Ahem ... maybe a good time to upgrade Qt3 phpBB?

Qt3 is currently sitting on v2.0.8 - latest version is 2.0.11. Might be a good time to upgrade considering all the security issues and bugs fixed.

[size=1]And add that RSS feed thing too![/size]

:wink:

The bottom just doesn’t say it, but we upgraded what needed upgrading during the last security issue. Past what was already patched by hand, the 11 update doesn’t bring much. At some point i will upgrade but the bigger upgrade at some point may be the upgrade to vbulletin. I am still testing it.

Chet

It fixes the viewtopic.php security bug. Another forum I am on was penetrated with it. Every index.php for every domain on the entire server was overwritten with a “p0wned” defacement page. Yes, they were “locked down” through virtual servers. Just FYI you may want to make sure that one’s handled duder.

Any particular reason you are considering vBulletin ?

It would probably take folks a couple of minutes to realize that anything had happened…

We have already made the changes for that issue, that is what i was saying. We have modified phpbb enough that applying an across the board patch can end up being a lenghthy process. But we have fixed the viewtopic issue. Also the way our servers are handled, it would contain the issue to just that site.

Vbulletin is more robust in how it handles things on the backend, as well allowing us to more on the front end without having to hack so deeply.

The people running phpbb can be real shitheads with their attitude of, our way is the right way and we will break old functionality at any time, for any reason because fuck it - we are phpbb. Vbulletin at least seems to care more about their users and keep functionality intact.

Chet

What is RSS?

Ahh, OK coolio man.

It fixes the viewtopic.php security bug. Another forum I am on was penetrated with it. Every index.php for every domain on the entire server was overwritten with a “p0wned” defacement page. Yes, they were “locked down” through virtual servers. Just FYI you may want to make sure that one’s handled duder.[/quote]

Having a virtual server does not mean anything is locked down, per se. Depends on how each site is set up – whether they are chroot-ed, etc. to prevent access to other user’s files.