Jul 26, 2008

And Again A New Phpbb - phpBB 2.0.17

Free Web Hosting, No Ads > CONTRIBUTE > Computers > Computer Security Issues & Exploits
Pages: 1, 2

free web hosting

And Again A New Phpbb - phpBB 2.0.17

HoRuS
Again got me a nice email from phpBB group...:

QUOTE
Hi everyone,

phpBB Group announces the release of phpBB 2.0.17, the "no, we did not forget
naming it last time" release. This release addresses several bugfixes and some
low security issues as well as the recently seemingly wide-spread XSS issue
(only affecting Internet Explorer).

Please have a look down this announcement for the code changes necessary to fix
the XSS issue, we are again astounded about the energy people put into finding
the smallest issue in phpBB 2.0.x, those must have a lot of time available. But
on the other hand it is always increasing the products security since we do not
introduce new features into the 2.0.x codebase.

With this announcement I want to give you some more information regarding
phpBB's security. psoTFX (Paul S. Owen, Project Manager) initiated and brought
forward the idea and concept of a complete security audit of the 2.0.x codebase.
We introduced some top-notch security people, phpBB-Modders and very talented
people from our teams to participate in this audit. We intend to implement the
changes necessary - and also fixing the found issues, hopefully giving the now
very aged codebase (it is still on a technical level from three years ago) a
lift and bringing it up-to-date with security mechanisms and techniques which
are common nowadays.

We also intend to open our private bugtracker system to the public for reporting
2.0.x bugs within the next days.

As with all new releases we urge you to update as soon as possible. You can of
course find this download available on our downloads page at
http://www.phpbb.com/downloads.php.
As per usual three packages are available to simplify your update.

The Full Package contains entire phpBB2 source and English language package.
The Changed Files Only contains only those files changed from previous versions
of phpBB. Please note this archive contains changed files for each previous
release.
Patch Files contains patch compatible patches from the previous versions of
phpBB.

As always, our Code Changes Tutorial is available too for those with heavily
modded boards.
It can be downloaded from http://www.phpbb.com/phpBB/viewtopic.php?t=308426

Select whichever package is most suitable for you.

Please ensure you read the INSTALL and README documents in docs/ before
proceeding with installation or updates!.


The changelog (contained within this release) is as follows:

- Added extra checks to the deletion code in privmsg.php - reported by party_fan
- Fixed XSS issue in IE using the url BBCode
- Fixed admin activation so that you must have administrator rights to activate
accounts in this mode - reported by ieure
- Fixed get_username returning wrong row for usernames beginning with numerics -
reported by Ptirhiik
- Pass username through phpbb_clean_username within validate_username function -
AnthraX101
- Fixed PHP error in message_die function
- Fixed incorrect generation of {postrow.SEARCH_IMG} tag in viewtopic.php -
reported by Double_J
- Also fixed above issue in usercp_viewprofile.php
- Fixed incorrect setting of user_level on pending members if a group is granted
moderator rights - reported by halochat
- Fixed ordering of forums on admin_ug_auth.php to be consistant with other
pages
- Correctly set username on posts when deleting a user from the admin panel


Please read the official announcement for the code changes necessary to fix the
XSS issue:
http://www.phpbb.com/phpBB/viewtopic.php?t=308490

the phpBB Group

----
To unsubscribe from this list visit
http://www.phpbb.com/lists/?p=unsubscribe&...fa841f636eb7040



--
Powered by PHPlist, www.phplist.com --


Like the 6th time in 5 months blink.gif

 

 

 


Reply

Saint_Michael
i tell you instead of bringing out newer version build up the list for a couple of months and then work on all of them, yeah thats getting rediculous that they keep on popping out a new version everyone week can't wait .18 and .19 to come out.

Reply

odomike
well, i think they are trying to improve the board and also treat the bugs they've got in there. Or else, thyey wont ever bother.

Reply

snlildude87
It's good to see updates from PHPBB coming out that fast. It would suck if your forum all of a sudden got hacked, and you would end up looking really bad. Updates will fix that.

Reply

guangdian
im also waiting for phpbb 3.0..smile.gif

but i think phpbb should do the most effort to their skins.
the default skin is so ugly

Reply

rvalkass
It is good to see phpBB keeping on top of the bugs and errors in their system. I agree with guangdian that phpBB need to work on their themes, its been the same for ages sad.gif

Reply

hype
You've gotta wait for 3.0, or else you've to go throught with PHPBB with those keeps on upgrading of forum until you get bored out of it... smile.gif

Reply

brandice
It's good to know that they are on top of any problems that come up and put up fixes for them right away. You've got to update these things as they come out, as well. If you put it off people might exploit you.

