June 16, 2024, 02:26:22 AM

Author Topic: upgrading the forum to the latest version...re: the hacking  (Read 3242 times)

0 Members and 1 Guest are viewing this topic.

Offline ttgapers

  • dun know
  • New Warrior
  • *
  • Posts: 42
    • View Profile
    • ttgapers.com - the latest from the caribbean
upgrading the forum to the latest version...re: the hacking
« on: August 01, 2006, 06:47:16 AM »
it appears the forum is at version 1.0.5

it appears this version has some sql vulnerabilities that "Don Johnson" might be using to exploit the board. might the site admins update to the latest stable or RC version, it may mitigate the attacks.

i checked out smf, and stable release is 1.0.7, and RC is at 1.11 i beleve.

jus looking out for the security of the forum and it's users.

if it is a sql injection as i think, users PM boxes etc., might have been compromised.

regards

ttgapers
ttgapers.com - the latest from the caribbean" style="border:0

Offline Dutty

  • Hero Warrior
  • *****
  • Posts: 9578
    • View Profile
Re: upgrading the forum to the latest version...re: the hacking
« Reply #1 on: August 01, 2006, 06:49:45 AM »
Nice!!!  :thumbsup: I have NO idea what all dat means  ???

But if it go work better...pull de lever and fix it oui   :beermug:
Little known fact: The online transportation medium called Uber was pioneered in Trinidad & Tobago in the 1960's. It was originally called pullin bull.

Offline cocoapanyol

  • Hero Warrior
  • *****
  • Posts: 2800
    • View Profile
Re: upgrading the forum to the latest version...re: the hacking
« Reply #2 on: August 01, 2006, 07:01:08 AM »
Yeah..ah get "Don Jonhson" crap dis morning too.  Dem people must be real hardup when de have tuh beg tom, dick and harry to watch dey sh**
I can please only one person per day. Today is not your day. Tomorrow isn't looking good either.

Offline Organic

  • Bamboo # 5
  • Hero Warrior
  • *****
  • Posts: 5573
  • Politics- 90% Personality 10% Principle
    • View Profile
Re: upgrading the forum to the latest version...re: the hacking
« Reply #3 on: August 01, 2006, 07:42:55 AM »
it appears the forum is at version 1.0.5

it appears this version has some sql vulnerabilities that "Don Johnson" might be using to exploit the board. might the site admins update to the latest stable or RC version, it may mitigate the attacks.

i checked out smf, and stable release is 1.0.7, and RC is at 1.11 i beleve.

jus looking out for the security of the forum and it's users.

if it is a sql injection as i think, users PM boxes etc., might have been compromised.

regards

ttgapers
am yes fuh true same thng i was thinking  ??? ??? ???
QUE?
Perhaps the epitome of a Trinidadian is the child in the third row class with a dark skin and crinkly plaits who looks at you out of decidedly Chinese eyes and announces herself as Jacqueline Maharaj.- Merle Hodge

Offline ttgapers

  • dun know
  • New Warrior
  • *
  • Posts: 42
    • View Profile
    • ttgapers.com - the latest from the caribbean
Re: upgrading the forum to the latest version...re: the hacking
« Reply #4 on: August 01, 2006, 09:28:57 AM »
Nice!!!  :thumbsup: I have NO idea what all dat means  ???

But if it go work better...pull de lever and fix it oui   :beermug:

yeah boy dutty...it looking like it need an update...

Quote
Soca Warriors Online Discussion Forum | Powered by SMF 1.0.5.
© 2001-2005, Lewis Media. All Rights Reserved.
© Theme by Midgard

A little more reading and one realizes SMF forums appear to be very insecure. in the long run it may be better to upgrade socawarriors to a more robut CMS. my recommendation would be Postnuke.

ttgapers
ttgapers.com - the latest from the caribbean" style="border:0

Offline TriniCana

  • Hero Warrior
  • *****
  • Posts: 7557
  • ah Catch ah Glad
    • View Profile
    • allyuhmuddaass@com
Re: upgrading the forum to the latest version...re: the hacking
« Reply #5 on: August 01, 2006, 09:46:41 AM »
Ya know ah reading this thread and dey other 3 concerning dey spam and hacker asswipe and ah thinking tur meh self...Allyuh ain't think that all this public information would lead into dey wrong hands again ?

With this information it should be PMed to those who wanna know. ;)

Offline ttgapers

  • dun know
  • New Warrior
  • *
  • Posts: 42
    • View Profile
    • ttgapers.com - the latest from the caribbean
Re: upgrading the forum to the latest version...re: the hacking
« Reply #6 on: August 01, 2006, 10:44:53 AM »
Ya know ah reading this thread and dey other 3 concerning dey spam and hacker asswipe and ah thinking tur meh self...Allyuh ain't think that all this public information would lead into dey wrong hands again ?

With this information it should be PMed to those who wanna know. ;)


I hear ya, but all this is publicly available in google, and all open source advisories.....even on the SMF website it lists the vulnerabilities and fixes.

ttgapers
ttgapers.com - the latest from the caribbean" style="border:0

Offline RasIred

  • Hero Warrior
  • *****
  • Posts: 854
    • View Profile
Re: upgrading the forum to the latest version...re: the hacking
« Reply #7 on: August 01, 2006, 11:09:03 AM »
TT gaper, send the moderators a lil heads up in Pm, and they could act on yur suggestion.

Good looking out  :beermug:


Tha Don Johnson is a stand and a half

Offline ttgapers

  • dun know
  • New Warrior
  • *
  • Posts: 42
    • View Profile
    • ttgapers.com - the latest from the caribbean
Re: upgrading the forum to the latest version...re: the hacking
« Reply #8 on: August 01, 2006, 11:19:18 AM »
Would that cost alot ???

as far as i can see, it costs zero as SMF appears to be open-source.


i will forward it to them, but i am sure they are aware of it by now. apparently this guy did the same thing twice? that means a vulnerability exists that has not been patched since the first hack.

ttgapers..
ttgapers.com - the latest from the caribbean" style="border:0

 

1]; } ?>