NESDev and Strangulation Records messageboards
Forum Index | FAQ | New User | Login | Search

Previous ThreadView All ThreadsNext ThreadShow in Flat Mode*


SubjectRe: Forum software change?  
Posted byAnonymous
Posted on9/9/04 11:23 PM
From IP70.240.144.35  



If you do change forums, try to get one that won't blindly accept post requests(or get requests that change data) from outside sources. I've noticed a huge number of CGI programs and PHP scripts do this.

I *think* phpBB uses referrer checks, which should be sufficient in most cases(do any personal firewall proxies muck around with the referrer field?) to guard against remote POST attacks, though not GET requests(unless you disable inline images and a few other features).

FUDforum blocks against this after I bugged the author. Changing the look of the forum is fairly easy, but you'll likely spend more time fixing the templates when you upgrade than you would with phpBB.
It supports both flat and threaded message display modes.
FUDforum is moderately faster than phpBB in generating pages.
The PHP code for it is incredibly obfuscated and hard to read.

Invision Power Board also blocks against this sort of attack, but it costs money, and the license is backwards(restricts how you may use the board). I haven't looked at vBulletin(which costs money), and it also has a screwy license.

-Xodnizel



-
Entire Thread
Subject  Posted byPosted On
*Forum software change?  blargg9/8/04 9:29 PM
.*Re: Forum software change?  koitsu9/9/04 9:32 PM
..*Re: Forum software change?  Memblers9/9/04 10:13 PM
...*Re: Forum software change?  quietust9/16/04 04:15 AM
....*Re: Forum software change?  koitsu9/16/04 1:55 PM
.....*Re: Forum software change?  koitsu9/19/04 02:09 AM
....Re: Forum software change?  Anonymous9/9/04 11:23 PM
....*Re: Forum software change?  RoboNes9/12/04 4:51 PM
....*Re: Forum software change?  tepples9/10/04 4:53 PM
.....*Re: Forum software change?  koitsu9/11/04 05:04 AM
......*Re: Forum software change?  Anonymous9/16/04 05:50 AM
.......*Re: Forum software change?  koitsu9/16/04 1:54 PM
........*Re: Forum software change?  Anonymous9/20/04 03:06 AM
........*Re: Forum software change?  Anonymous9/18/04 02:12 AM
.......*Re: Forum software change?  Anonymous9/16/04 05:58 AM
Jump to

Memblers' homepage             Contact Me

Forums powered by WWWThreads Demo