Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
1 registered (A-GATE), 28 Guests and 14 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 12/20/03
Posts: 4424
Top Posters (30 Days)
Ruben 51
Gizmo 24
DennyP 24
Dunny 15
SteveS 13
AllenAyres 12
SD 10
dbremer 10
drkknght00 9
doug 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Page 1 of 2 1 2 >
Topic Options
#226951 - 05/31/09 12:06 PM SQL injectgion on 6.5 classic
SigningsHotline Offline
stranger
Registered: 05/27/07
Posts: 18
Hi there:

I am using Classic 6.5.0. I have been receiving "Report A Post" emails with comments in them selling Viagra and diet pills. Smells like SQL injection. A temp fix is to move the post to another area then move it back to the original area and it changes the post number on it. But my question is, does anyone know of a patch that is available to fix this? Either direct from UBB or by an outside developer?

Thank you in advance!
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#226952 - 05/31/09 12:11 PM Re: SQL injectgion on 6.5 classic [Re: SigningsHotline]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
HUH????
Classic does not use MySql. It is a flat file system using CGI and PHP for the accelerator.
It sounds more like a spam issue which pops up all the time with classic today
_________________________
Blue Man Group
Top
#226953 - 05/31/09 12:18 PM Re: SQL injectgion on 6.5 classic [Re: Ruben]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
Just took a quick peek at your site you have report a post enabled on your site. So anyone can send a message including guests to the report a post. The only good part about it is only admins and moderators will get the message.

You could just turn the feature off I guess.
_________________________
Blue Man Group
Top
#226956 - 05/31/09 06:26 PM Re: SQL injectgion on 6.5 classic [Re: Ruben]
Gizmo Offline

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
Classic wasn't exactly "secure" in the captcha implementation in the latest build; automated bots could easily spam the everloving hell out of the forum...

Fix? UBB.T7 or disable features bots are abusing.
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#226988 - 06/02/09 12:32 PM Re: SQL injectgion on 6.5 classic [Re: Gizmo]
AllenAyres Offline
Registered: 12/29/03
Posts: 1995
Loc: Texas
At the least update to 6.7.3 - lots of bugs were fixed in there, tho I don't think Charles fixed any SQL injection issues wink
_________________________
- Allen
- ThreadsDev | PraiseCafe
Top
#226990 - 06/02/09 01:08 PM Re: SQL injectgion on 6.5 classic [Re: AllenAyres]
Gizmo Offline

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
Originally Posted By: AllenAyres
ho I don't think Charles fixed any SQL injection issues wink
Lol considering it's not MySQL based, I don't really see how he COULD fix SQL injection issues... let alone how there could be some... That'd be amazing...
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#226994 - 06/02/09 04:51 PM Re: SQL injectgion on 6.5 classic [Re: Gizmo]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
I wouldn't sweat it. The classic version is flat file based and there is not as many security issues as many on here let on.

I have been running classic since 1995 and I never had anyone get in my forum and create any problems. I have had others on my servers as well running classic and still have 2 classic boards running on my servers and still no problems.
Top
#226995 - 06/02/09 05:01 PM Re: SQL injectgion on 6.5 classic [Re: JAISP]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
Originally Posted By: JAISP

I have been running classic since 1995 and I never had anyone get in my forum and create any problems. I have had others on my servers as well running classic and still have 2 classic boards running on my servers and still no problems.


I agree to a point depending on the classic version.
The real issue was the spamming in my case.
In his case it looks the same.
So options are close the board to guests or just turn off notify posts and give users another avenue if needed. Like a help forum.
Either case if spammers can find a email address they will use it.
_________________________
Blue Man Group
Top
#226996 - 06/02/09 07:42 PM Re: SQL injectgion on 6.5 classic [Re: Ruben]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
That's why I use a web form for people contacting me on my web sites. No email given and none known till i reply to the form message.

