|
![]() |
|
| Author |
|
|||||||
|
Term
Posts: 4274
Location: Queensland
|
There is currently a worm floating around that looks for phpbb installs with a specific version (2.0.10) that have a security flaw. As a result of this, and knowning that alot of our hosted sites dont really pay much attention to these issues, we've globally disabled viewtopic from working on the hosting servers. Until we are able to come up with a global fix we are going to leave this disabled, we apologise for any inconvenience that this will cause. |
|||||||
| #0 09:36am 21/04/06 |
|
|||||||
|
system
|
--
|
|||||||
| #0 |
|
|||||||
|
stinky
Posts: 1543
Location: Brisbane, Queensland
|
URL to worm and what it does?
|
|||||||
| #1 10:38am 21/04/06 |
|
|||||||
|
stinky
Posts: 1544
Location: Brisbane, Queensland
|
||||||||
| #2 10:46am 21/04/06 |
|
|||||||
|
Jim
Posts: 4284
Location: Brisbane, Queensland
|
I've stuck a global 'fix' in place but the best thing to do is update phpbb.
This is actually a pretty old exploit, it was fixed in phpbb 2.0.11 and it's now up to 2.0.20. I've noticed it being used on our hosting box before but not to the extent it was last night, it was actually overloading the server trying to spawn commands. |
|||||||
| #3 10:55am 21/04/06 |
|
|||||||
|
Opec
Posts: 4059
Location: Brisbane, Queensland
|
Jim just don't care
|
|||||||
| #4 10:59am 21/04/06 |
|
|||||||
|
Jim
Posts: 4288
Location: Brisbane, Queensland
|
I care
So much that I might update apache on there one day |
|||||||
| #5 11:31am 21/04/06 |
|
|||||||
|
Insom
Posts: 917
Location: Brisbane, Queensland
|
please continue
|
|||||||
| #6 11:39pm 23/04/06 |
|
|||||||
|
Jim
Posts: 4303
Location: Brisbane, Queensland
|
time for you to put more limits on the amount of penif in your mouf djzort
|
|||||||
| #7 07:47am 24/04/06 |
|
|||||||
|
Mantra
Posts: 1475
Location: Brisbane, Queensland
|
please continuetrim |
|||||||
| #8 09:29am 24/04/06 |
|
|||||||
|
Insom
Posts: 919
Location: Brisbane, Queensland
|
get an s3
|
|||||||
| #9 12:55pm 24/04/06 |
|
|||||||
|
Jim
Posts: 4305
Location: Brisbane, Queensland
|
get a job
|
|||||||
| #10 01:01pm 24/04/06 |
|
|||||||
|
Opec
Posts: 4069
Location: Brisbane, Queensland
|
your so haX0r LOL
|
|||||||
| #11 01:18pm 24/04/06 |
|
|||||||
|
stinky
Posts: 1548
Location: Brisbane, Queensland
|
hmm, technically apache is up to date.... but i didnt know php5 built against apache 1.3. that series of apache is just a distant memory... :P It wasn't until late last year/early this year ( can't remember exact date ) that apache foundation decided httpd v2 was ready for production servers. You must have a very short attention span for that to be a distant memory. |
|||||||
| #12 01:23pm 24/04/06 |
|
|||||||
|
Jim
Posts: 4306
Location: Brisbane, Queensland
|
yeah 1.3 is still maintained, and since php strongly advise using the prefork mpm with apache2 anyway, there's no big urgency to move to apache2
|
|||||||
| #13 01:46pm 24/04/06 |
|
|||||||
|
system
|
--
|
|||||||
| #13 |
|
|||||||
|
| ||||||||