+ Reply to Thread
Page 2 of 2
FirstFirst 1 2
Results 26 to 48 of 48

Thread: phpBB security update

  1. #26
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    I got both the patch and the changed files with no problem earlier today.

    allen

  2. #27
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    Actually for 2.0.11 to 2.0.12, it appears that there are only 14 files -- 66,900 bytes -- in various directories to over-write. I'm upgrading now, as soon as I finish a backup.

    The instructions say "As for the other upgrade procedures you should run install/update_to_latest.php after you have finished updating the files. This will update your database schema and data (if appropriate) and increment the version number."

    I see no install directory in the kit, and, of course I blew away the old one after the last upgrade. I wonder if they left it out and the upgrade is incomplete?

    I should know shortly.

    allen

  3. #28
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    Well, my board still runs, but does not display the version at the bottom.

    Now for the next one...

    allen

  4. #29
    cmyksteve's Avatar
    cmyksteve is offline Sure honey just not blue cmyksteve has a spectacular aura about cmyksteve has a spectacular aura about
    Join Date
    Feb 2004
    Location
    Ohio
    Posts
    272
    Rep Power
    51
    Quote Originally Posted by allendick
    Well, my board still runs, but does not display the version at the bottom.
    Reading on the phpBB forum, that's one of the changes. Seems the Santy worm keyed on that to find vulnerable boards.

    At midnight, the SourceForge downloads interface is still broken. There's some kind of redirect that's screwing up the downloads. So as of Monday midnight anyway- clicking these links won't work. But pasting them into your browser will deliver the files.

    Last edited by cmyksteve; 02-22-2005 at 01:31 AM. Reason: crediting source of quote

  5. #30
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    Yup, that worked, so I downloaded again, since the admin panel complained in red type that I was running an old version, even after the upgrade.

    Same files, though, as far as I can tell. Still no 'install' directory or file to run to complete the upgrade.

    allen

  6. #31
    cmyksteve's Avatar
    cmyksteve is offline Sure honey just not blue cmyksteve has a spectacular aura about cmyksteve has a spectacular aura about
    Join Date
    Feb 2004
    Location
    Ohio
    Posts
    272
    Rep Power
    51
    Quote Originally Posted by allendick
    Same files, though, as far as I can tell. Still no 'install' directory or file to run to complete the upgrade.

    allen
    Allen-

    I did get to run install/update_to_latest.php with the Changed Files package I downloaded. There were four folders already "unstuffed" (see the screen shot) before I opened the 2.0.11_to_2.0.12.tar archive.

    So in addition to "the contents" of the folders in the 2.0.11_to_2.0.12.tar archive, I also uploaded the one file from inside the cache folder and the whole folders install and contrib. Then ran install/update_to_latest.php I was then locked out of my board until I deleted those directories again.

    My Fantastico doesn't show any phpBB2 installed in that account. I'm assuming that's because I didn't use Fantastico to create that board.

    Steve
    Attached Images

  7. #32
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    Okay, thanks. That solved my problem. I was not unzipping the outer archive before unzipping the inner archive, and this did not see the other folders.

    Seems all is well, now.

    allen

  8. #33
    cmyksteve's Avatar
    cmyksteve is offline Sure honey just not blue cmyksteve has a spectacular aura about cmyksteve has a spectacular aura about
    Join Date
    Feb 2004
    Location
    Ohio
    Posts
    272
    Rep Power
    51
    The next board I updated from 2.0.11 to 2.0.12 went well also. Here's a screen shot after I ran
    Code:
    http://mydomain.com/install/update_to_latest.php
    

    In this account, Fantastico shows the version number when I first installed the board. The board's been updated several times since (without using Fantastico) and those version changes didn't register with Fantastico.
    Attached Images

  9. #34
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    Yup. Just finished all mine.

    FWIW, I notice that mine says 'mysql14', not just 'mysql', as in yours. Otherwise, it is the same.

    allen

  10. #35
    cmyksteve's Avatar
    cmyksteve is offline Sure honey just not blue cmyksteve has a spectacular aura about cmyksteve has a spectacular aura about
    Join Date
    Feb 2004
    Location
    Ohio
    Posts
    272
    Rep Power
    51
    I just checked at phpbb.com and can now get the updates through their regular SourceForge channels.
    Downloads page for 2.0.12 updates is working again.

