AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 03, 2008, 05:18:05 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4766 Members
Latest Member: beverlys
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  3rd Party Software  |  Forum Software  |  Topic: Secure phpBB....How? 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Secure phpBB....How?  (Read 2137 times)
HELP!
Guest


Email
Secure phpBB....How?
« on: February 24, 2005, 10:28:12 PM »

I received a some-what rude email about securing phpBB. How do I do this? It said something about two previous notices, however, I have only received one and it was received TODAY. I was curious why I was told this in a rude way when my email was only received today. Please someone help me out with this, I need to fix this before my PAID SERVICE is SHUT DOWN!!!!!!!!!!
Logged
apache
Tech Team
Full Member
********
Offline Offline

Posts: 15


View Profile
Re: Secure phpBB....How?
« Reply #1 on: February 25, 2005, 08:00:15 AM »

Good Morning,

If the notice was misconstrude at being rude we are sorry, but we include in you Account Access Email for you to sign up in the support forums for Updates, Security Threats, and general information.  This forum is to also help benefit the customers.

I will be more than glad to help you as I can.  If you could please provide me with your domain name I can check and see what programs that were emailed to you that are at Risk. 

Also if you could please sign up for an account in the forum it would make things much easier on you and you can set certain things for you to get notified by that are of importance.  This way also if we have major conflicts and have to email the whole group you email is apart of the ones that get contacted.

Quote
K-OTik Security Advisory : KOTIK/ADV-2005-0194
CVE Reference : CAN-2005-0258 - CAN-2005-0259
Rated as : Moderate
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-02-23

 * Technical Description *

Two vulnerabilities were identified in phpBB, and may be exploited by remote attackers to read or deleted arbitrary system files. The first flaw is due to an input validation error when handling specially crafted requests to upload avatars, which may be exploited by attackers to read arbitrary system files. The second vulnerability is due to a directory traversal error when handling the "avatarselect" return value, which may be exploited by attackers to unlink arbitrary system files.

 * Affected Products *

phpBB version 2.0.11 and prior

 * Solution *

phpBB version 2.0.12 :
http://www.phpbb.com/downloads.php

 * References *

http://www.k-otik.com/english/advisories/2005/0194
http://idefense.com/application/poi/display?id=204&type=vulnerabilities
http://idefense.com/application/poi/display?id=205&type=vulnerabilities
 

This should help you in the information that you need.  Please still send me your domain name so that we can make sure all of your information and programs are up to date.

Should you need more assistance. Please post here

Thanks
Apache
Logged
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Re: Secure phpBB....How?
« Reply #2 on: February 25, 2005, 10:48:12 AM »

I received a some-what rude email about securing phpBB. How do I do this? It said something about two previous notices, however, I have only received one and it was received TODAY. I was curious why I was told this in a rude way when my email was only received today. Please someone help me out with this, I need to fix this before my PAID SERVICE is SHUT DOWN!!!!!!!!!!

Morning Josh,

First off, I am sorry you think we are being rude to demand that you keep everyone on the server protected by staying up to date with your software.  Second, as I have told you before, AOL loses email. As you can see if you look around the forums, many people DID get these mails, asked questions and complied. (And yes, that is how I knew this was your message because you are the only person who has unsecured PhpBB AND logs in via AOL).  In addition, For 3 WEEKS this same notice appeared under Important Notices on all of our Customer Access Panels.

In trouble tickets you have been advised to stay on top of this forum for important information.  That you logged in as guest, shows that you have not even created an account in the forums to STAY informed.  We even refused to let you use a password that is THE most easily guessed and hacked password on the Internet, and told you then that you had to maintain your system in a secure fashion

Our Acceptable Use Policy, which everyone indicates they have read when they place an order, states, in part:

You must adopt adequate security measures to prevent or minimize unauthorized use of your account.

I realize you do NOT run business websites here, so down time or major system slow downs caused by hacking might not be a high priority to you, but it is to most of the people who we server and it is our number ONE priority.

I am sorry AOL must have eaten the two previous emails that were sent.  Its one of the hazards of using AOL.  As we said in the notice e-mail, we are sorry we have to take such a strong stance on this.  But we can not continue to allow the inactivity of some webmasters to compromise our servers and our customers.  If you consider this rude, I am sorry, but its a fact of life.  We will no longer allow people to user or change their passwords to dictionary words and we will be spot checking sites regularly to make sure they are staying current on any 3rd party applications that have known security holes.

OUR job is to protect EVERY user on our servers.  YOUR job as a webmaster is to make sure YOU are acting responsibly by maintaining the security of your system.

