Author |
Message |
![[Post New]](/forum/templates/html/images/icon_minipost_new.gif) 13/05/2005 14:06:01
|
okcamp
Beginner
Joined: 08/11/2004 22:02:55
Messages: 19
Location: U.S.A.
Offline
|
Yesterday I received this message from my ISP:
"There was a recent security issue with older phpBB versions. More
information on this can be found here:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=288194.
If you use this script, please ensure you have upgraded to the latest version, 2.0.15. If you do not use this script, you do not need to do anything.
phpBB boards running versions less than 2.0.15 must be upgraded."
We run Guestbook v2.2 and I don't know if this pertains to us or not. Before I start searching for and relacing code I'd like to be somewhat sure that I know what I'm doing.
Carbonize....your advice, please.
|
|
![[Post New]](/forum/templates/html/images/icon_minipost_new.gif) 13/05/2005 14:28:38
|
Auron
Expert
![[Avatar]](/forum/images/avatar/13803940053f323eaa510a6.jpg)
Joined: 23/06/2003 22:02:17
Messages: 1053
Offline
|
phpbb and the guestbook are two COMPLETELY DIFFERENT php scripts.
Update phpBB at www.phpbb.com
The email does not mention the gb so it's VERY obvious it has nothing to do with the gb and JUST phpBB.
|
Visit my site @ www.ragnaru.com
Adv. Poll Install Guide NOW BACK ONLINE! (And also rather out of date I would of thought) |
|
![[Post New]](/forum/templates/html/images/icon_minipost_new.gif) 13/05/2005 14:34:50
|
okcamp
Beginner
Joined: 08/11/2004 22:02:55
Messages: 19
Location: U.S.A.
Offline
|
Auron,
VERY obvious to you.....
I do appreciate the response.
|
|
![[Post New]](/forum/templates/html/images/icon_minipost_new.gif) 13/05/2005 14:48:20
|
Carbonize
Master
![[Avatar]](/forum/images/avatar/96871336492d73e733f55.jpg)
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
One of the downsides of using phpBB like this site and my own do is that it is a target of a lot of nwanted attention.To this end it is regularly being updated to fix exploits that have been found. This does not mean that it's makers cannot write good script but that in any large project you are going to have bugs and security issues. So long as you have not modified your copy of phpBB you can simply just upload the changed files otherwise you will have to manually edit the files.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
![[Post New]](/forum/templates/html/images/icon_minipost_new.gif) 13/05/2005 14:56:38
|
okcamp
Beginner
Joined: 08/11/2004 22:02:55
Messages: 19
Location: U.S.A.
Offline
|
I plan to contact the ISP to see if and how the message pertains to me.
We don't have any forms on our website and the only php scripts we use are in the guestbook.
There is no copy of phpBB in our directory.
|
|
![[Post New]](/forum/templates/html/images/icon_minipost_new.gif) 13/05/2005 15:16:43
|
Carbonize
Master
![[Avatar]](/forum/images/avatar/96871336492d73e733f55.jpg)
Joined: 12/06/2003 19:26:08
Messages: 4292
Location: Bristol, UK
Offline
|
Sounds like the usua knee jerk reaction from an ISP who doesn't bother to check things out. Had a similar problem with lunarpages telling everyone to remove Advanced Guestbook just because of the 2.2 login exploit.
|
Carbonize
I am not the maker of the Advanced Guestbook
get Lazarus |
|
|