You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 153 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - Why You Should NOT Use PHP-Nuke Versions 7.7 or 7.8 [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
jimmo
Corporal
Corporal


Joined: Feb 14, 2004
Posts: 60

Location: Germany

PostPosted: Mon Jul 11, 2005 1:49 am Reply with quoteBack to top

Hi All!

This article here

http://64bit.us/article-print-83.html

indicates that the security in PHPNuke 7.7 and 7.8 is even worse than before. It says that the *only* thing to do is *not* user either version 7.7 or 7.8. I am curious as to what others have to say.

Regards,

jimmo

_________________
The Linux Knowledge Base and Tutorial project is looking for volunteers: http://www.linux-tutorial.info
Find all posts by jimmoView user's profileSend private messageVisit poster's website
gadji
Sergeant
Sergeant


Joined: Oct 14, 2003
Posts: 115


PostPosted: Mon Jul 11, 2005 3:18 am Reply with quoteBack to top

This is a good debating point jimmo.

Some people here will say that if you keep all of your patches/phpBB versions up to date then you shouldn't have any problems.

Others however will say that if you use those versions then you are leaving an open invitation for hackers.

At the end of the day it's really down to what you want to do with your site. If you're careful to keep regular db AND file backups then you shouldn't have any problems at all, in my opinion.

The idea behind the wysiwig editors is a good one, but it just needs a bit more security work done on it before it will be fully secure.
Find all posts by gadjiView user's profileSend private message
benk
Private
Private


Joined: Jul 16, 2005
Posts: 37


PostPosted: Sat Jul 16, 2005 4:15 am Reply with quoteBack to top

I'm pretty new to phpnuke, I started off installing 7.8 not knowing any better and then I began reading the forums and found out about this issue. So, then I just did a simple test. I tried to submit some news with html...just basic stuff like:

<h1><font color=red>news story</font></h1>

and it went through, it actually processed the html tags...so I'd say there's a risk. I haven't tried any javascript though but still, allowing these types of tags compromises the way you want your site to look.

I'm now in the process of downgrading to 7.6.
Find all posts by benkView user's profileSend private messageVisit poster's website
ishtar
Sergeant
Sergeant


Joined: Jun 19, 2005
Posts: 96

Location: Suriname

PostPosted: Sat Jul 16, 2005 8:14 am Reply with quoteBack to top

so....what can we do if we have used 7.7 or 7.8
Find all posts by ishtarView user's profileSend private messageMSN Messenger
scz
Nuke Soldier
Nuke Soldier


Joined: Apr 07, 2004
Posts: 27


PostPosted: Sat Jul 16, 2005 8:23 am Reply with quoteBack to top

get a downgrade. Nukescripts offers such a downgrade to 7.6. Smile

_________________
free articles
free article submission
Find all posts by sczView user's profileSend private messageVisit poster's website
ishtar
Sergeant
Sergeant


Joined: Jun 19, 2005
Posts: 96

Location: Suriname

PostPosted: Sat Jul 16, 2005 3:13 pm Reply with quoteBack to top

ok i went to that site i cant really find the info, or im not looking good. i wanna downgrade to 7.6

ok u guys tell me, which version is the best?
Find all posts by ishtarView user's profileSend private messageMSN Messenger
benk
Private
Private


Joined: Jul 16, 2005
Posts: 37


PostPosted: Sat Jul 16, 2005 3:28 pm Reply with quoteBack to top

Go here, it's not too hard to find in google:
http://www.nukescripts.net/modules.php?name=Downloads&op=getit&lid=100270
Find all posts by benkView user's profileSend private messageVisit poster's website
triptoy5
Nuke Cadet
Nuke Cadet


Joined: Jul 19, 2005
Posts: 1


PostPosted: Tue Jul 19, 2005 7:41 pm Reply with quoteBack to top

downgrading to 7.6 is all fine and dandy, but I cant seem to find out how to downgrade to anything lower. I have some special needs/interest to downgrade the database to about 7.0 or a little lower. If anyone can provide any links/resources/help/advice on this subject it would be very appreciated.

If for some reason, your not a registerd user of nukecops and dont feel like registering to answer this question Smile, feel free to email me at chaos@triptoy.net or IM me on AIM: DJTripToy

Much appreciated : ))
Find all posts by triptoy5View user's profileSend private message
CripTiK
Nuke Soldier
Nuke Soldier


Joined: Jul 19, 2005
Posts: 24


PostPosted: Mon Jul 25, 2005 3:12 pm Reply with quoteBack to top

Ok, I downgraded my site to 7.6 from 7.7 and I am assuming I would still need to run the 7.6 patch?
Find all posts by CripTiKView user's profileSend private message
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by TOGETHER TEAM srl ITALY http://www.togetherteam.it - DONDELEO E-COMMERCE http://www.DonDeLeo.com - TUTTISU E-COMMERCE http://www.tuttisu.it
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.598 Seconds - 181 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::