Page 1 of 2

Security Vulnerabilities in phpBB

Posted: Wed Apr 20, 2005 12:26 pm
by Guest
This forum (phpBB 2.0.11) is vulnerable to multiple security holes which could easily be used to gain administrator access. It is very import that Forum updates to the latest version of phpBB or risk the privacy of all users. I would create an account to tell you this but I would be in danger of getting my password stolen.

Posted: Wed Apr 20, 2005 2:22 pm
by [SGC_ReplicĂ…tors]
what type of security holes?

Posted: Wed Apr 20, 2005 3:02 pm
by Guest

Posted: Wed Apr 20, 2005 3:25 pm
by Forum
at least there are less holes than windows, or IE, or MSN :)
either way, will update soon...

Posted: Wed Apr 20, 2005 4:57 pm
by Guest
Thanks, long live open source.

Re: Security Vulnerabilities in phpBB

Posted: Wed Apr 20, 2005 7:00 pm
by myFriend
Anonymous wrote:This forum (phpBB 2.0.11) is vulnerable to multiple security holes which could easily be used to gain administrator access. It is very import that Forum updates to the latest version of phpBB or risk the privacy of all users. I would create an account to tell you this but I would be in danger of getting my password stolen.

ever herd of keeping suff like this quiet. if there is something this big you don't go and stick it for every one to know. its like shouting the bank safe is made of ducktape. PLZ use the PRIVATE MESSAGE system so you don't encerage people to try to hack! :smt075

Posted: Wed Apr 20, 2005 7:05 pm
by Xavier
:-$

I agree. I would prefer only you know than the entire community.

This is a huge neon sign, saying, "Everyone please hack".

:smt021

Hopefully this thread is removed and no one speak of this again until it's updated.

Posted: Wed Apr 20, 2005 7:55 pm
by forgive_me
and wats the big thinh....its THE FORUM.....good thing that its not the game.....so who cares if u can hach the forum....u get wath...access to posts u already see......BIG THING :shock:

Posted: Wed Apr 20, 2005 7:57 pm
by Xavier
I use my forum password elsewhere. Such as the SGW chatroom. Such as lots of different forums.

I'm sure there would also be people whose password for SGW is the same as their password for the forum. Access to these passwords would not be good.

Posted: Wed Apr 20, 2005 8:01 pm
by forgive_me
Xavier wrote:I use my forum password elsewhere. Such as the SGW chatroom. Such as lots of different forums.

I'm sure there would also be people whose password for SGW is the same as their password for the forum. Access to these passwords would not be good.
unless u find a way to decode the md5 WITH CHEY....than u are a genious and wont need to find a persons password to get in someones acount....

passwords are incripted with MD5(google for info) that hase a extra protection by ading a chey(in hexazecimal value).....so it will take u aprosimatly 275 days with a intel pentiun 4 at 3200Hz to decode one password....want to try? :P

Posted: Wed Apr 20, 2005 8:03 pm
by Xavier
I don't know the technicalities behind it, I was just following what Guest wrote for the first post.

Posted: Wed Apr 20, 2005 8:05 pm
by forgive_me
Xavier wrote:I don't know the technicalities behind it, I was just following what Guest wrote for the first post.
trust me on this....dont belive everything a guest wrotes.....

Posted: Wed Apr 20, 2005 8:14 pm
by Xavier
Ok, after our discussion in the chat room, I think I will trust you. Just a false alarm? Maybe. :)

Posted: Wed Apr 20, 2005 8:26 pm
by WhiteyDude
Apart from the typos forgive_me, you are absolutly right.

They can't really find a way to decrypt the MD5's unless they have a lot of time on their hands.

Also, please stop calling these hackers - they are crackers, not hackers.


I consider myself a hacker, as hacking is a persuit of knowlage.

Please click here to learn the difference.

Thanks guys.



/Whitey

Posted: Wed Apr 20, 2005 8:32 pm
by Xavier
WhiteyDude wrote:Apart from the typos forgive_me, you are absolutly right.

Be nice!!! :x I see typos in your messages too!
WhiteyDude wrote:Also, please stop calling these hackers - they are crackers, not hackers.

I consider myself a hacker, as hacking is a persuit of knowlage.

Please click here to learn the difference.

...

In that case you have pursued knowledge a lot. :P