If you are not registered or logged in, you may still use these forums but with limited features. Show recent topics
  [Search] Search   [Hottest Topics] Hottest Topics   [Members]  Member Listing   [FAQ]  FAQ 
[Register] Register / 
[Login] Login 
message from ISP re: phpBB script (Carbonize--help, please!)  XML
Forum Index » Advanced Guestbook Forum
Author Message
okcamp
Beginner

Joined: 08/11/2004 22:02:55
Messages: 19
Location: U.S.A.
Offline

Yesterday I received this message from my ISP:

"There was a recent security issue with older phpBB versions. More
information on this can be found here:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=288194.

If you use this script, please ensure you have upgraded to the latest version, 2.0.15. If you do not use this script, you do not need to do anything.
phpBB boards running versions less than 2.0.15 must be upgraded."

We run Guestbook v2.2 and I don't know if this pertains to us or not. Before I start searching for and relacing code I'd like to be somewhat sure that I know what I'm doing.

Carbonize....your advice, please.
Auron
Expert
[Avatar]

Joined: 23/06/2003 22:02:17
Messages: 1053
Offline

phpbb and the guestbook are two COMPLETELY DIFFERENT php scripts.

Update phpBB at www.phpbb.com

The email does not mention the gb so it's VERY obvious it has nothing to do with the gb and JUST phpBB.

Visit my site @ www.ragnaru.com
Adv. Poll Install Guide NOW BACK ONLINE! (And also rather out of date I would of thought)
[Email] [WWW]
okcamp
Beginner

Joined: 08/11/2004 22:02:55
Messages: 19
Location: U.S.A.
Offline

Auron,

VERY obvious to you.....

I do appreciate the response.
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

One of the downsides of using phpBB like this site and my own do is that it is a target of a lot of nwanted attention.To this end it is regularly being updated to fix exploits that have been found. This does not mean that it's makers cannot write good script but that in any large project you are going to have bugs and security issues. So long as you have not modified your copy of phpBB you can simply just upload the changed files otherwise you will have to manually edit the files.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
okcamp
Beginner

Joined: 08/11/2004 22:02:55
Messages: 19
Location: U.S.A.
Offline

I plan to contact the ISP to see if and how the message pertains to me.

We don't have any forms on our website and the only php scripts we use are in the guestbook.

There is no copy of phpBB in our directory.
Carbonize
Master
[Avatar]

Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline

Sounds like the usua knee jerk reaction from an ISP who doesn't bother to check things out. Had a similar problem with lunarpages telling everyone to remove Advanced Guestbook just because of the 2.2 login exploit.

Carbonize
I am not the maker of the Advanced Guestbook

get Lazarus
[Email] [WWW] [Yahoo!] aim icon [MSN] [ICQ]
 
Forum Index » Advanced Guestbook Forum
Go to:   
Based on the open source JForum