Jump to content

Any fix for this Security Exploit -- Boards being hacked already...

Featured Replies

We are unaware of any confirmed unpatched exploits for the latest release of IP.Board right now. If you believe you have discovered a new exploit or have information about a security issue we would encourage you to submit a ticket so we can investigate.

IPB Bug:

http://cxsecurity.com/issue/WLB-2013030024

Please fix the problem

The version 3.4.4 and 3.4.5 has problems :smile:

That has already been fixed as of 3.4.3.

Really?

http://a44422.demo.invisionpower.com/index.php?andor_type=and&app=core&do=search&module=search&search_app[$trololo]=1&search_app_filters[core][searchInKey]=&search_app_filters[core][sortDir]=1&search_app_filters[core][sortDir]=0&search_app_filters[core][sortKey]=date&search_author=1&search_content=both&search_date_end=01/01/1967&search_date_start=01/01/1967&search_term=1&sid=e351ab4dcbf9ae7848e3b8175cf6fc8d
http://a44422.demo.invisionpower.com/index.php?andor_type=and&app=core&do=search&module=search&search_app=core&search_app_filters[core][searchInKey]=&search_app_filters[core][sortDir]=1&search_app_filters[core][sortDir]=0&search_app_filters[core][sortKey]=date&search_author=1&search_content=both&search_date_end=01/01/1967&search_date_start=01/01/1967&search_term=1&sid[$trololo]=1

And much more :smile:

That's completely different. I've filed a bug report for that.

I would recommend, however, that you configure any production servers to not show errors but rather log them to a file that is not accessible to the general public, which is also recommended by the PHP authors themselves.

I didn't know IPS offered support to nulled boards. :sleep:

I didn't know IPS offered support to nulled boards. :sleep:

huh?

That has nothing to do with this topic.

I do not have forum,I closed my forum. :smile:

Uses IPB for test only

That doesn't actually justify using nulled software. If you want to use IP.Board, you need to either just use the demo to see if IP.Board is for you, or purchase a copy from IPS. But again, that's not what this topic is about.

I do not have forum,I closed my forum. :smile:

Uses IPB for test only

As was noted, you must still have a license. There is no "free version", even for testing purposes. You will need to Purchase a license, or remove the software from wherever it's installed.

doesn't someone have to have license to post in in suite feedback section ?

Archived

This topic is now archived and is closed to further replies.

Recently Browsing 0

  • No registered users viewing this page.