phpBB <= 2.0.10 vulnerability

Support/Development for PHP
carlswart
Forum User
Forum User
Posts: 20
Joined: Sun Dec 19, 2004 2:41 am
Location: South Africa

phpBB <= 2.0.10 vulnerability

Unread post by carlswart »

There is a new worm exploiting the vulnerability in phpBB, as described in the URL below:
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=240513

For more information on the worm see: http://vil.nai.com/vil/content/v_130471.htm

Is there an easy and realiable way to identify all phpBB installations on our servers? I suppose searching for viewtopic.php is a good start.

ART, will you be releasing an updated RPM for the phpBB application ?
carlswart
Forum User
Forum User
Posts: 20
Joined: Sun Dec 19, 2004 2:41 am
Location: South Africa

Unread post by carlswart »

I have posted a small Perl script to detect possible vulnerable phpBB installations. The script also enables a workaround.

Please see my phpBB page, located at the following URL: http://www.carlswart.co.za/phpbb/
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Unread post by scott »

Yeah, but its the holidays and I run grsec....sooo... it doesnt really effect me :P I'll get to it soon though
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Unread post by scott »

Haha, apparently I went back in time and released phpBB 2.0.11 on December 1 :P Look in the app vault channel
carlswart
Forum User
Forum User
Posts: 20
Joined: Sun Dec 19, 2004 2:41 am
Location: South Africa

Unread post by carlswart »

scott thank you so much!!!

I were asleep. I saw the post about the app-vault channel, but did not add it to my yum.conf. Sorry! :oops:
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Unread post by scott »

heh, its OK. I forgot about it too
Post Reply