Reply

boyCradle
Don't they have people to test their scripts first before launching their suposed "latest" versions?? It is sickening to update your phpBB frequently because your latest update has a bug or bugs.

Reply

Dragonfly
I'm struggling or stucked at phpBB 2.0.10 and see what has happen, in five months many updates have to be enforced. Its good that these guys are really working hard on those bugs, equally I have to follow their pace, but I'm not.. I just stuck in 2.0.10 and I don't have enthusiasm to update this time. Still my forum is working. I'm still observing what is going on.

Reply

Latest Entries

SecureA
oh , again security hole?

Reply

Dynomite
phpBB is good for a 100% free forum that you can get premoddified versions of. You really can't compare it to IPS's IPB or Jelsoft's VBulliten. The people working on phpBB have jobs, they make their program for free. The people working on IPB and VBulliten are paid, they can spend hours and hours working on super-boards. If the phpBB staff didn't have to work they would probably have better software.
I think phpBB is great, the exploits are usually fixed within a day after an exploit or bug is fixed, and sometimes they fix them before any exploits are discovered.

Reply

Thunder
There are alot of new forums comming out. Invision with its 2.1 beta and Vbulletin with their 3.5. Everybody always competing to produce the better stuff but i dont know Vbulletin and Invision Power Board pretty competetive right now so lets see who is better and will win the challenge i guess. Those are the only two i'd recommend atleast. PHPBB sucks i think.

Reply

steven
I was starting to cry before, but now that i read your reply, thanks for the advice. laugh.gif

Reply

badinfluence
QUOTE(steven @ Jul 22 2005, 12:47 PM)
Oh man!! Why?

I can't keep up with those phpbb guys because I was thinking of putting a phpbb forum on my website. However I do have a question: on trap17, will the new version be automatically updated for hosted users?

I am not sure. Please reply.        biggrin.gif
*



i'm afraid off topic but quick replay "no".. trap17 maintain the most stable release of every scripts. but instaling latest phpBB by manual isnt that hard. find something under tutorial section. for the topic, if you want to get running phpBB 2.0.17, update or install by manual. get some guide from phpbbhacks.com also. smile.gif

Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.
Confirm Code:

