Previous Thread
Next Thread
Print Thread
Rate Thread
#306756 08/15/2003 2:36 AM
Joined: Aug 2003
Posts: 6
Junior Member
Junior Member
Offline
Joined: Aug 2003
Posts: 6
hello everyone, before i begin with my post i just want to let everyone know right off that i'm a noob with this stuff so thanks for your patience. i am learning...slowly
I am looking at setting up a forum for my new website. As far as forum software is concerned i was thinking of using UBB Threads by Infopop. I have been playing with the demo software and I enjoy it alot. However i recently came across a security article that outlines how this software can be easily taken advantage of by the use of SQL hacking. Now i know the version of the software they review is outdated compared to the current version, but my question is...is it still possible to do something like the article outlines with the current UBBthreads software? the last thing i would want on my new forum is some mystery administrator or to have my database dumped . Anyways, thanks

Sponsored Links
Joined: Dec 2000
Posts: 1,471
Addict
Addict
Offline
Joined: Dec 2000
Posts: 1,471
That article talks about the perl version of wwwthreads and not about the current ubb.threads version. Security has been much improved during the years.
There's no known way to exploit ubb.threads at the moment. There has been some security fixes during but Infopop reacts very quickly if necessary.

I don't understand your last question, sorry.


Joined: Nov 2001
Posts: 10,369
I type Like navaho
I type Like navaho
Joined: Nov 2001
Posts: 10,369
I think it's very secure.

Yeah, that's not really an issue anymore.... First of all it's no longer written in Perl. And all the globals are registed at the top of every script... so you can't add variables into the URL of a script - as the top of every script goes through every variable that it uses right at the very top.

For example

// Get the input
$Cat = get_input("Cat","get");
$Baord = get_input("Board","get");
$Whatever = get_input("Whatever","post");
$FooMoo = get_input("FooMoo","both");


This will tell each script how it's allowed to accept variables. Either by get, or post, or both. If the variable is received from the wrong method... it ends up empty.

Dave_L is probably the best one to comment on security issues. He's really good at that.

Joined: Aug 2003
Posts: 6
Junior Member
Junior Member
Offline
Joined: Aug 2003
Posts: 6
awesome you have answered all my questions exactly

Joined: Apr 2002
Posts: 1,768
Addict
Addict
Offline
Joined: Apr 2002
Posts: 1,768
And all the globals are registed at the top of every script...

Not all of the modifications posted here do that, though, even recent ones. If you're concerned about security, be careful about adding mods.

Sponsored Links
Joined: Aug 2003
Posts: 6
Junior Member
Junior Member
Offline
Joined: Aug 2003
Posts: 6
so what is the difference between wwwthreads and ubbthreads? I am a member of the Futuremark.com Forums and i notice they use wwwthreads. i really like their layout and was hoping to have something similar. If it is different, is it the same or more/less secure than ubbthreads? Does it have more options as far as configurability go?

Joined: Feb 2002
Posts: 2,286
Veteran
Veteran
Joined: Feb 2002
Posts: 2,286
Prior to Infopo buying the product about 15 months ago, it was known as wwwthreads and was owned by Rick Baker, who today is still the man behind the code It was renamed ubbthreads to fit into the product line of Infopop.



Fans Focus - Focusing on Fans of Sport

(Okay - mainly football (the British variety wink at the moment - but expanding all the time....)
Joined: Aug 2003
Posts: 6
Junior Member
Junior Member
Offline
Joined: Aug 2003
Posts: 6
so the version of wwwthreads that they have is exactly the same as the latest version of ubbthreads? it seems different because i'm not seeing the php at the top?

Joined: Jun 2001
Posts: 3,273
That 70's Guy
That 70's Guy
Offline
Joined: Jun 2001
Posts: 3,273
It would appear that futuremark is using the perl version of .threads but I am not sure what perl version. The perl version is no longer supported I believe. Hope that helps.

Joined: Dec 2000
Posts: 1,471
Addict
Addict
Offline
Joined: Dec 2000
Posts: 1,471
No, they use the perl version of wwwthreads. Rick ported the whole thing to php. As Ian said, Infopop buyed wwwthreads several months ago, renamed it to ubb.threads.
The old perl versions isn't maintained any more.

So with buying ubb.threads you get a advanced and brand new model of wwwthreads. Developed in php and not in perl. Many more feature, more secure, more reliable and easier to use.

Sponsored Links
Joined: Feb 2002
Posts: 2,286
Veteran
Veteran
Joined: Feb 2002
Posts: 2,286
No - the versions have come on a long way since the www days - I am guessing that they are running a 5.xx perl version.


Fans Focus - Focusing on Fans of Sport

(Okay - mainly football (the British variety wink at the moment - but expanding all the time....)
Joined: Aug 2003
Posts: 6
Junior Member
Junior Member
Offline
Joined: Aug 2003
Posts: 6
so if their version is so old, i wonder why they havn't upgraded. does infopop offer free updates or do you have to pay extra?

Joined: Jun 2001
Posts: 3,273
That 70's Guy
That 70's Guy
Offline
Joined: Jun 2001
Posts: 3,273

Joined: Nov 2001
Posts: 10,369
I type Like navaho
I type Like navaho
Joined: Nov 2001
Posts: 10,369
And wwwthreads license holders pay a greatly reduced rate for upgrades.

Joined: Feb 2002
Posts: 2,286
Veteran
Veteran
Joined: Feb 2002
Posts: 2,286
Yep


Fans Focus - Focusing on Fans of Sport

(Okay - mainly football (the British variety wink at the moment - but expanding all the time....)
Joined: Aug 2000
Posts: 1,290
Addict
Addict
Offline
Joined: Aug 2000
Posts: 1,290
Threads has come a long way, it's very secure and confident in itself, oh sure there was some low times, but it's self esteem is on the mend..




- Custom Web Development
http://www.JCSWebDev.com

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Posts: 70
Joined: January 2007
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20240506)