  11. #36
    cmyksteve's Avatar
    cmyksteve is offline Sure honey just not blue cmyksteve has a spectacular aura about cmyksteve has a spectacular aura about
    Join Date
    Feb 2004
    Location
    Ohio
    Posts
    272
    Rep Power
    51

    Security update 2.0.13

    phpBB has another update- labeled Critical. Here's the info behind the update phpBB Announcement

    Here's their link for the files you'll need to keep your forum safe from attack. phpBB 2.0.13
    Last edited by cmyksteve; 02-27-2005 at 10:58 PM. Reason: typo

  12. #37
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    Thanks for that. I've done one. Three more to go.

    Hey! I'm getting pretty good at this!

    allen

  13. #38
    stratplan's Avatar
    stratplan is offline Registered User stratplan will become famous soon enough
    Join Date
    Sep 2002
    Location
    Texas, USA
    Posts
    668
    Rep Power
    79
    Quote Originally Posted by allendick
    Hey! I'm getting pretty good at this!
    allen
    Wish I was! I wiped out an installation of Mambo with an update. And yup, hadn't backed up. Duuuh.

  14. #39
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    Anybody use the Invision board, available from cPanel? I have one of them and, so far have not heard of any problems. (Not that I have been looking hard).

    allen

  15. #40
    TechWeasel's Avatar
    TechWeasel is offline Registered User TechWeasel will become famous soon enough
    Join Date
    May 2003
    Location
    Toronto, Canada
    Posts
    192
    Rep Power
    51
    I've never set up an invision board so I don't know what it's like from an admin end... Nice user interface, but I believe it requires a $70 per year user license, does it not?
    Brad

    Deadenddays.com
    The Internet's Premiere Weekly Romantic Zombie Soap Opera Comedy Video Series Thing.

    Click here to visit Page-Zone's Support Helpdesk

  16. #41
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    Really?

    It is in the Scripts Library in cPanel, and I don't see any mention of that. I have two installations and neither has given any trouble. (Actually, sinc I am looking, I notice that there is an update in the cPanel. OK. I just ran it. No problem.)

    Frankly, I haven't done any admin on it for a year, so don't recall.

    I'll have to take a look.

    allen

  17. #42
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    "I've never set up an invision board so I don't know what it's like from an admin end... "

    I've had two set up for a while, but they are not my main boards. In fact, they are almost totally unused. I set one up with the idea of using it in an interractive blog fashion, but never did.

    I just took a good look a few minutes ago, and IMO, Invision blows phpBB away on many, many fronts. Also, I have never had any problem with bad posts or emergency update announcements, as I have with phpBB.

    I guess what got me started looking is that I wanted to move topics and discussions around on one of my phpBBs and could not find a way. I went to the admin on one of my Invisions and was REALLY impressed at all the options.

    For anyone curious, I suggest installing a board to play with. It is easy to blow it away after if it is not what you want.

    Anyone have a clue on how to convert my phpBBs into Invison?

    allen

  18. #43
    TechWeasel's Avatar
    TechWeasel is offline Registered User TechWeasel will become famous soon enough
    Join Date
    May 2003
    Location
    Toronto, Canada
    Posts
    192
    Rep Power
    51
    Thanks for the heads up, I'll have to check it out.

    I'm not convinced that phpbb is any less secure than any other forum software - it's just been hammered this year because it's by far the most adopted system out there (Especially for amateur forum admins who perhaps don't lock down their systems as tight as they should)... thus it's the fattest target for script kiddies. Then again, staying away from "the fattest targets" is not a bad security strategy in and of itself! :-)

    As for converting a quick google turned up a wide selection of database converters over at Invision:

    http://www.invisionboard.com/?convertors

    Their most recent phpbb convertor is from v2.0.6 - however as they mention in this thread the mysql database is the same throughout all the v2 series of phpbb so it should work just fine up to the current v2.0.13... I'd still backup first.

    Let us know how it works for you!

    (NB: You can move posts in phpbb by clicking the "Mod Thread" button at the bottom of the page (usually looks like a page being ripped in half) which will then let you move and/or split threads...etc.)
    Brad

    Deadenddays.com
    The Internet's Premiere Weekly Romantic Zombie Soap Opera Comedy Video Series Thing.

