Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
2 registered (Peter, tradge), 31 Guests and 16 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 05/13/08
Posts: 596
Top Posters (30 Days)
Ruben 49
DennyP 24
Gizmo 23
Dunny 17
SteveS 14
AllenAyres 12
dbremer 10
drkknght00 9
SD 9
driv 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Page 1 of 2 1 2 >
Topic Options
#170913 - 12/23/06 02:02 AM Smarty - security?
Basil Offline
addict
Registered: 08/18/06
Posts: 685
Loc: Southwest US
How much more secure is smarty over just plain php scripts and why?

Basil
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#170960 - 12/23/06 07:33 PM Re: Smarty - security? [Re: Basil]
Gizmo Offline

Registered: 06/05/06
Posts: 14994
Loc: Portland, OR; USA
I don't think anyone uses smarty for "security", I believe the decision to use smarty was so people could tweak templates wthout the need to worry about them nerfing core code...
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#170979 - 12/23/06 08:38 PM Re: Smarty - security? [Re: Gizmo]
Basil Offline
addict
Registered: 08/18/06
Posts: 685
Loc: Southwest US
Well, it is my understanding that running with smarty is more secure that just running straight php. Anyway, that's one excuse I'm using to my members on my site as to why I must switch to Threads 7 (I had been hacked once before I fixed the "holes" in 6.5.X). For me I think the added security would be (should be) a seiing point.
Top
#170984 - 12/23/06 10:05 PM Re: Smarty - security? [Re: Basil]
Gizmo Offline

Registered: 06/05/06
Posts: 14994
Loc: Portland, OR; USA
haha there ya go, securty :nods:
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#170986 - 12/23/06 11:13 PM Re: Smarty - security? [Re: Gizmo]
Basil Offline
addict
Registered: 08/18/06
Posts: 685
Loc: Southwest US
It took me 36 hours with no sleep to clean up the mess when my 6.5.X was hacked. I fixed the security hole in the couple of scripts affected, but I also added some code that sends me an email with the perps IP any time someone accesses any of the affected scripts in their browser. I get about a dozen such attempts per week, no kidding (most are from Netherlands, or China). So for me, security is actually a pretty big deal anyway.
Top
#170989 - 12/24/06 12:12 AM Re: Smarty - security? [Re: Basil]
Gizmo Offline

Registered: 06/05/06
Posts: 14994
Loc: Portland, OR; USA
lol why not start banning the ip's from your server? hehe
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#170994 - 12/24/06 12:26 AM Re: Smarty - security? [Re: Gizmo]
Ian Offline
Registered: 06/05/06
Posts: 4337
Loc: Essex, UK
Basil - I get 10 attempted signups every day from spammers - but because everyone has to verify their email, none of the spammers get onto the forum - as they all seem to use invalid ones.

Of course that is no guarantee of not being hacked, but they are likely to do that without loggin on.
Top
#170996 - 12/24/06 12:30 AM Re: Smarty - security? [Re: Ian]
Basil Offline
addict
Registered: 08/18/06
Posts: 685
Loc: Southwest US
The hackers who hacked me did not need to log in, they just knew which php scripts had teh hols and were able to exploit them.
Top
#171001 - 12/24/06 01:03 AM Re: Smarty - security? [Re: Basil]
Ian Offline
Registered: 06/05/06
Posts: 4337
Loc: Essex, UK
Indeed - this is how they do it - this is why it is important to always use the latest version of any software available, as many scripts are vulnerable - of course it may not always be the forum software that is at fault.

I too have been hacked - fortunately I was able to quickly restore from a backup and patch, without too many people noticing...

And no, I was not using the latest version, so have myself to blame to a degree. Of course the issues with any upgrade is the many hacks that one tends to build in.

What people also have to remember is that an author of a piece of software may not reveal a particular security issue, so as not to alarm people - or to put at risk more people than is necessary.
Top
#171003 - 12/24/06 01:10 AM Re: Smarty - security? [Re: Basil]
jgeoff Offline
Pooh-Bah
Registered: 08/08/06
Posts: 1922
Loc: NJ

*knock on wood* I've been pretty lucky so far. 5.5 years without a major problem (spammers, haxors) w/ Classic (and now Threads).

Gotta say, my AllPosters script's support forum uses phpBB -- and even WITH CAPTCHA AND Email Verification, they were getting bombarded with spam posts! I'm like, sheesh! It's such a tiny forum that no one really uses much, and all that grief?? Is phpBB that insecure even with those safeguards??

Okay, having said that, I'm sure I'll start getting hit now! \:D
_________________________
GangsterBB.NET (Ver. 7.5.6)
2007 Content Rulez Contest - Hon Mention
UBB.classic 6.7.2 - RIP
Browsers: Chrome, Firefox, & Safari (Win7 and iPhone); No IE, ever!
Top
Page 1 of 2 1 2 >



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Custom forum permissions
by ntdoc
05/18/12 02:07 PM
Forum Stats
10489 Members
36 Forums
33841 Topics
181696 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image