<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: MyBB Security</title>
	<atom:link href="http://dennistt.net/2006/06/23/mybb-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://dennistt.net/2006/06/23/mybb-security/</link>
	<description>Dennis Tsang's little corner on the big internet!</description>
	<pubDate>Sat, 22 Nov 2008 04:07:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>By: david</title>
		<link>http://dennistt.net/2006/06/23/mybb-security/#comment-145</link>
		<dc:creator>david</dc:creator>
		<pubDate>Mon, 26 Jun 2006 17:38:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.dennistt.net/2006/06/23/mybb-security/#comment-145</guid>
		<description>backup backup backup

I was affected by that hacker and naturally I don't have a current backup (not that I had a lot on my boards, but it's the principle of it....)</description>
		<content:encoded><![CDATA[<p>backup backup backup</p>
<p>I was affected by that hacker and naturally I don&#8217;t have a current backup (not that I had a lot on my boards, but it&#8217;s the principle of it&#8230;.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bobby</title>
		<link>http://dennistt.net/2006/06/23/mybb-security/#comment-139</link>
		<dc:creator>Bobby</dc:creator>
		<pubDate>Mon, 26 Jun 2006 07:03:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.dennistt.net/2006/06/23/mybb-security/#comment-139</guid>
		<description>You might want to implement the following into MyBB for more added security. Take these as suggested features for 1.4:
- By default have administrators change the admin folder, through the installation process
- Disallow access to the admin cp if there is an update which has not yet been patched. For example, we have a 'Check for Newer Version' option now, make it somehow that when an administrator logs into the admin cp, the system will check mybb.com for any new releases/updates etc. If there is one, inform the user and dissalow any options in the cp.
- Have users downloading mybboard also enter their email into the mailing list. Like what Apple does when your downloading iTunes etc. It automatically has preselected, 'Get Newsletter', do something the same with mybb.
- Have a secret passkey sent to an administrator every month, which has been randomly selected by the board itself. That passkey must be entered to change major aspects of the board, like the 'Enter Password' you have when people want to change their email in the user cp.
- If someone tries to login numerous times without luck, block their ip for 24hrs.
- Don't allow any special characters at all in usernames
- Have a small captcha image on the login screen.</description>
		<content:encoded><![CDATA[<p>You might want to implement the following into MyBB for more added security. Take these as suggested features for 1.4:<br />
- By default have administrators change the admin folder, through the installation process<br />
- Disallow access to the admin cp if there is an update which has not yet been patched. For example, we have a &#8216;Check for Newer Version&#8217; option now, make it somehow that when an administrator logs into the admin cp, the system will check mybb.com for any new releases/updates etc. If there is one, inform the user and dissalow any options in the cp.<br />
- Have users downloading mybboard also enter their email into the mailing list. Like what Apple does when your downloading iTunes etc. It automatically has preselected, &#8216;Get Newsletter&#8217;, do something the same with mybb.<br />
- Have a secret passkey sent to an administrator every month, which has been randomly selected by the board itself. That passkey must be entered to change major aspects of the board, like the &#8216;Enter Password&#8217; you have when people want to change their email in the user cp.<br />
- If someone tries to login numerous times without luck, block their ip for 24hrs.<br />
- Don&#8217;t allow any special characters at all in usernames<br />
- Have a small captcha image on the login screen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dennis</title>
		<link>http://dennistt.net/2006/06/23/mybb-security/#comment-138</link>
		<dc:creator>Dennis</dc:creator>
		<pubDate>Mon, 26 Jun 2006 02:51:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.dennistt.net/2006/06/23/mybb-security/#comment-138</guid>
		<description>It seems like several boards were exploited with the vulnerability patched in 1.1.4.  It is unfortunate to see what consequences do arise because of two missing quotation marks.</description>
		<content:encoded><![CDATA[<p>It seems like several boards were exploited with the vulnerability patched in 1.1.4.  It is unfortunate to see what consequences do arise because of two missing quotation marks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dennis</title>
		<link>http://dennistt.net/2006/06/23/mybb-security/#comment-137</link>
		<dc:creator>Dennis</dc:creator>
		<pubDate>Sun, 25 Jun 2006 18:17:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.dennistt.net/2006/06/23/mybb-security/#comment-137</guid>
		<description>Peter has posted some ways that you can secure your MyBB even further:
http://community.mybboard.net/showthread.php?tid=9991</description>
		<content:encoded><![CDATA[<p>Peter has posted some ways that you can secure your MyBB even further:<br />
<a href="http://community.mybboard.net/showthread.php?tid=9991" onclick="javascript:pageTracker._trackPageview('/outbound/comment/community.mybboard.net');" rel="nofollow">http://community.mybboard.net/showthread.php?tid=9991</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DrPoodle</title>
		<link>http://dennistt.net/2006/06/23/mybb-security/#comment-136</link>
		<dc:creator>DrPoodle</dc:creator>
		<pubDate>Sat, 24 Jun 2006 22:15:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.dennistt.net/2006/06/23/mybb-security/#comment-136</guid>
		<description>There are always going to be security holes in any type of software, which means there are always going to be ways in for malicious users. The way I see it, the more MyBB security patches there are, the less ways in there are for board exploiters.

With a complex script like MyBB, it is likely that holes are going to be found and exploited by malicious users, but we can be sure to make it damn hard for them anyway!</description>
		<content:encoded><![CDATA[<p>There are always going to be security holes in any type of software, which means there are always going to be ways in for malicious users. The way I see it, the more MyBB security patches there are, the less ways in there are for board exploiters.</p>
<p>With a complex script like MyBB, it is likely that holes are going to be found and exploited by malicious users, but we can be sure to make it damn hard for them anyway!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan</title>
		<link>http://dennistt.net/2006/06/23/mybb-security/#comment-132</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Sat, 24 Jun 2006 07:02:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.dennistt.net/2006/06/23/mybb-security/#comment-132</guid>
		<description>I wholeheartedly agree. There is no reason anyone shouldn't upgrade their forums as soon as possible.

MyBB offers manual patches for the 1.1.x serious where you can install the patches into the code itself without having to download the entire package.

This way you can ensure that you yourself applied the patch.

I STRONGLY suggest for Administrators with a lot of modifications to their board take this route everytime a new release is made. It is simple and easy, sometimes the patches take two seconds, like the update from 1.1.3 to 1.1.4.

Anyone who doesn't do this does not have a legitmate excuse why they shouldn't. If you really cared for your board you would update it with any patch the Developers release, regardless of the severity of the bug.

I hope by reading these posts people change their minds about how they handle their boards.</description>
		<content:encoded><![CDATA[<p>I wholeheartedly agree. There is no reason anyone shouldn&#8217;t upgrade their forums as soon as possible.</p>
<p>MyBB offers manual patches for the 1.1.x serious where you can install the patches into the code itself without having to download the entire package.</p>
<p>This way you can ensure that you yourself applied the patch.</p>
<p>I STRONGLY suggest for Administrators with a lot of modifications to their board take this route everytime a new release is made. It is simple and easy, sometimes the patches take two seconds, like the update from 1.1.3 to 1.1.4.</p>
<p>Anyone who doesn&#8217;t do this does not have a legitmate excuse why they shouldn&#8217;t. If you really cared for your board you would update it with any patch the Developers release, regardless of the severity of the bug.</p>
<p>I hope by reading these posts people change their minds about how they handle their boards.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
