Forum Fixing

General Moho topics.

Moderators: Víctor Paredes, Belgarath, slowtiger

Post Reply
VidE
Posts: 58
Joined: Sun Oct 22, 2006 3:34 am

Forum Fixing

Post by VidE »

Mr. Lost Marble, Administrator (Mike?) person, who is minding the forum... Thank You BIG TIME for getting the forum back and happening! Not just the posting but the search functions.
User avatar
Rasheed
Posts: 2008
Joined: Tue May 17, 2005 8:30 am
Location: The Netherlands

Post by Rasheed »

Now the server only has to be hardened against things like "SQL injection" (whatever that is). I think that is how the hackers got in the last two times.
User avatar
heyvern
Posts: 7042
Joined: Fri Sep 02, 2005 4:49 am

Post by heyvern »

I find it unlikely that any type of publicly available forum software with wide use like phpBB is going to allow "SQL injection". Possibly this could be used to just view things but not to change the database.

If this were the case then maybe a new version phpBB is probably needed... still that seems unlikely since all forums are based on sending SQL commands.

-vern
User avatar
Rhoel
Posts: 844
Joined: Fri Feb 25, 2005 8:09 am
Location: Phnom Penh, Cambodia
Contact:

Post by Rhoel »

heyvern wrote:I find it unlikely that any type of publicly available forum software with wide use like phpBB is going to allow "SQL injection". Possibly this could be used to just view things but not to change the database.

If this were the case then maybe a new version phpBB is probably needed... still that seems unlikely since all forums are based on sending SQL commands.

-vern
phpBB is now in version 3 - this board is on version 2.

3 was a top-down rebuild with specific focus on security. I have it running on another site and it does have some nice features: Some favorites are done. Not sure how Mike would do an upgrade - whether this is an auto process or not.

Rhoel
Post Reply