4 ms·
PhpBB, the gift that keeps on giving. Isn't phpBB one of the most compromised pieces of software installed?
by couchwire 12y ago
PhpBB, the gift that keeps on giving. Isn't phpBB one of the most compromised pieces of software installed?
- knieveltech 12y agoI'm pretty sure sendmail still wears that crown.
- astrodust 12y agoUnpatched Exim was giving it a pretty good run for a while.
- porker 12y agoWell well well. A sysadmin friend swears by exim as the safest mailserver software ever. I will enjoy ribbing him at the pub on Friday :)
- astrodust 12y agoNot a bad track record, but not flawless: http://www.cvedetails.com/vulnerability-list/vendor_id-10919/product_id-19563/Exim-Exim.html http://www.cvedetails.com/vulnerability-list/vendor_id-10919... The 9.3 one was world-destroying, nuke-from-orbit type bad. "execute arbitrary code via an SMTP session" is not what you want to hear in a bug report.
- porker 12y agoYikes! I'm still impressed by qmail's track record: http://www.cvedetails.com/vulnerability-list/vendor_id-86/product_id-143/Dan-Bernstein-Qmail.html http://www.cvedetails.com/vulnerability-list/vendor_id-86/pr...
- knieveltech 12y agoJust wait. Evidence suggests it is impossible to send mail without also providing remote code execution as a service.
- astrodust 12y agoAs good as qmail is, the official release is so far behind the times it's ridiculous. The unofficial patches, made unofficial by a stubborn refusal on the part of the author to merge them in, have fixed most of these issues, but then what's the point of using qmail if you have to use the untrusted version? Sadly qmail is a lesson of how you can be correct and completely wrong at the same time. Imagine a completely secure operating system that only runs on 32-bit systems. Could you actually advocate using it in a serious production capacity?
- GigabyteCoin 12y agophpBB (the software) wasn't compromised in this situation. An admin's account credentials were.
- McGlockenshire 12y agophpBB 2 was a total security nightmare and anyone running it or version 1 in production should be shot. They realized how horrible things were and massively cleaned up their act around version 3. No published vulnerabilities issued since 2010, and only a handful for 3.x in general. http://secunia.com/advisories/product/17998/?task=advisories http://secunia.com/advisories/product/17998/?task=advisories