As we said in our email, if you can not perform your updates, there is a good chance someone here, (or at the 3rd party application support website), can assist you.  If that is not possible, one of our technicians can perform THIS update for a small fee.  But it will still be your responsibility to stay on top of possible security holes in software YOU choose to run.

peace

Wolf
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
josh
Jr. Member
**
Offline Offline

Posts: 3


View Profile
Re: Secure phpBB....How?
« Reply #3 on: February 25, 2005, 04:03:33 PM »

Hello,

I am terribly sorry for any inconvienience that I may have caused you. After rereading my post, I did notice that it came off rude on my part, and I am terribly sorry for that, please accept mt humble apologies. I was woke up by my mother (am a junior in high school, btw) when this message appeared at about midnight last night, which frankly upset me. Then I just took it in the wrong way, I know that is no excuse.

I am sorry to the webmasters as well, it is not my fault that AOL eats messages, it is what my mother wants and pays for, so I can do nothing about it. I know I have somewhat neglected my responsiblities of being a "webmaster", but I am responsible for 4 completely different church-related website, 1 home business website, and what will soon be another (hopefully hosted at W4C). In addition, I am a junior in high-school with 2 AP Courses, church regularly, and I am the Vacation Bible School Director for our church (withing the last 2 weeks I have received over 7 packages totalling over $2000.00 in VBS product that I had to count and seperate (nearly 100 different products). I will try to focus on my websites again once the VBS rush is over in early March.

Please direct me as what I need to do to secure the site and be moved over. I assume I go to that downloads.php page and download a .zip, which one? Patch, Changes, or Full? Then upload? If I get a response in the next hour I can do it while at work and using DSL, much faster than my dial-up.

My domain is www.theapostlesyouth.com (for apache)

Terribly Sorry,

Josh
Logged
apache
Tech Team
Full Member
********
Offline Offline

Posts: 15


View Profile
Re: Secure phpBB....How?
« Reply #4 on: February 25, 2005, 04:43:26 PM »

phpBB version 2.0.12 :
http://www.phpbb.com/downloads.php

 * References *

http://www.k-otik.com/english/advisories/2005/0194
http://idefense.com/application/poi/display?id=204&type=vulnerabilities
http://idefense.com/application/poi/display?id=205&type=vulnerabilities
 

Hey Joshe go to these sites and check and see if they have the updates you require.  Another customer of ours has stated that the updates are there.

Thanks So Much
Apache
Logged
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Re: Secure phpBB....How?
« Reply #5 on: February 25, 2005, 07:50:29 PM »

Hello,

I am terribly sorry for any inconvienience that I may have caused you. After rereading my post, I did notice that it came off rude on my part, and I am terribly sorry for that, please accept mt humble apologies. I was woke up by my mother (am a junior in high school, btw) when this message appeared at about midnight last night, which frankly upset me. Then I just took it in the wrong way, I know that is no excuse.

I am sorry to the webmasters as well, it is not my fault that AOL eats messages, it is what my mother wants and pays for, so I can do nothing about it. I know I have somewhat neglected my responsiblities of being a "webmaster", but I am responsible for 4 completely different church-related website, 1 home business website, and what will soon be another (hopefully hosted at W4C). In addition, I am a junior in high-school with 2 AP Courses, church regularly, and I am the Vacation Bible School Director for our church (withing the last 2 weeks I have received over 7 packages totalling over $2000.00 in VBS product that I had to count and seperate (nearly 100 different products). I will try to focus on my websites again once the VBS rush is over in early March.

Please direct me as what I need to do to secure the site and be moved over. I assume I go to that downloads.php page and download a .zip, which one? Patch, Changes, or Full? Then upload? If I get a response in the next hour I can do it while at work and using DSL, much faster than my dial-up.

My domain is www.theapostlesyouth.com (for apache)

Terribly Sorry,

Josh

No worries Josh - I understand ALL too well how stress can make us over react or things we say come out much differently than we intended - see *my* postings regarding security from early last week.

However, you can NOT go to our level 1 techs in the tech support center for assistance.  They refer it to members of the move team.  We have stressed repeatedly that these issues can not go thru normal tech channels.

We can not upgrade these programs as we do not have the time, nor know what you have done with mods, etc.  If you can not find anyone here or at the PhpBB support forums to assist you, please POST such and we can probably find a team member who can do so for a nominal charge.

Again, this is NOT an issue for the tech support center.

thanks

Wolf
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  3rd Party Software  |  Forum Software  |  Topic: Secure phpBB....How? « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!