Re: [Full-Disclosure] RE: Worm hitting PHPbb2 Forums

Valdis.Kletnieks_at_vt.edu
Date: 12/25/04

  • Next message: Billy Dodson: "UDP Port Sweep question"
    To: "Mattias R. Lindgren" <mailinglists@mattiaslindgren.com>
    Date: Sat, 25 Dec 2004 02:11:39 -0500
    
    
    

    On Wed, 22 Dec 2004 22:51:40 MST, "Mattias R. Lindgren" said:

    > There is a workaround posted http://forums.ir0x0rz.com/viewtopic.php?t=34
    >
    > I'm hoping this will be enough to protect phpBB installs.

    As I understand it, the phpBB *fix* is a whole whopping one-liner,
    or you can upgrade to a fixed release of phpBB (2.0.11)

    http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2004-11/1204.html

    That was a *MONTH* ago. And now that *finally* a worm shows up, people are
    running around trying to "protect" stuff they should have *fixed* already??

    Quite frankly, if the people you're trying to protect can't find the time
    in *a month* to deploy a one-line fix, quite obviously *they* don't care about
    their stuff. Why are you doing things to enable them to *keep* not caring?

    But then, I've never been able to watch news stories about "800 pound person
    needs 4 people to help them up taking them to the hospital". If you're 800
    pounds and bedridden, who's bringing you the food?

    Do your users a favor - don't keep feeding them when they're 800 pounds already.

    Oh yeah - and everybody out there, have a happy <appropriate winter solstice
    holiday>... :)

    
    



  • Next message: Billy Dodson: "UDP Port Sweep question"

    Relevant Pages

    • Re: Re: computer simulation
      ... resources, including force, to spread freedom and fix the ... After a lifetime of searching for my religion, ... you didn't do everything you could to protect the Iraqi women. ... first scientifically-verifiable evidence of the divine. ...
      (talk.origins)
    • Re: "Application has failed to start..." error message with VS2005 on new machine
      ... secondarily, it is to protect my 88-year-old mother from ... The fact that it is not consistent is disturbing. ... Reinstalling the application may fix this problem" ... Does anyone know what this means and how to find out what is missing? ...
      (microsoft.public.vc.mfc)
    • Re: Tips on welding up a shaft
      ... |>I have a machine at work, I do not have to fix it in the next couple days ... is 1144 a good steel for making an input shaft for a lathe? ... |> only have a wirefeed welder to work with, ... |> "Additionally as a security officer, I carry a gun to protect ...
      (rec.crafts.metalworking)
    • Re: BUG? "Call fasync() functions without the BKL" is racy
      ... At least this protect us from tty too. ... Restore BKL protection to manipulations of f_flags ... short-term fix; the real fix will not involve the ... error = ioctl_fioasync(fd, filp, argp); ...
      (Linux-Kernel)
    • Re: [Full-Disclosure] New phpBB ViewTopic.php Cross Site Scripting Vulnerability (with fix)
      ... Due PHPBB.COM erased this posting without any comment here just the fix ... > Advisory Name:New phpBB ViewTopic.php Cross Site Scripting Vulnerability ... Full-Disclosure - We believe in it. ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)

  • Quantcast