#1 (permalink)  
Old 11-17-2008, 02:28 PM
geek's Avatar
Senior Member
 
Join Date: Apr 2008
Posts: 1,274
Default Phpbb 3

I was recently asked to look at this forum software and I have to say it is desperately wanting. I can't believe people still use it, there are so many security holes there it ain't funny. Any thoughts?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 11-17-2008, 05:56 PM
Member
 
Join Date: Apr 2008
Posts: 92
Default

Are you serious?

There were many old versions of phpBB 2 that had major security holes, however people did not update their forum software, causing large amounts of damage on many forums around the net.

Ever since then, phpBB has ensured to keep very tight code. When phpBB 3 was in beta, a professional third party code auditing team was brought in to audit the code to ensure they did a good/secure job.

I would say phpBB 3 is one of the most secure piece of PHP based online forum software.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 11-18-2008, 09:20 PM
geek's Avatar
Senior Member
 
Join Date: Apr 2008
Posts: 1,274
Default

Well then it must be the addons or modifications that open it back. However their registration process is wanting. I mean anyone could bypass their captcha.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 11-19-2008, 12:20 AM
Member
 
Join Date: Apr 2008
Posts: 92
Default

The captcha is totally controllable via the admin control panel, by default it's of decent complexity and can be greatly improved with tighter settings. I have yet to observe any auto-registering bots on any phpBB3 forum.

Yes, MOD's can create security risks, however all mods in the "Official Mod Database" have been code audited for security, and are usually regularly maintained.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 11-19-2008, 12:43 PM
bdh734's Avatar
Senior Member
 
Join Date: Jun 2008
Location: A small room with flickering blue and green lights
Posts: 309
Send a message via MSN to bdh734 Send a message via Yahoo to bdh734
Default

Yes, I agree with PCGUY112887, phpBB version 3 is secure out of the box. But when you add mods you are adding code that was not tested with the original release. Therefore the risks are increased. But the community does try to audit and inform of any security risks. I also do not know of any bots that will register and bypass the captcha.
__________________
For HELP, summon support with the Bat-Signal: http://support.hostv.com/

Sysadmins are sexy.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 11-20-2008, 11:43 PM
geek's Avatar
Senior Member
 
Join Date: Apr 2008
Posts: 1,274
Default

I would not call it secure out of the box with so many spam bots walking all over so many of their forums.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 11-21-2008, 09:30 AM
bdh734's Avatar
Senior Member
 
Join Date: Jun 2008
Location: A small room with flickering blue and green lights
Posts: 309
Send a message via MSN to bdh734 Send a message via Yahoo to bdh734
Default

It is secure out of the box...what do you mean spam bots walking all over on so many of their forums?
Explain.
__________________
For HELP, summon support with the Bat-Signal: http://support.hostv.com/

Sysadmins are sexy.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 11-25-2008, 02:39 PM
Senior Member
 
Join Date: Apr 2008
Posts: 1,345
Default

The registration page uses an archaic captcha that can be walked over by spam bots. Better protection is a must.
__________________
Health!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 04-14-2010, 09:19 AM
Junior Member
 
Join Date: Mar 2010
Location: Uzbekistan
Posts: 1
Send a message via ICQ to Mooryescors
Default

cash on delivery online prescriptions lovegra
__________________
tenuate and levitra
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 06-17-2010, 11:46 PM
Junior Member
 
Join Date: Mar 2010
Location: Luxemburg
Posts: 1
Send a message via ICQ to Pypedyess Send a message via Yahoo to Pypedyess
Default Excellent site! Great work! Cheers!

I found this site using google.com. And i want to thank you for your work. You have done really excellent site. Great work, great site! Cheers!

Sorry for offtopic
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 09:56 AM.


Powered by: vBulletin
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15