P.Z. Low Cost CPanel Web Hosting  

Go Back   P.Z. Low Cost CPanel Web Hosting > Page-Zone Web Hosting Main Forum > Announcements

Announcements General announcements of interest to all. It is highly recommended that you subscribe to this section.

Reply
 
LinkBack Thread Tools Display Modes
Please upgrade or disable outdated php scripts
Old
  (#1 (permalink))
Jim
of Page-Zone
Jim will become famous soon enoughJim will become famous soon enough
 
Status: Offline
Posts: 1,130
Join Date: Jun 2002
Location: Wauseon, Ohio
Rep Power: 97
My location
Please upgrade or disable outdated php scripts - 03-17-2007, 01:48 AM

If anyone running outdated or insecure php scripts could update them or disable them it would be greatly appreciated. One server we just checked had quite a few outdated scripts running. For instance php bb which is one of the worst to leave even one build behind is showing a lot of outdated builds on the one server we've checked so far:

Latest 2.0.22

Version: 2.0.4, (usernames removed) /forum/
Version: 2.0.21, /fourm/
Version: 2.0.2, /forum/
Version: 2.0.2, /forum/
Version: 2.0.19, /forum/
Version: 2.0.19, /forums/
Version: 2.0.18, /main/
Version: 2.0.5, ./modules/P/NphpBB2/
Version: 2.0.21, /bb/
Version: 2.0.2, /forum/
Version: 2.0.2, /forum/
Version: 2.0.11, modules/DForum/
Version: 2.0.20, /forums/
Version: 2.0.17, /forum/
Version: 2.0.2, /legacy/
Version: 2.0.1, /
Version: 2.0.2, /forum/
Version: 2.0.0, /theo.../
Version: 2.0.4, /forum/
Version: 2.0.2, /premium/
Version: 2.0.6, /tst/
Version: 2.0.21, /forum/
Version: 2.0.20, /forum/
Version: 2.0.19, /forum/
Version: 2.0.20, /board/
Version: 2.0.19, /forum/
Version: 2.0.6, /forum/
Version: 2.0.21, /discuss/
Version: 2.0.21, /discussion/
Version: 2.0.21, /board/
Version: 2.0.17, /pcs/
Version: 2.0.0, /forum/

phpbb.com site is down due to hardware failure right now, and they say they will be down for days. But there is a link to get the newest version there

It isn't only phpbb though. Looking through a lot of defaced sites and servers at other hosting companies brings up (almost exclusively) sites running all of the major mass distributed php scripts. Joomla, et. al. and there are recent advisories out on many of the common scripts.

We have a slight amount of breathing room due to the fundamental security changes we made about this time last year which wreaked havock and caused a lot of customers to either abandon insecure scripts or move to one of those servers that are getting hacked right now.

We'll be adding some inline IDS hardware pretty soon (probably tomorrow) to make sure we stay on top of potential problems.

The real time logs (here) are showing increased sophistication and mod_security is begining to be breached although we are updated to the latest possible build and slightly into the experimental side of that code with patches. The hackers never give up and another Bushism comes to mind "they only need to be right once"

www.zone-h.org - Digital Attacks Archive: today's verified attacks


--
Thank You,
Jim Snape
Page-Zone
--
   
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Did you disable my SSH access Jim General Questions and Comments 0 07-01-2008 11:27 PM
Disable Analog stats? ldesign General Questions and Comments 0 01-07-2008 12:32 AM
Fantastico De Luxe Outdated Installations Notification edwurster General Questions and Comments 9 07-15-2007 02:13 AM
Please upgrade or disable outdated php scripts allendick General Questions and Comments 16 03-20-2007 05:58 PM
How to enable/disable ssh for existing accounts? charles Web Host Manager 3 05-22-2003 03:36 AM


Live Help



Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC6
vBulletin Skin developed by: vBStyles.com
Copyright © 2002 Page-Zone Web Hosting. All rights reserved.
Smilies provided by Crack's Smilies http://www.mysmilies.com