Register - Login
Views: 99870146
Main - Memberlist - Active users - Calendar - Wiki - IRC Chat - Online users
Ranks - Rules/FAQ - Stats - Latest Posts - Color Chart - Smilies
05-04-22 06:51:12 PM
Jul - Computers and Technology - AcmlmBoard New poll - New thread - New reply
Pages: 1 2Next newer thread | Next older thread
Xkeeper

Level: 263


Posts: 1/25353
EXP: 297181934
For next: 1778519

Since: 07-03-07

Pronouns: they/them/????????

Since last post: 4 days
Last activity: 7 hours

Posted on 08-07-07 04:58:33 PM Link | Quote
Daily Cycle II ~ -2822
acmlmboard (ack-klem-buhord) n. (see also: Swiss cheese)

____________________
"Xkeeper is like the can at the bottom of a supermarket display. Pulling him out is just asking for a catastrophic mess."
Stats
Level NaN
EXP: 0/0
Time: 35 days
Ranked at #167
 

 
Deleted User
Collection of nobodies
Posted on 08-07-07 06:17:52 PM Link | Quote
Originally posted by Xkeeper
acmlmboard (ack-klem-buhord) n. (see also: Swiss cheese)

Thread won.

____________________


===================
[Posted by Grey Mario]
Deleted User
Collection of nobodies
Posted on 08-08-07 02:10:10 AM Link | Quote
Originally posted by Xkeeper
acmlmboard (ack-mulm-buhord) n. (see also: Swiss cheese)
Swiss cheese doesn't have nearly as many holes as an acmlmboard

____________________


===================
[Posted by NightKev]
Kas
Member
Level: 28


Posts: 15/145
EXP: 128237
For next: 3101

Since: 07-28-07

From: Sheffield, UK

Since last post: 1.2 years
Last activity: 1.2 years

Posted on 08-09-07 05:50:50 PM Link | Quote
phpbb is famous for being vulnerable to people who know the source code inside-out. All it takes is someone knowledgeable to find an exploit, tell others about it and presto, you can take over half the internet's forums. That's why really big, important forums either use Vbulletin or a privately secured version of phpbb. Keeping important code closed is a good start to keeping your site secure; of course, it's only a small start.
Xkeeper

Level: 263


Posts: 1/25353
EXP: 297181934
For next: 1778519

Since: 07-03-07

Pronouns: they/them/????????

Since last post: 4 days
Last activity: 7 hours

Posted on 08-09-07 05:53:34 PM Link | Quote
Daily Cycle II ~ -2736
Yes... a lot of it is making sure tht the basic vulnerabilities, like actually turning off register_globals and encapsulating your damn queries.

*Xkeeper sighs

____________________
"Xkeeper is like the can at the bottom of a supermarket display. Pulling him out is just asking for a catastrophic mess."
Stats
Level NaN
EXP: 0/0
Time: 37 days
Ranked at #171
 

 
chungy
Member
Level: 31


Posts: 14/174
EXP: 168466
For next: 16897

Since: 08-04-07


Since last post: 14.1 years
Last activity: 13.9 years

Posted on 08-09-07 10:01:36 PM Link | Quote
Originally posted by Kas
phpbb is famous for being vulnerable to people who know the source code inside-out.

Uhh...no. I don't know why the rumor that phpBB is extremely insecure keeps spreading, but it's entirely false. Oh wow, three exploits to the source within a year, all patched by the phpBB no more than two days after discovery, must make it really insecure. Actually, probably the reason the rumor keeps spreading is that forum maintainers AREN'T updating as often as they should.
Deleted User
Collection of nobodies
Posted on 08-09-07 10:04:43 PM Link | Quote
Originally posted by KittyKev
stag019 said phpBB was good...he lied >:[

I did? When?

____________________


===================
[Posted by The Black Parade]
Rena
I had one (1) message in Discord deleted and proceeded to make a huge, huge mess about how it was a violation of free speech and how moderators are supposed to be spam janitors and nobody should have the right to tell me not to talk about school shootings
Level: 135


Posts: 573/5390
EXP: 29079571
For next: 255434

Since: 07-22-07

Pronouns: he/him/whatever
From: RSP Segment 6

Since last post: 343 days
Last activity: 343 days

Posted on 08-10-07 08:18:19 AM Link | Quote
JL2 - Post #573 - 08-10-07 03:18:19 AM
Day 18, rank 9; Level 23 (11.3%)
1056/9373 (59406/67723)
GPP: 155; GT: 54.565
Originally posted by Kas
Keeping important code closed is a good start to keeping your site secure; of course, it's only a small start.
Security through obscurity? Good luck.

____________________
Eon

Hammer Brother
MLB
Level: 68


Posts: 73/1085
EXP: 2626400
For next: 102400

Since: 07-22-07


Since last post: 311 days
Last activity: 131 days

Posted on 08-10-07 10:05:43 AM Link | Quote
"Official" distribution terms aside, users of AcmlmBoard in practice often make their changes to the source code proprietary.

