Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Page 1 of 2 12 LastLast
Results 1 to 15 of 25

This is a discussion on So... MyBB, eh? in the Open Discussion & Chit-chat forum
I'm curious as to what made you guys choose MyBB for the HostGUI board over the bigger (free) guns like phpBB or SMF. Not that ...

  1. #1
    JPC Guru
    Join Date
    Jan 2004
    Location
    I'm right behind you....
    Posts
    389

    So... MyBB, eh?

    I'm curious as to what made you guys choose MyBB for the HostGUI board over the bigger (free) guns like phpBB or SMF. Not that I'm complaining. I recently jumped ship from phpBB and landed safely with MyBB and would recommend it to everyone. It's the best free forum system out there; people just haven't found that out yet. I'm just kinda curious why Jag went with a lesser-known system over something more established. Just seems... unusual.

    Also, MyBB is rediculously easy to customize. You guys should axe the default theme and template and implement the one we all know and love from here

  2. #2
    Darth Admin (aka Jag) JPC-Greg's Avatar
    Join Date
    Sep 1998
    Posts
    5,201
    You answered your own question in there. I dont trust nor like the lack of features with phpbb too well. I didnt hear of MyBB til someone mentioned it here on our own forums but it rocks. Im going to try and heavily push that forum over phpbb. As for customizing , it was a late night thing putting that forum up and I havent had time to go back. You voluntering to make a theme?
    Greg L. | Chief Executive Officer
    JaguarPC.com

    Helpful Links
    Knowledge Base | Network Status

    Need a Manager?
    (pm) | (email) David, Customer Service Manager
    (pm) | (email) Zach, Community Liason, Sales manager
    (pm) | (email) Masood, Chief Technical Officer
    (pm) | (email) Les, Chief Operations Officer

  3. #3
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    I'm sure you guys know this, but...

    CVE: http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=mybb

    NVD: http://nvd.nist.gov/nvd.cfm (Search for MyBB)
    Last edited by Vin DSL; 05-12-2006 at 03:16 PM.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  4. #4
    JPC Guru
    Join Date
    Jan 2004
    Location
    I'm right behind you....
    Posts
    389
    I didnt hear of MyBB til someone mentioned it here on our own forums
    Hehe, that would be me


    Vin:
    http://community.mybboard.net/showth...588#pid545 88

    Most of the vulnerabilities you mention require a user to already have access to the AdminCP to exploit them (and they've now been fixed).

    Besides.... http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=phpbb

  5. #5
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Alrighty then!

    I just wanted to make sure you guys realized MyBB is NOT a secure alternative to phpBB. Some ppl think, if they use a BB that nobody's heard of, they'll be flying below the hacker's radar...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  6. #6
    Darth Admin (aka Jag) JPC-Greg's Avatar
    Join Date
    Sep 1998
    Posts
    5,201
    heh, hoping that wasnt meant to mean phpbb is a secure source to begin with

    If its online, its not secure..end of story. I just became an instant fanboy of mybb when i used it, installed it, and messed around with it for a few moments.
    Greg L. | Chief Executive Officer
    JaguarPC.com

    Helpful Links
    Knowledge Base | Network Status

    Need a Manager?
    (pm) | (email) David, Customer Service Manager
    (pm) | (email) Zach, Community Liason, Sales manager
    (pm) | (email) Masood, Chief Technical Officer
    (pm) | (email) Les, Chief Operations Officer

  7. #7
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Just for giggles, you might try running this against your site:

    *Deleted by VinDSL -- Use your imagination*

    CVE says there's no patch available...
    Last edited by Vin DSL; 05-12-2006 at 04:59 PM.
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  8. #8
    Friendly rainboy's Avatar
    Join Date
    Apr 2006
    Location
    Eindhoven, The Netherlands
    Posts
    546
    Not really nice to post proof of concept exploit links here .. asking for trouble if i may say . not that they should be hidden away. Just think you should not bring other people some new idea's

    Any product is unsafe, some more as others.

    Kind regards,
    Patrick

  9. #9
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,304
    that was nice...

  10. #10
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Bah, I run exploits against my web site (but NOT the server) all the time. So do the Turks and Persian hackers, et cetera -- I see them in my logs every day...

    How else are you gonna know if your site is secure -- or not?
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  11. #11
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by Ron
    that was nice...
    LoL! You should talk...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  12. #12
    Friendly rainboy's Avatar
    Join Date
    Apr 2006
    Location
    Eindhoven, The Netherlands
    Posts
    546
    sure they are ... but it still not nice to invite people over and see what happens, wait till a exploit of such a product from another user brings your site down.. are you happy then ? but then.. maybe you are

  13. #13
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    I guess you didn't understand what I said...

    I run exploits against my own web site all the time. Sometimes I'll get bored and do it for 2-3 days straight -- run exploits -- type garbage in the address bar -- you name it! That's how you discover stuff like the former POC.

    As a matter of fact, 'we' accidently discovered a bug in PHP that can bring down practically any MySQL server in the world! The script kiddies haven't dicovered this one yet, but it's only a matter of time. When they do, 'we' will be ready!

    Isn't it better to be proactive about these things, rather than shutting the barndoor after the horse gets out?
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

  14. #14
    Darth Admin (aka Jag) JPC-Greg's Avatar
    Join Date
    Sep 1998
    Posts
    5,201
    Quote Originally Posted by Vin DSL
    As a matter of fact, 'we' accidently discovered a bug in PHP that can bring down practically any MySQL server in the world! The script kiddies haven't dicovered this one yet, but it's only a matter of time. When they do, 'we' will be ready!
    You wanna share this tidbit with me?
    Greg L. | Chief Executive Officer
    JaguarPC.com

    Helpful Links
    Knowledge Base | Network Status

    Need a Manager?
    (pm) | (email) David, Customer Service Manager
    (pm) | (email) Zach, Community Liason, Sales manager
    (pm) | (email) Masood, Chief Technical Officer
    (pm) | (email) Les, Chief Operations Officer

  15. #15
    Yeah, I know a LOT! Vin DSL's Avatar
    Join Date
    Mar 2003
    Location
    Arizona Uplands
    Posts
    10,775
    Quote Originally Posted by rainboy
    ...it[s] still not nice to invite people over and see what happens...
    Oh, BTW, I invited Jag and Galen to run this widely published vuln against their own site[s] -- to see what would happen (probably nothing) -- the same as I would do. I ran it against my own site immediately after I posted that message, even though I don't run MyBB.

    I wasn't issuing a challenge to hackers, so don't get your tulips in a bunch...
    DISCLAIMER Any resemblance between the views expressed above and those of the owners and operators of this system is purely coincidental. Any resemblance between these views and my own are non-deterministic. The existence of Vin DSL is questionable. The existence of views in the absence of anyone to hold them is problematic. The existence of the reader is left as an exercise in the second-order coefficient.

    No Guts, No Story! VinDSL © 2010

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •