The Wayback Machine - https://web.archive.org/all/20050204164620/http://www.phpbb.com:80/phpBB/viewtopic.php?f=14&t=248046
PHP Bulletin Board Home
News About Home
Features of phpBB Test drive phpBB Downloads Support for phpBB The phpBB Community Styles for customising phpBB 3rd party modifications to phpBB


PHP exploits and phpBB

 
Post new topic   Reply to topic    phpBB.com Forum Index -> Announcements
View previous topic :: View next topic  
Author Message
psoTFX
Development Team Leader
Development Team Leader


Joined: 03 Jul 2001
Posts: 9388

PostPosted: 18 Dec 2004 14:57    Post subject: PHP exploits and phpBB Reply with quote

Recently a serious exploitable issue was discovered in PHP (the scripting language in which phpBB, IPB, vB, etc. are written) versions prior to 4.3.10. The problematical functions include unserialize and realpath. phpBB (along with a great many other scripts including IPB, vB, etc.) use these two functions as a matter of course.

It has come to our attention that code has now been released which uses this exploit in PHP to obtain confidential information in phpBB. Such information includes data contained in phpBB's config.php file. We therefore recommend the following:

1) If you maintain your own server be sure to upgrade to the newest available release of PHP (both versions 4 and 5). Be aware that at this time phpBB 2.0.x has problems functioning under PHP5 without modification.

2) If you pay for hosting ensure you hosting provider has upgraded thier installation of PHP (again remember that phpBB 2.0.x and other scripts will not function under PHP5 without modification).

Please do not submit this PHP issue to our security tracker, it is beyond our control. Fixed versions of PHP do exist and as above we encourage you to ensure your system is running such a version. Equally please examine any "hacking" issues you have carefully to ensure they are not caused by this PHP problem (rather than phpBB). Remember, this is not a phpBB exploit or problem, it's a PHP issue and thus can affect any PHP script which uses the noted functions.
_________________
phpBB Development Team Leader ...
... and former style guru to the stars, or maybe not.
phpBB NG | Security Tracker | Bug Tracker | da' blog
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    phpBB.com Forum Index -> Announcements All times are GMT
Page 1 of 1
Watch this topic for replies
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


News | Features | Demo | Downloads | Support | Community | Styles | Mods | Merchandise | About | Home
Host Department Web Hosting | phpBB Hosting at $7.95 | Sports Betting

Powered by phpBB © 2001, 2003 phpBB Group :: Hosting donated by Doreo Hosting

SourceForge Logo