you save the database config file and you will lose any hacks you may have installed.
    Vision Plateau Web Services - Total Control Hosting
    http://www.visionplateau.com

  5. #5
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    The changelog mentions a somewhat auspiciously timed update of phpBB to 2.0.10a. I am curious to know if this update includes this change.

    BTW, 2.0.11 has been released which includes the above linked security fix as well as a few other updates.

  6. #6
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default

    What is the exploit for this?

    Is it possible to block it with mod_security?

  7. #7
    Member
    Join Date
    Sep 2004
    Posts
    529

    Default

    umm, why not just fix the security problem in the first place? Instead of trying to keep people from using the exploit? Seems like a band-aid fix to me.

  8. #8
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Agree, it literally takes 5 minutes to update to the lastest, never ever compromise or "quick fix" when it comes to security.
    Regards,
    David
    Forum Moderator

  9. #9
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Quote Originally Posted by dgbaker
    Agree, it literally takes 5 minutes to update to the lastest, never ever compromise or "quick fix" when it comes to security.
    How do you upgrade phpbb forums using tons of mods in 5 minutes though?

  10. #10
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    You are right, with regards to mods, but that holds true for any upgrade of any software. The 5 minute upgrade is for upgrading phpBB standard files and information, any mods would have to be redone again. You should though at the very least do the viewtopic fix as noted on their forum.
    Regards,
    David
    Forum Moderator

  11. #11
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    Quote Originally Posted by dgbaker
    You are right, with regards to mods, but that holds true for any upgrade of any software. The 5 minute upgrade is for upgrading phpBB standard files and information, any mods would have to be redone again. You should though at the very least do the viewtopic fix as noted on their forum.
    Yup, I did the viewtopic fix yesterday. From what I understand it is the only critical issue. The other issues that are fixed in 2.0.11 seem less serious.

    I'll do the upgrades to 2.0.11 when I have time since it will take a while to reinstall all the mods.

  12. #12
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default

    Quote Originally Posted by dezignguy
    umm, why not just fix the security problem in the first place? Instead of trying to keep people from using the exploit? Seems like a band-aid fix to me.
    Do you have to fix it on each account that is using it?

    How do I know who is using it?

    If I have 1,000 people using it would take over 10 days to fix assuming there was nothing else to do during those days.

  13. #13
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Do a locate for viewtopic.php, that will tell you how many need to be possibly updated. Then you can either change them one each or replace all of them with a patched one.

    I would not risk my servers and business to avoid extra work, unfortunatly this is part of having and running a business. You sometimes have to do a lot of extra work.
    Regards,
    David
    Forum Moderator

  14. #14
    BANNED
    Join Date
    Oct 2004
    Posts
    166

    Default

    # locate viewtopic.php | wc -l
    179
    times 50 servers
    about 44750 minutes or 34 business days

  15. #15
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Quote Originally Posted by EdRooney
    # locate viewtopic.php | wc -l
    179
    times 50 servers
    about 44750 minutes or 34 business days

    So, by those numbers, you mean to tell me you have 8900+ clients and you do not have staff that manage the servers? Or an automated process for mass updates? How do think EV1 and the likes do it? They either mass automate or they do each server with a script. This is actually less effort than running easyapache is. Write a simple shell script that does locate and replaces with a patched one. It would take you only a few minutes to write the script.

    But hey, it's your server and clients that get screwed, so it's all up to you how you do it or don't do it.
    Regards,
    David
    Forum Moderator

Similar Threads & Tags
Similar threads

  1. phpBB vulnerability? Have you seen this?
    By wa4fat in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 07-02-2005, 06:46 PM
  2. Security Vulnerability?
    By anup123 in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 06-22-2005, 05:30 PM
  3. ClamAV Security Vulnerability
    By fizz in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-14-2004, 09:09 AM
  4. css vulnerability in phpBB
    By netwrkr in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 01-03-2004, 08:58 PM
  5. Security vulnerability in PHP
    By GordonH in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 12-31-2003, 10:18 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube