
The following message ONLY applies to customers
who use phpBB to run a forum on their web
site.
Dear Beza.Net Customer:
In an effort to keep customers
informed about new security threats affecting their web site, Beza.net
is releasing this security advisory to all site operators who utilize
the open-source phpBB
forum application. All phpBB site operators must perform the
following security steps to prevent malicious users from performing attacks
on web
site visitors
and
gaining
full access to a phpBB web site:
Step 1: All site owners MUST upgrade to the current release of
phpBB. Please go here to
download the latest release of phpBB. Site owners who wish to have Beza.net
staff
perform the upgrade, please see below for more information.
Step 2: Once you have upgraded to the latest phpBB,
you must disable avatar functionality to prevent an avatar
script insertion vulnerability. This vulnerability affects all phpBB
releases including the current release 2.0.17. Click here to
view a how-to graphic for more info.
phpBB site owners must perform these steps as soon as
possible to prevent serious security compromise of their web site. This
is a mandatory update for all phpBB site operators.
For
more information about the various security issues with phpBB, please
see the following security notices:
| Date |
Security Advisory |
| Oct 24, 2005: |
phpBB Avatar Script Insertion Vulnerability |
| Sep 21, 2005: |
phpBB Remote Avatar Information Disclosure Weakness |
| Jul 21, 2005: |
phpBB BBcode "url" Script
Insertion Vulnerability |
| Jun 28, 2005: |
phpBB "highlight" PHP
Code Execution and Script Insertion |
| May 05, 2005: |
phpBB BBcode Script Insertion Vulnerability |
| Mar 08, 2005: |
phpBB Autologin Security Bypass Vulnerability |
| Mar 07, 2005: |
phpBB Signature Script Insertion Vulnerability |
| Feb 28, 2005: |
phpBB "autologinid" Security
Bypass |
| Feb 22, 2005: |
phpBB Avatar Functions Information Disclosure and Deletion |
| Jan 03, 2005: |
phpBB Multiple Vulnerabilities |
| All Notices: |
phpBB Security
notices for phpBB 1.x and 2.x |
As a courtesy to Beza.net customers who utilize a non-MODed phpBB on
their web site, Beza.net offers an annual security maintenance plan for
a nominal
fee of
$25/year. This fee covers phpBB site operators with security fixes/updates
for a 12-month period. If you wish to subscribe to this service, please
submit a
support trouble ticket from within your Beza.net account Control Panel
requesting "phpBB Annual Maintenance for $25/yr" service.
Failure to follow the above security advisories can result in your
web site being hacked and taken over by hackers. Furthermore,
any Beza.net customer who fails to take corrective measures based on
the above advisories will
be found
to be
in contempt
of Beza.net Terms
of Service Agreement and Acceptable
Use Policy. This is necessary to ensure Beza.net network and servers
are safe and secure for all to use.
Please contact us if you have any questions or concerns about this
security advisory. Thank you,
Admin
System
Security
Beza.Net
Phone: (800) 505-9774
Website: http://www.beza.net
|