Also my web form tells me many things about the person sending to me through the forum. This helps in knowing if I need to reply or not.
Top
#227011 - 06/03/09 05:31 PM Re: SQL injectgion on 6.5 classic [Re: JAISP]
SigningsHotline Offline
stranger
Registered: 05/27/07
Posts: 18
I am writing this with a bag over my head so you won't recognize me as I feel like a fool. I totally forgot this is a flat file and cannot be SQL injection! But it does appear to be a bot and not a human doing it as it keeps hitting the same "repot a post" from 2006.

So if there is no way to add captcha to this feature I will live with it. Moving the thread and then moving it back again is a band-aid fix.

Unless there is a captcha mod out there that anyone is aware of?
Top
#227012 - 06/03/09 05:37 PM Re: SQL injectgion on 6.5 classic [Re: SigningsHotline]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
You can ban the bot via an .htaccess file if it is the same bot all the time.

Code:
order allow,deny
deny from xxx.xxx.xxx.xxx
allow from all
Top
#227013 - 06/03/09 05:41 PM Re: SQL injectgion on 6.5 classic [Re: SigningsHotline]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
The fool is us. I don't recall a true captcha mod for classic but it was discussed several times at UBBDev.com. Somebody did add a Captcha feature with a human question answer feature at some point in time but never followed up on the modification. If they did it was lost in time.

If upgrading is out of the question, then try to use what tools you have at hand.
Such as turn off features that allow bots from harvesting email accounts, close the board to guests, Email verification, Etc.

Other than that you can block by Ip not just by the classic control panel but by .htaccess if it is a repeat offender.
_________________________
Blue Man Group
Top
#227058 - 06/05/09 01:05 PM Re: SQL injectgion on 6.5 classic [Re: JAISP]
AllenAyres Offline
Registered: 12/29/03
Posts: 1995
Loc: Texas
Originally Posted By: Gizmo
Originally Posted By: AllenAyres
ho I don't think Charles fixed any SQL injection issues wink
Lol considering it's not MySQL based, I don't really see how he COULD fix SQL injection issues... let alone how there could be some... That'd be amazing...


umm... my point wink

Originally Posted By: JAISP
I have been running classic since 1995


"# First version of UBB created May 7, 1996 (by Ted O'Neill)."

wink
_________________________
- Allen
- ThreadsDev | PraiseCafe
Top
#227068 - 06/06/09 12:23 PM Re: SQL injectgion on 6.5 classic [Re: AllenAyres]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
Ok Excuse me then 1996. I had purchased the firs version when they were only out like a few months. I still have the board archived and all of its post's as well. It was on a new site so I went by the Domain Registration date to get close. My Mistake.

Anyway no one really cares, lol.
Top
#227077 - 06/06/09 07:01 PM Re: SQL injectgion on 6.5 classic [Re: JAISP]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
Originally Posted By: JAISP
Ok Excuse me then 1996. I had purchased the firs version when they were only out like a few months. I still have the board archived and all of its post's as well. It was on a new site so I went by the Domain Registration date to get close. My Mistake.

Anyway no one really cares, lol.

I agree Lockerman.(Sorry Jaisp Just a habit with the name)
Who cares except for the person with the problem.
I would suggest to him as stated by myself, you and others. Use security methods available or start the upgrade process.
_________________________
Blue Man Group
Top
#227316 - 06/23/09 01:03 PM Re: SQL injectgion on 6.5 classic [Re: Ruben]
AllenAyres Offline
Registered: 12/29/03
Posts: 1995
Loc: Texas
I actually care... do you still have the free version files from something like v1 or v2? I had them but lost them on some hard drive I can't find anymore frown

For posterity and all... we had it running on UBBDev a few years back but I can't find the files anymore.
_________________________
- Allen
- ThreadsDev | PraiseCafe
Top
Page 1 of 2 1 2 >



Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Temporary Password email not being received
by
05/24/12 10:02 PM
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Forum Stats
10492 Members
36 Forums
33842 Topics
181709 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image