    Click here to visit Page-Zone's Support Helpdesk

  19. #44
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52
    As for converting a quick google turned up a wide selection of database converters over at Invision
    Thanks
    Let us know how it works for you!
    Now I just need a 'roundtuit'.
    (NB: You can move posts in phpbb by clicking the "Mod Thread" button at the bottom of the page (usually looks like a page being ripped in half) which will then let you move and/or split threads...etc.)
    Thanks! I thought that I had seen something like that a long time back, but could not find it.

    phpBB could use a more intuitive interface. IMO, anyhow.

    Maybe that will solve the problems enough that I won't convert. We'll see. It appears that there are a lot of useful bells and whistles on Invision

    allen

  20. #45
    cmyksteve's Avatar
    cmyksteve is offline Sure honey just not blue cmyksteve has a spectacular aura about cmyksteve has a spectacular aura about
    Join Date
    Feb 2004
    Location
    Ohio
    Posts
    272
    Rep Power
    51

    phpBB Security update to 2.0.15

    Version 2.0.15 of phpBB was just released for bug fixes, but they also mention one serious security fix. Here's a link to their announcement on the phpBB forum.

    And a link to the udated files in their download area.
    Steve

    * * * * * * * * * * * * * * * * * * * * * * *
    Forum Announcements | Sprint Looking Glass

  21. #46
    cmyksteve's Avatar
    cmyksteve is offline Sure honey just not blue cmyksteve has a spectacular aura about cmyksteve has a spectacular aura about
    Join Date
    Feb 2004
    Location
    Ohio
    Posts
    272
    Rep Power
    51

    phpBB security update

    The phpBB Group announces the release of phpBB 2.0.16. This release addresses some bugfixes and one critical security issue.

    Here's a link to their 2.0.16 updater files


    Steve
    Steve

    * * * * * * * * * * * * * * * * * * * * * * *
    Forum Announcements | Sprint Looking Glass

  22. #47
    allendick's Avatar
    allendick is offline Registered User allendick will become famous soon enough
    Join Date
    Mar 2003
    Location
    Alberta, Canada
    Posts
    193
    Rep Power
    52

    phpBB Tip

    I got tired of SPAMmers finding my one of my phpBBs by using Google and then signing up and posting junk--or just listing a dangerous URL in the members list (that can even happen if they are not approved to post), so I tried renaming the directory where it is located, then adding that directory to my robots.txt.

    I used FrontPage to rename the directory, so I don't know if it worked any special magic while renaming, but I suspect it did not, so any otta work. I also changed the scripts directory pointer in the phpBB configuration panel to the new name. That's all I did as far as the forum is concerned. Of course, I also changed the links on my site to the new location as well.

    Seems to work--so far--and the forum runs fine. No SPAM!

    I realise that not everyone wants their forum hidden from Google, but, for those who don't care if it is indexed, here is a solution.

    YMMV.

    allen

  23. #48
    SailFan is offline Registered User SailFan is on a distinguished road
    Join Date
    Feb 2004
    Posts
    19
    Rep Power
    37
    Also, there are some pretty effective spam post prevention MODs available...

    http://www.phpbb.com/phpBB/catdb.php?cat=57

+ Reply to Thread
Page 2 of 2
FirstFirst 1 2

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. AOL Update???
    By CJD in forum General Questions and Comments
    Replies: 5
    Last Post: 01-22-2007, 04:39 PM
  2. .htaccess and phpBB security flaw
    By ENRICO in forum General Questions and Comments
    Replies: 3
    Last Post: 01-20-2005, 10:48 PM
  3. php security update
    By Sheila in forum General Discussion
    Replies: 1
    Last Post: 12-20-2004, 11:04 AM
  4. Replies: 1
    Last Post: 02-04-2004, 11:47 AM
  5. fantastico update
    By daver in forum General Questions and Comments
    Replies: 4
    Last Post: 10-07-2003, 08:30 AM

Visitors found this page by searching for:

-

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
Automatic Translations (Powered by Powered by Google):
Albanian Arabic Belarusian Bulgarian Catalan Chinese Croatian Czech Danish Dutch English Estonian Filipino Finnish French Galician German Greek Hebrew Hindi Hungarian Icelandic Indonesian Irish Italian Japanese Korean Latvian Lithuanian Maltese Norwegian Persian Polish Portuguese Romanian Russian Serbian Slovak Slovenian Spanish Swahili Swedish Taiwanese Thai Turkish Ukrainian Vietnamese Welsh Yiddish