____________________



Links: Eon Hacks, Eon Wiki, Eon Blog, Eon Forums

More commonly known as theclaw.
Xkeeper

Level: 263


Posts: 1/25353
EXP: 297181934
For next: 1778519

Since: 07-03-07

Pronouns: they/them/????????

Since last post: 4 days
Last activity: 7 hours

Posted on 08-10-07 10:17:11 AM Link | Quote
Daily Cycle II ~ -2717
Originally posted by HyperHacker
Originally posted by Kas
Keeping important code closed is a good start to keeping your site secure; of course, it's only a small start.
Security through obscurity? Good luck.

Relying on only one thing is dumb, yes, but if you write good code and keep the source hidden, it will take much longer to find any possible exploits rather than pouring over the source code to see how things work.

Originally posted by Eon
"Official" distribution terms aside, users of AcmlmBoard in practice often make their changes to the source code proprietary.

And many times they're coded just as bad, if not worse

____________________
"Xkeeper is like the can at the bottom of a supermarket display. Pulling him out is just asking for a catastrophic mess."
Stats
Level NaN
EXP: 0/0
Time: 38 days
Ranked at #175
 

 
chungy
Member
Level: 31


Posts: 15/174
EXP: 168466
For next: 16897

Since: 08-04-07


Since last post: 14.1 years
Last activity: 13.9 years

Posted on 08-10-07 08:50:10 PM Link | Quote
Originally posted by Eon
"Official" distribution terms aside, users of AcmlmBoard in practice often make their changes to the source code proprietary.

Though Acmlm doesn't seem to mind; even from a direct conversation with him, all he really cared for was that people retain credit to him. Weather they make their code open or closed, he didn't mind.
Nicole

Disk-kun
Level: 146


Posts: 359/6469
EXP: 38290047
For next: 223247

Since: 07-07-07

Pronouns: she/her
From: Boston, MA

Since last post: 79 days
Last activity: 20 hours

Posted on 08-11-07 01:32:31 AM Link | Quote
Originally posted by Eon
"Official" distribution terms aside, users of AcmlmBoard in practice often make their changes to the source code proprietary.

I didn't even know the board had "official" distribution terms...

____________________
??
chungy
Member
Level: 31


Posts: 17/174
EXP: 168466
For next: 16897

Since: 08-04-07


Since last post: 14.1 years
Last activity: 13.9 years

Posted on 08-11-07 02:44:13 AM Link | Quote
It doesn't, well at least not the ones from Acmlm.

Jesper's 1.a2 has a license somewhat similar to the BSD license (though it forbids sale of the software), the legality of it is somewhat thrown into question since Acmlm didn't make any explicit permission, but given his permissive stance I doubt he'd care too much. Unless you're using 1.a2, it doesn't really matter to you.
Kas
Member
Level: 28


Posts: 19/145
EXP: 128237
For next: 3101

Since: 07-28-07

From: Sheffield, UK

Since last post: 1.2 years
Last activity: 1.2 years

Posted on 08-14-07 07:25:30 PM; last edit by Kas on 08-14-07 07:25 PM Link | Quote
Originally posted by chungy
Originally posted by Kas
phpbb is famous for being vulnerable to people who know the source code inside-out.

Uhh...no. I don't know why the rumor that phpBB is extremely insecure keeps spreading, but it's entirely false. Oh wow, three exploits to the source within a year, all patched by the phpBB no more than two days after discovery, must make it really insecure. Actually, probably the reason the rumor keeps spreading is that forum maintainers AREN'T updating as often as they should.


...Those are still exploits, and when one is discovered a vast number of communities are affected. I've read somewhere that in the past some exploits have remained unpatched for months. Penny Arcade famously switched from PHPBB because of its insecurity.

So no, I didn't say it was extremely insecure. i said it's insecure to people who know what to look for, and that can a very simple task. Once an exploit is uncovered, anybody who knows a little can use it. [Insert lame patronising remark here]

Originally posted by Xkeeper
Originally posted by HyperHacker
Originally posted by Kas
Keeping important code closed is a good start to keeping your site secure; of course, it's only a small start.
Security through obscurity? Good luck.

Relying on only one thing is dumb, yes, but if you write good code and keep the source hidden, it will take much longer to find any possible exploits rather than pouring over the source code to see how things work.



This is exactly what I meant when I said a small start, HH .
Pages: 1 2Next newer thread | Next older thread
Jul - Computers and Technology - AcmlmBoard New poll - New thread - New reply


Rusted Logic

Acmlmboard - commit 47be4dc [2021-08-23]
©2000-2022 Acmlm, Xkeeper, Kaito Sinclaire, et al.

30 database queries, 3 query cache hits.
Query execution time: 0.088768 seconds
Script execution time: 0.027148 seconds
Total render time: 0.115917 seconds