Security Vulnerabilities in phpBB

Guest

Security Vulnerabilities in phpBB

This forum (phpBB 2.0.11) is vulnerable to multiple security holes which could easily be used to gain administrator access. It is very import that Forum updates to the latest version of phpBB or risk the privacy of all users. I would create an account to tell you this but I would be in danger of getting my password stolen.
[SGC_ReplicÅtors]
Forum Addict
Posts: 3949
Joined: Sun Mar 13, 2005 4:57 pm
ID: 0

what type of security holes?
User avatar
Forum
Site Admin
Posts: 2844
Joined: Sun Jan 30, 2005 1:52 pm

Honours and Awards

at least there are less holes than windows, or IE, or MSN :)
either way, will update soon...
Don't make me use this!!!
Guest

Thanks, long live open source.
myFriend
Fledgling Forumer
Posts: 154
Joined: Sat Feb 19, 2005 9:12 pm
ID: 0
Location: i am never lost i am were i am

Re: Security Vulnerabilities in phpBB

Anonymous wrote:This forum (phpBB 2.0.11) is vulnerable to multiple security holes which could easily be used to gain administrator access. It is very import that Forum updates to the latest version of phpBB or risk the privacy of all users. I would create an account to tell you this but I would be in danger of getting my password stolen.

ever herd of keeping suff like this quiet. if there is something this big you don't go and stick it for every one to know. its like shouting the bank safe is made of ducktape. PLZ use the PRIVATE MESSAGE system so you don't encerage people to try to hack! :smt075
Last edited by myFriend on Wed Apr 20, 2005 7:07 pm, edited 1 time in total.
I am dyslexic and i did do spell check. sarry for the type-o's

i will face my fears and let them past though me; we live we die... but not in vain; OO for cying out loud; Sir with all disrespect, I don't give a dam
Xavier
Fledgling Forumer
Posts: 113
Joined: Mon Mar 28, 2005 12:40 am
ID: 0
Location: Melbourne, Australia
Contact:

:-$

I agree. I would prefer only you know than the entire community.

This is a huge neon sign, saying, "Everyone please hack".

:smt021

Hopefully this thread is removed and no one speak of this again until it's updated.
Image
---
~Phoenix~ wrote:Rememberance day for what event?
forgive_me
Forum Irregular
Posts: 443
Joined: Thu Feb 24, 2005 3:45 pm
ID: 0
Location: far far away
Contact:

and wats the big thinh....its THE FORUM.....good thing that its not the game.....so who cares if u can hach the forum....u get wath...access to posts u already see......BIG THING :shock:
Xavier
Fledgling Forumer
Posts: 113
Joined: Mon Mar 28, 2005 12:40 am
ID: 0
Location: Melbourne, Australia
Contact:

I use my forum password elsewhere. Such as the SGW chatroom. Such as lots of different forums.

I'm sure there would also be people whose password for SGW is the same as their password for the forum. Access to these passwords would not be good.
Image
---
~Phoenix~ wrote:Rememberance day for what event?
forgive_me
Forum Irregular
Posts: 443
Joined: Thu Feb 24, 2005 3:45 pm
ID: 0
Location: far far away
Contact:

Xavier wrote:I use my forum password elsewhere. Such as the SGW chatroom. Such as lots of different forums.

I'm sure there would also be people whose password for SGW is the same as their password for the forum. Access to these passwords would not be good.
unless u find a way to decode the md5 WITH CHEY....than u are a genious and wont need to find a persons password to get in someones acount....

passwords are incripted with MD5(google for info) that hase a extra protection by ading a chey(in hexazecimal value).....so it will take u aprosimatly 275 days with a intel pentiun 4 at 3200Hz to decode one password....want to try? :P
Xavier
Fledgling Forumer
Posts: 113
Joined: Mon Mar 28, 2005 12:40 am
ID: 0
Location: Melbourne, Australia
Contact:

I don't know the technicalities behind it, I was just following what Guest wrote for the first post.
Image
---
~Phoenix~ wrote:Rememberance day for what event?
forgive_me
Forum Irregular
Posts: 443
Joined: Thu Feb 24, 2005 3:45 pm
ID: 0
Location: far far away
Contact:

Xavier wrote:I don't know the technicalities behind it, I was just following what Guest wrote for the first post.
trust me on this....dont belive everything a guest wrotes.....
Xavier
Fledgling Forumer
Posts: 113
Joined: Mon Mar 28, 2005 12:40 am
ID: 0
Location: Melbourne, Australia
Contact:

Ok, after our discussion in the chat room, I think I will trust you. Just a false alarm? Maybe. :)
Image
---
~Phoenix~ wrote:Rememberance day for what event?
WhiteyDude
Forum Intermediate
Posts: 845
Joined: Thu Feb 24, 2005 4:44 pm
ID: 0
Location: SGC Australia
Contact:

Apart from the typos forgive_me, you are absolutly right.

They can't really find a way to decrypt the MD5's unless they have a lot of time on their hands.

Also, please stop calling these hackers - they are crackers, not hackers.


I consider myself a hacker, as hacking is a persuit of knowlage.

Please click here to learn the difference.

Thanks guys.



/Whitey
SHIFT TONE! OMG!

STFUBBQ?

SGW-irc founder

Image
It means Perseverance
Xavier
Fledgling Forumer
Posts: 113
Joined: Mon Mar 28, 2005 12:40 am
ID: 0
Location: Melbourne, Australia
Contact:

WhiteyDude wrote:Apart from the typos forgive_me, you are absolutly right.

Be nice!!! :x I see typos in your messages too!
WhiteyDude wrote:Also, please stop calling these hackers - they are crackers, not hackers.

I consider myself a hacker, as hacking is a persuit of knowlage.

Please click here to learn the difference.

...

In that case you have pursued knowledge a lot. :P
Image
---
~Phoenix~ wrote:Rememberance day for what event?
Locked

Return to “Bugs Archive”