iGuest 3 Report post Posted February 20, 2005 I notice that this forum board, powered by phpBB, is behind on its security. You guys should upgrade to version 2.0.1.1. Share this post Link to post Share on other sites
iGuest 3 Report post Posted February 20, 2005 yeah..this board have been online since 8 Nov 2004...=) Share this post Link to post Share on other sites
iGuest 3 Report post Posted February 20, 2005 I remember phpBB warns and greatly encourage everyone using older version to upgrade to 2.0.1.1 due to the santy worms. Many forum boards powered by phpBB are attacked by the worms, so the phpBB developers come out with a new version because of security. I suggest you guys to upgrade when you can. If you need help, I can offer my help. Share this post Link to post Share on other sites
iGuest 3 Report post Posted February 20, 2005 Santy's dead. Google killed fairly soon after it was released. Share this post Link to post Share on other sites
iGuest 3 Report post Posted February 20, 2005 That is correct. Google did kill it. However phpBB still want their users to be updated for security. We may never know who is able to get pass google. Like last week, phpBB site is attacked and is down for that whole week. Share this post Link to post Share on other sites
iGuest 3 Report post Posted February 20, 2005 Yeah, but that didn't have anything at all to do with the Santy worm or Google. And since the Santy worm spread using only google, it was completely stopped. No one (not even me!) can get past a google search block. It just doesn't happen.btw, you can search the query santy was using and get the blocked message: "Powered by phpbb 2.0.10" allinurl: viewtopic.php Share this post Link to post Share on other sites
iGuest 3 Report post Posted February 20, 2005 Oh! I did not do the search. I will do it soon to find out more to this. Share this post Link to post Share on other sites
iGuest 3 Report post Posted February 20, 2005 Yeah, but that didn't have anything at all to do with the Santy worm or Google. And since the Santy worm spread using only google, it was completely stopped. No one (not even me!) can get past a google search block. It just doesn't happen.btw, you can search the query santy was using and get the blocked message: "Powered by phpbb 2.0.10" allinurl: viewtopic.php Forgive me, but I don't understand how entering a search can have anything to do with hacking a bulletin board. However, I do get a blocked message when I type in the code. Share this post Link to post Share on other sites
iGuest 3 Report post Posted February 20, 2005 Yeah, let me explain. Santy was using that special Google search to identify any sites which were running phpBB 2.0.10. That query also limits the pages to the viewtopic.php file of the phpBB installation. There was a security hole in phpBB 2.0.10 in the viewtopic.php file which, if exploited correctly, would cause a buffer overflow and allow the worm to copy itself to the web server. Once it was there, it would replace the contents of all files on the server ending with certain extensions with a message saying the site has been defaced. So, in short, the google query allowed to worm to find all pages which had a security hole.Do you get it now? If not, I may be able to explain it better. Share this post Link to post Share on other sites