10.02.2013 Views

PHP Programming Language - OpenLibra

PHP Programming Language - OpenLibra

PHP Programming Language - OpenLibra

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

phpBB 234<br />

valid and the MOD can be successfully installed on a vanilla phpBB installation. [52]<br />

The latest version of AutoMOD is 1.0.0-RC4, released on April 28, 2010. [51] AutoMOD can be downloaded from<br />

the AutoMOD information page [53] and support can be obtained in the AutoMOD support forum. [54]<br />

AutoMOD is the successor to EasyMOD, a tool for phpBB2 which was also developed by the phpBB MOD Team<br />

and performed essentially the same task. The latest version of EasyMOD is 0.4.0, released on June 30, 2008. [55]<br />

Support and downloads for EasyMOD can be obtained in the EasyMOD support forum. [56]<br />

Unified MOD Installation Library (UMIL)<br />

The Unified MOD Installation library is a library designed to simplify the installation and uninstallation of the<br />

database side of MODs., [57] It is designed to be useful for configuring the forum for the new MOD, performing<br />

database actions such as adding and removing tables and columns, and purging the forum's cache. UMIL is GPL<br />

licensed [57] and the latest version is 1.0.1. It can be downloaded from the UMIL page. [58] To create a UMI-file<br />

automatically, a MOD author can use the Unified MOD Installation File creation tool. [59]<br />

phpBB Portals<br />

There are more than 15 different Portal options designed to work within the Administrator Control panel of phpBB<br />

3.x. There is no official Portal created or authorized by the creators of the phpBB.<br />

Security<br />

In December 2004, a large number of Web sites were defaced by the Santy worm, which used vulnerabilities in<br />

outdated versions of phpBB2 to overwrite <strong>PHP</strong> and HTML pages. [60] Although these were the result of outdated<br />

versions of <strong>PHP</strong> and phpBB, incidents like these have caused the security of phpBB to be disputed. There have also<br />

been a few times where new releases of phpBB have come out a few days apart, although the last occurrence of this<br />

was in early 2005. [61] However, the phpBB Team usually responds to security reports as soon as possible, and<br />

releases a new version quickly. The phpBB Group, attempting to learn from previous failures, performed a codebase<br />

security audit before the release of 2.0.18. [62] The phpBB3 codebase received an external security audit in September<br />

2007, which was done by SektionEins. [63] The sixth release candidate of phpBB3 was published following the<br />

results of the security audit. [17]<br />

Additionally, many things have been changed in phpBB2 to avoid problems in the future, including many features<br />

backported from the phpBB3 codebase. Among those is a re-authentication system for the administration panel<br />

(introduced after a cookie verification issue allowed attackers to gain administrator access). [64]<br />

In November 2005, the phpBB Group announced a new Incident Investigation Team (IIT), a sub-team of their<br />

Support Team, which is responsible for assisting users in the cleanup and repair of an attacked phpBB installation<br />

and investigating reports of new exploits. [65] The team announced a tracker the following January where<br />

administrators of attacked bulletin boards could report an attack and receive support from the IIT.<br />

The CAPTCHA system in phpBB2 has proven vulnerable to automated registrations, with numerous phpBB-based<br />

forums being swamped by spam registrations. Due to the feature freeze, the antispam solutions have to be installed<br />

separately. The phpBB team has published recommendations [66] on protecting the boards from spam. At the<br />

moment, the best method is to use a question-answer challenge, implemented by Textual Confirmation or<br />

Registration Auth Code MODs. phpBB3 has a much stronger CAPTCHA system, however during the phpBB3<br />

development/beta phase it was frequently criticised for being difficult to read. [67] The development team has been<br />

working on improving its readability prior to phpBB3's final release.<br />

Additionally, the teams have announced that each minor release of phpBB3 (3.0.1, 3.0.2, etc.) will be preceded by<br />

individual release candidates in an effort to prevent instances where subsequent releases would be only days apart (as<br />

happened a couple of times during the 2.0.x line). [68]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!