+  Forum Owners
|-+  Forum Software» phpBB» phpBB not safe?
Username:
Password:
Pages: [1]
  Print  
Author Topic: phpBB not safe?  (Read 1119 times)
xopialaker
Newbie
*
Offline Offline

Posts: 13


View Profile
« on: June 15, 2007, 06:16:48 PM »

Hi,

There are numerous instances of forums being hacked. But from what read on some websites, as well as heard from few of the people, phpBB is the one that gets hacked the most.

Though not all people are able to afford vBulletin or Invision Power Board, free forum software like phpBB would be the way to go for them. But still, the forum's security is important, especially when the forum grows popular.

Is there any past experiences of anyone with the security issue of phpBB (if it exists) and a way by which it can be solved?
Logged
MakaveLi
Newbie
*
Offline Offline

Posts: 21


View Profile
« Reply #1 on: June 15, 2007, 06:34:29 PM »

Hello, phpBB is not safe because it's a open source project. I remember there was a script that make threads as .html's not sure exactly where. This is what this forum did. Some of my forums got hacked which had over 1,000 members, which was very disappointing. I recommend you to stay with vBulletin or IPB because they are great forum software and updated when needed. It's like saying you get what you paid for.
Logged
toshmahorey
Jr. Member
**
Offline Offline

Posts: 65


View Profile
« Reply #2 on: June 15, 2007, 07:10:25 PM »

Hi,

There are numerous instances of forums being hacked. But from what read on some websites, as well as heard from few of the people, phpBB is the one that gets hacked the most.

Though not all people are able to afford vBulletin or Invision Power Board, free forum software like phpBB would be the way to go for them. But still, the forum's security is important, especially when the forum grows popular.

Is there any past experiences of anyone with the security issue of phpBB (if it exists) and a way by which it can be solved?

yes phpbb does seem to be the one most targeted by defacers.  but i think this is due to its popularity.  the people that deface web sites and forums want to gain maximum exposure for the "feats" and since phpbb seems to be the most popular forum software in use it makes sense for them to target phpbb.

i have used phpbb in the past and have never had a problem with hacks or defacements. having said that I always run the latest release with all relevant security patches. i imagine the people who have their sites defaced fall behind on updates.

Logged
toshmahorey
Jr. Member
**
Offline Offline

Posts: 65


View Profile
« Reply #3 on: June 15, 2007, 07:14:08 PM »

Hello, phpBB is not safe because it's a open source project. I remember there was a script that make threads as .html's not sure exactly where. This is what this forum did. Some of my forums got hacked which had over 1,000 members, which was very disappointing. I recommend you to stay with vBulletin or IPB because they are great forum software and updated when needed. It's like saying you get what you paid for.

i'm not sure it being open source has much to do with it. vbulletin has had many security issues in the past so has ipb. all forum software has had its security related problems unfortunately it is just the nature of the game.
Logged
coolguy85
Newbie
*
Offline Offline

Posts: 30


View Profile
« Reply #4 on: June 17, 2007, 03:55:50 PM »

I think phpBB may not be as safe. Nonetheless, the main reason it gets hacked more is because it is used more, especially by novice admins. If someone is willing to invest the money for a paid forum software, then that means they will probably also invest the money and/or time to keep their forums secure. In contrast, cheap forum admins who go with free software are more likely to care less about their forums security, and they tend to take less steps to avoid hackings.

I mean no offense to anyone. In fact, I use phpBB.
Logged
Arsenal
Newbie
*
Offline Offline

Posts: 16


View Profile
« Reply #5 on: June 26, 2007, 05:17:50 AM »

I am a moderator on a phpbb forum and it seems pretty secure. However, the admin is careful and does invest money in the forum to keep it secure.
Logged
Harry
Newbie
*
Offline Offline

Posts: 26


View Profile
« Reply #6 on: July 02, 2007, 07:54:04 PM »

well when you run free software.. it's what happens a lot! You see a vB get hacked and there is an update within a few hrs. You see a phpbb get hacked and an update can takes up to a week. That's what you get for freeware.. when you pay for something it's gonna pay off. Don't get me wrong phpbb is a great forum software, but it's support lacks a lot.
Logged
devilzfan300
Newbie
*
Offline Offline

Posts: 11


View Profile
« Reply #7 on: July 12, 2007, 07:52:17 PM »

I think being hacked is more of an issue with your host, not the script you run with your host.  Use a reliable host like hostmonster.com. The biggest problem I found was autobots registering to my forum by the hundreds.  After running two forums, I figured out the best ways to fight this spam, and now I have zero spambot registrations.

1) Most spammers find your site through google by searching the copyright at the bottom of your page.  Do not delete the copyright, but change some of the words around in the credits.  For instance, instead of "written by", change it to "coded by" and stuff like that.   This will help stop spammers from finding you in the first place.

2) Ban usernames with typical adult language or prescription meds. Dont forget to enclose it with astericks: *word* .  This makes sure that the word it not used anywhere in the word.

3) Ban email addresses that end in common spambot email addresses.  One that pops into mind with me is .ru, but whatever is attacking your specific forum, ban it.  There is a mod that makes this very easy and more effective

4) Download these three mods.  These three mods and the above tips completely protected me:
http://www.phpbb.com/mods/db/index.php?i=misc&mode=display&contrib_id=1751
http://www.phpbb.com/community/viewtopic.php?t=373695
http://www.phpbb.com/community/viewtopic.php?t=390401

5) If  you need more mods, there are plenty here:
http://www.phpbb.com/community/viewtopic.php?t=427852
Logged

Submit your forum to Forum Detector
http://www.forumdetector.com
Plutonic
Newbie
*
Offline Offline

Posts: 23


View Profile
« Reply #8 on: July 13, 2007, 05:12:57 AM »

I have had three phpBB forums and I highly recommend them, Not one of my forums was hacked, nor did any have spam.
Logged
Chatty Kathy
Newbie
*
Offline Offline

Posts: 24



View Profile
« Reply #9 on: July 13, 2007, 10:24:13 AM »

I think there was a bit of dumbness in my decisions of first liking phpbb 2.  You see, I set up a free forum at my fast forum dot org, I fell in love with that forum software.  Here is the part I did not know!! The admin that hosted these free forums was very keen on modding the forum code and it was a most excellent experience for all of us admins running our boards as subdomains on his site.

BUT, when you go someplace else, take phpbb2 out of the box and put it on your own site.  It's just so.... UN modded Cheesy Cheesy. And all the cool features you were accustomed to are not included without doing a lot of work.  Very tedious and confusing task for newborns Sad


Yes, I totally agree, if you are willing to pay for code, by all means do it.  I really used to like IPB Invision Power Board. BUT, now, the profiles are unappealing to me. I'm not sure how much you can change these on the Admin side.

I have been impressed with the cool functions of VB vBulletin code, however, the overall appearance seems bulgey/heavy/bloated.


At this point, I do not like the new phpbb 3! Sad (that opinion may change in time, of course)


MYBB is looking good! Wink


To end this, I will say I am using phpbb 2 with an upcoming project and I will modify it with my favorite codes.

Sorry for long winded post!
Logged

Smiley
billo
Jr. Member
**
Offline Offline

Posts: 59


View Profile
« Reply #10 on: July 25, 2007, 02:55:30 PM »

My forum already hacked once with a large database which has annoyed me a lot. I think there should be some solution for it. I can see countless porn posts on many PHPBB2 forums and people are preferring other forum solutions. Does it mean that PHPBB2 is loosing its popularity and integrity?
Logged
Pages: [1]
  Print  
 
Jump to: