Jump to content

Recommended Posts

Posted

If you run any version of IPB, there has been a new security hole discovered. The ssi.php file can be SQL injected remotely allowing a cracker to gain access to the passwords (kind of a backdoor into the admin cp). The ssi.php file is only needed if you are integrating with a website (kind of like an RSS feed) and has no effect to the rest of the board if removed or renamed. I have an online friend whose forum was taken down by a cracker and when he finally got the site back up (all of the admin/mod passwords had been changed), it was taken back down again very quickly. Through the process of elimination, they discovered the problem with the ssi.php file (incidentally, a while back, it was announced that there was a problem with the ssi.php file, but it was considered to be minor). Invision worked with the webmaster of the site and they do know about the problem, so probably either expect a new security patch on the horizon or just the advice to remove/rename the ssi.php file.

Posted
and yes, I'm talking to myself again...

No worries, we are used to it.

 

Whoops B)

:lol:

Posted

I just dont use ipb but it's for different reasons. Guess I'm safe this time around. For me it's because I contribute to allot of gpl and os products and I dont care for their license.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...