top_left top_right
bottom_left
Next Event: Unknown | Forum Rules | QGL Website | Event Registration
openFolder AusForums.com
iconwatfolderLineopenFolder LANs
iconwatfolderLineopenFolder QGL
iconwatfolderLineopenFolder QGL Forum
Author
Topic: Hosted site issues
Term
Posts: 4274
Location: Queensland

There is currently a worm floating around that looks for phpbb installs with a specific version (2.0.10) that have a security flaw. As a result of this, and knowning that alot of our hosted sites dont really pay much attention to these issues, we've globally disabled viewtopic from working on the hosting servers.

Until we are able to come up with a global fix we are going to leave this disabled, we apologise for any inconvenience that this will cause.
system
--
stinky
Posts: 1543
Location: Brisbane, Queensland
URL to worm and what it does?
stinky
Posts: 1544
Location: Brisbane, Queensland
http://www.securityfocus.com/bid/10701/exploit
Jim
Posts: 4284
Location: Brisbane, Queensland
I've stuck a global 'fix' in place but the best thing to do is update phpbb.

This is actually a pretty old exploit, it was fixed in phpbb 2.0.11 and it's now up to 2.0.20. I've noticed it being used on our hosting box before but not to the extent it was last night, it was actually overloading the server trying to spawn commands.
Opec
Posts: 4059
Location: Brisbane, Queensland
Jim just don't care
Jim
Posts: 4288
Location: Brisbane, Queensland
I care
So much that I might update apache on there one day
Insom
Posts: 917
Location: Brisbane, Queensland
please continue
Jim
Posts: 4303
Location: Brisbane, Queensland
time for you to put more limits on the amount of penif in your mouf djzort
Mantra
Posts: 1475
Location: Brisbane, Queensland
please continue
trim
Insom
Posts: 919
Location: Brisbane, Queensland
get an s3
Jim
Posts: 4305
Location: Brisbane, Queensland
get a job
Opec
Posts: 4069
Location: Brisbane, Queensland
your so haX0r LOL
stinky
Posts: 1548
Location: Brisbane, Queensland
hmm, technically apache is up to date.... but i didnt know php5 built against apache 1.3. that series of apache is just a distant memory... :P


It wasn't until late last year/early this year ( can't remember exact date ) that apache foundation decided httpd v2 was ready for production servers. You must have a very short attention span for that to be a distant memory.
Jim
Posts: 4306
Location: Brisbane, Queensland
yeah 1.3 is still maintained, and since php strongly advise using the prefork mpm with apache2 anyway, there's no big urgency to move to apache2
system
--
Not a new post since your last visit.
New Post Since your last visit
Back To Forum
Advertise with Us | Privacy Policy | Contact Us
© Copyright 2001-2026 AusGamers Pty Ltd. ACN 093 772 242.
Hosted by Mammoth Networks - Australian VPS Hosting
Web development by Mammoth Media.