MyBB Community Forums

Full Version: Worm problems
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
First of all, I'd like to thank all the developers for such a great forum system. I'm happy I was told about this. Smile

Second, have you all heard about the problems with PHP? I know that there has been a worm going around lately that has attacked phpbb boards. I was wondering if Mybb has any such problem or if a worm could start hitting us?

Thanks all.
No, I havn't heard actually. Is there a link or something I could read??

Im sure that if its a bug in php, the developers of php will, fix it.
k776 Wrote:No, I havn't heard actually. Is there a link or something I could read??

Im sure that if its a bug in php, the developers of php will, fix it.

Actually, yes, there is. The new version of PHP is supposed to fix it, but I'm really not sure what the worm is all about. It probably is the serialize bug, but there hasn't really been a lot of info on it.
Supposedly it only effects files of 777 permissions - IPB users have been hit also - I know my hosting company upgraded the php over the weekend so I should be safe.
It will affect the file no matter the permissions of it. It's a memory issue in PHP. MyBB uses serialize'd arrays to hold some specific data. (Read threads for guests). I'm guessing that you could add MyBB on the list of forums which could be hit with it.

The problem is a PHP problem and as far as I know of there is no work around we can do to avoid this.

For more information, you can read the phpBB thread: http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=248046

Also, the worm you are talking about is something completely different to this PHP exploit. You can find details on that worm @ http://www.kaspersky.com/news?id=156681162. This does not affect MyBB and there has been no worm like this for MyBB.

Chris.
Chris Boulton Wrote:It will affect the file no matter the permissions of it. It's a memory issue in PHP. MyBB uses serialize'd arrays to hold some specific data. (Read threads for guests). I'm guessing that you could add MyBB on the list of forums which could be hit with it.

The problem is a PHP problem and as far as I know of there is no work around we can do to avoid this.

For more information, you can read the phpBB thread: http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=248046

Also, the worm you are talking about is something completely different to this PHP exploit. You can find details on that worm @ http://www.kaspersky.com/news?id=156681162. This does not affect MyBB and there has been no worm like this for MyBB.

Chris.

Okay. Thank you. Smile