Help - Search - Members - Calendar
Full Version: [Solved]password exposed in download script
Marratech User Forum > Marratech > Other Questions
adaviel
I was looking at Mozilla, and find a marratech password in my history file.
Looks like you had at some point used a password in a form using HTTP GET

kxx&Password2=***&Software=005_marratech60_linux&submit=Submit& .....

not a good idea, especially if people resue passwords like they ought not to ...
Serge
Weird.... we use a straight version of PHPBB ... do you think this is the case for all PHPBB forums all over?

Any hints on how to solve this would be appreciated!

/Serge
Rolf Larsson
That's in the download script, I think. They're scheduled to be rewritten in the near future.
Andrey
We were using phpbb for some our clients but then switched to vBulletin(www.vbullettin.com) after some attacks throuth phpbb powered forums. Its more powerfull and much more stable for large forums (we have one vbulletin forum with 4000+ users on it running from 3 years with no problems). Its commercial product so you have 24h support included and fast updates and bug fixes.

You can find some more information abuot what people say by searching "phpBB vs vBulletin" in Google.


Regards,
Andrey
Serge
Thanks for the tip.

The password issue stems from the download script that was created by a third party contracted by one of our contractors :shock:

We will do our best to fix it sooner than later.

As for PHPBB, you are right Andrey. We are also leaning towards vBulletin as it is a full time job modding and uppgrading phpbb!

/Serge
Rolf Larsson
The only thing vBulletin appears to lack is integrated support for LDAP. We've been looking at Invision Board, but we're still undecided.
Serge
Just an update about this. The Username and Password requirement for downloading has been removed, thereby solving this issue.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.