includes/kb_****.php fix? »  Show posts from    to     

Icy Phoenix


Old Support Topics - includes/kb_****.php fix?



Frost [ Wed 10 Jan, 2007 15:44 ]
Post subject: includes/kb_****.php fix?
I looked but I couldn't tell wether or not this fix has been done in the beta.

I recently heard about the kb_constants.php exploit and the fix was supposed to be to add..
Code: [Hide] [Select]
if ( !defined('IN_PHPBB') )
{
die("Hacking attempt");
}


to all the kb_****.php files under the comments but I looked in the files and I saw..

Code: [Hide] [Select]
if ( !defined( 'IN_PORTAL' ) )

{

die( "Hacking attempt" );

}


Is this right or has it not been done yet?
I thought it might be safest to do...

Code: [Hide] [Select]
if( !defined('IN_PHPBB') )

{

die('Hacking attempt');

exit;

}

else

{

if( !defined('IN_PORTAL') )

{

die('Hacking attempt');

exit;

}

}


But then again I am a designer not a coder :oops:

Oh yea, lol

In reference to..

http://www.securityfocus.com/bid/21577


Mighty Gorgon [ Thu 11 Jan, 2007 02:10 ]
Post subject: Re: includes/kb_****.php fix?
KB in Icy Phoenix should be protected against this... :roll:


Frost [ Thu 11 Jan, 2007 09:32 ]
Post subject: Re: includes/kb_****.php fix?
Ok, I was comparing two different phpbb's trying to figure out who already did the fix the right way

Looks like you win :lol_flag:


Mighty Gorgon [ Fri 12 Jan, 2007 02:17 ]
Post subject: Re: includes/kb_****.php fix?
Frost wrote: [View Post]
Looks like you win :lol_flag:

Thanks... where is the prize? :mri:


joni806 [ Fri 12 Jan, 2007 05:54 ]
Post subject: Re: Includes/kb_****.php Fix?
hello me you could put a file zip or to rar the same gives, I am bad in php and not like doing it


Frost [ Fri 12 Jan, 2007 07:13 ]
Post subject: Re: includes/kb_****.php fix?
joni806 wrote: [View Post]
hello me you could put a file zip or to rar the same gives, I am bad in php and not like doing it


DO NOT DO THE ABOVE EDITS

I was just asking MG a question, he already had it done and your files are already correct. Sorry :icy_lol_flag:

Mighty Gorgon wrote: [View Post]
Frost wrote: [View Post]
Looks like you win :lol_flag:

Thanks... where is the prize? :mri:


Um... :? Here www.black-fusion.com/media/prize.html :icy_lol_flag:


TheSteffen [ Fri 12 Jan, 2007 08:22 ]
Post subject: Re: includes/kb_****.php fix?
Great Frost :mricy:


Frost [ Fri 12 Jan, 2007 08:59 ]
Post subject: Re: includes/kb_****.php fix?
lol I googled italian prize, took the first prize i saw and made it text :icy_lol_flag:


Mighty Gorgon [ Wed 31 Jan, 2007 02:02 ]
Post subject: Re: includes/kb_****.php fix?
Ha ha ha... thank you, it is really nice! :wink:




Powered by Icy Phoenix