Pages: 1, 2
Similar Topics

Keywords : phpbb, phpbb, 2, 0, 17

  1. Hackers Hijack A Half-million Sites: Phpbb Forum Users Must Read
    (8)
  2. Phpbb 2.0.18
    Released on the 31st (12)
    To anyone out there using phpBB, the next release has been sent out. Report:
    http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=336756 Download:
    http://www.phpbb.com/downloads.php Additional Download for the Changed Files Only:
    http://www.phpbb.com/files/releases/change...8_repackage.zip I found an error! One of the
    reports was made by myself. Even though it was not a bug, it was about the cosmetic display on the
    index page concerning the subSilver template. As people may have noticed, the ''Mark all
    forums read'' is displayed before you even....
  3. [exploit] Phpbb <=2.0.12 Vulnerability.
    How to be Admin on phpBB in Simple steps (2)
    Another vulnerability in PHPbb based forums that can be used to easily gain any user level access to
    the forum. Even the admin account is not not secure with the default setup. Click Here for more
    details about -"How to be Admin on phpBB in Simple steps!" And here is the Homepage of
    PHPbb and click here to download the latest version.....
  4. [exploit] Phpbb 2.0.15 "viewtopic.php"
    Remote PHP Code Execution Exploit (3)
    phpBB 2.0.15 "viewtopic.php" Remote PHP Code Execution Exploit #!/usr/bin/pyth0n print
    "\nphpBB 2.0.15 arbitrary command execution eXploit" print " 2005 by rattle@awarenetwork.org"
    print " well, just because there is none." import sys from urllib2 import Request, urlopen from
    urlparse import urlparse, urlunparse from urllib import quote as quote_plus INITTAG = ' '
    ENDTAG = ' ' def makecmd(cmd): return reduce(lambda x,y: x+'.chr(%d)'%ord(y),cmd
    ,'chr(%d)'%ord(cmd )) _ex = "%sviewtopic.php?t=%s&highlight=%%27." _ex += ....
  5. Phpbb 2.0.16 Is Out!
    A new version again... (8)
    PhpBB, one of the most popular PHP based forums is here out in the form of a new version - 2.0.16. A
    few critical issues were corrected, but other than that, nothing special... Still waiting for
    Olympus /sad.gif' border='0' style='vertical-align:middle' alt='sad.gif' /> QUOTE Hi
    everyone, phpBB Group announces the release of phpBB 2.0.16. This release addresses some bugfixes
    and one critical security issue. To fix this, please apply the following change: In viewtopic.php
    Find: CODE $message = str_replace('"', '"', substr....
  6. Phpbb Upload Script "up.php" Arbitrary File Upload
    (0)
    To: BugTraq Subject: phpBB Upload Script "up.php" Arbitrary File Upload Date: Apr 8 2005 2:21AM
    Author: Status-x Message-ID:
    ##################################################################### Advisory #1 "phpBB Upload
    Script "up.php" Arbitrary File Upload" $ Author: Status-x $ Contact: phr4xz gmail com -
    status-x hackersoft net $ Date: 7 April 2005 $ Website: http://defacers.com.mx $
    Original Advisory: http://www.defacers.com.mx/advisories/2.txt $ Risk: High $ Vendor
    URL: http://phpbb.com $ Affected Software: phpB....
  7. Phpbb 2.0.15 Is Out!
    (15)
    phpBB 2.0.15 is out! It has a few bugfixes and improved security features. Don't wait to be
    a victim of an exploit! You can download it from here: http://www.phpbb.com/downloads.php
    Here is the notification e-mail that I have received: QUOTE("The phpBB team") Hi everyone,
    phpBB Group announces the release of phpBB 2.0.15, the "summer needs to be hot" release. This
    release addresses some bugfixes and addressing some security issues, one being serious. With this
    release the admin re-authentication security feature from phpBB Olympus has been backported....
  8. Bugs Found In Phpbb 2.0.13
    PhpBB 2.0.14 released to fix them (8)
    Recently, a few exploits were made for phpBB 2.0.13 (like this one):
    http://lists.virus.org/bugtraq-0503/msg00109.html And some bugs were noticed as well (like this
    one): http://www.addict3d.org/index.php?page=vie...ecurity&ID=3563 And so, the phpBB team has
    released a new version of phpBB - 2.0.14. Here is the e-mail that I have received from their mailing
    list: QUOTE(phpBB list) Hi everyone, phpBB Group announces the release of phpBB 2.0.14, the "We
    know we are (not) furry" edition. This release addresses some bugfixes as well as fixing some minor
    non-critic....
  9. Phpbb Exploit
    (17)
    Recently, an exploit has been found out that allows people to use their cookies to gain access to
    the ACP. And Firefox assists with it /ohmy.gif' border='0' style='vertical-align:middle'
    alt='ohmy.gif' /> ! Basically what happens that is when you visitthe phpBB forum, it logs a
    cookie containing your Session ID (Basically who and when you are). What it does, after much
    decoding and encoding, is allows you to replace your SID with the admin's, thus enabling them to
    gain access. To fix this, upgrade to the latest version of phpBB, 2.0.13. Dun dun dunnnnn! B....
  10. Phpbb Hackers
    LOL (21)
    I got an email today: The following is an email sent to you by an administrator of "KORUPTION OWNZ
    YOUR S****Y SITE". If this message is spam, contains abusive or other comments you find offensive
    please contact the webmaster of the board at the following address: korupted@korupted.com Include
    this full email (particularly the headers). Message sent to you follows:
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Dear members. Your petty website has been hacked. The hacker's
    name is Koruption. Next time dont use a outdated verison of phpbb b***hes So im a bit pissed off
    and chec....
  11. Phpbb Exploit
    PhbBB exploits unleashed! (4)
    /laugh.gif' border='0' style='vertical-align:middle' alt='laugh.gif' /> hello Oh
    !!!!! agian PHPBB exploits & bugs phpbb team must /laugh.gif' border='0'
    style='vertical-align:middle' alt='laugh.gif' /> dead check here
    http://k-otik.com/exploits/20050228.phpbbsession.c.php /wink.gif' border='0'
    style='vertical-align:middle' alt='wink.gif' /> for more security use IPB OR VBULLETIN
    /unsure.gif' border='0' style='vertical-align:middle' alt='unsure.gif' /> Thanks Best REgars ,
    liridonahm EDIT : PHPBB EXPLOITS, Trap17 is not responsible ....

    1. Looking for phpbb, phpbb, 2, 0, 17

Searching Video's for phpbb, phpbb, 2, 0, 17
advertisement



And Again A New Phpbb - phpBB 2.0.17



 

 

 

 

ADD REPLY / Got an Opinion! Remove these ADs! RAPID SEARCH! Free Web Hosting [X]
Express your Opinions, Thoughts or Contribute more info. to help others.
Ask your Doubts & Queries to get answers, So that "Together We can help others!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE