Previous Thread
Next Thread
Print Thread
Hop To
Joined: Dec 2004
Posts: 1
R
stranger
stranger
R Offline
Joined: Dec 2004
Posts: 1
I've heard that there is a new worm attacking php boards, totally ripping them apart.

How safe is UBB.Threads??? Anyone have any idea about this?

Here is the link to what I've found on it so far:

http://developers.slashdot.org/article.pl?sid=04/12/17/1641212&tid=169&tid=172

Joined: Jun 2004
Posts: 24
S
stranger
stranger
S Offline
Joined: Jun 2004
Posts: 24
It got one of the Threads 6.4 boards that I administer and destroyed it.

It didn't effect the SQL data, so upgrading to Threads 6.5 got it running again. I'm told that 6.4 is more secure.

Joined: Dec 2003
Posts: 611
Former Developer
Former Developer
Joined: Dec 2003
Posts: 611
This worm only infects phpBB boards, and exploits a bug only present in phpBB.

The worm works on the server level, and will try to overwrite any file present on the server with itself. If your UBB.threads board was hit, it was because there's a phpBB somewhere else on the server.

I repeat, it is NOT possible for UBB.threads to be the vector for this worm.

One thing you SHOULD be worried about is old PHP versions. Like everyone else, we use the serialize()/unserialize() functions in UBB.threads. A malicious user could pass in data to UBB.threads to exploit a PHP security problem in these functions. There is nothing we can do to filter this data effectively. We urge all server owners to upgrade to PHP 4.3.10 immediately.

The phpBB worm and the serialize/unserialize issue are not connected.


Charles Capps
Former UBB.classic Maintainer

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Version 7.7.5 Images suddenly not displaying
by Stovebolt - 05/04/2024 11:19 AM
Do I need to rebuild my database?
by Baldeagle - 04/07/2024 2:58 AM
Who's Online Now
2 members (Ruben, 1 invisible), 422 guests, and 169 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20240506)