10.02.2013 Views

PHP Programming Language - Cultural View

PHP Programming Language - Cultural View

PHP Programming Language - Cultural View

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

phpBB 234<br />

valid and the MOD can be successfully installed on a vanilla phpBB installation. [52]<br />

The latest version of AutoMOD is 1.0.0-RC4, released on April 28, 2010. [51] AutoMOD can be downloaded from<br />

the AutoMOD information page [53] and support can be obtained in the AutoMOD support forum. [54]<br />

AutoMOD is the successor to EasyMOD, a tool for phpBB2 which was also developed by the phpBB MOD Team<br />

and performed essentially the same task. The latest version of EasyMOD is 0.4.0, released on June 30, 2008. [55]<br />

Support and downloads for EasyMOD can be obtained in the EasyMOD support forum. [56]<br />

Unified MOD Installation Library (UMIL)<br />

The Unified MOD Installation library is a library designed to simplify the installation and uninstallation of the<br />

database side of MODs., [57] It is designed to be useful for configuring the forum for the new MOD, performing<br />

database actions such as adding and removing tables and columns, and purging the forum's cache. UMIL is GPL<br />

licensed [57] and the latest version is 1.0.1. It can be downloaded from the UMIL page. [58] To create a UMI-file<br />

automatically, a MOD author can use the Unified MOD Installation File creation tool. [59]<br />

phpBB Portals<br />

There are more than 15 different Portal options designed to work within the Administrator Control panel of phpBB<br />

3.x. There is no official Portal created or authorized by the creators of the phpBB.<br />

Security<br />

In December 2004, a large number of Web sites were defaced by the Santy worm, which used vulnerabilities in<br />

outdated versions of phpBB2 to overwrite <strong>PHP</strong> and HTML pages. [60] Although these were the result of outdated<br />

versions of <strong>PHP</strong> and phpBB, incidents like these have caused the security of phpBB to be disputed. There have also<br />

been a few times where new releases of phpBB have come out a few days apart, although the last occurrence of this<br />

was in early 2005. [61] However, the phpBB Team usually responds to security reports as soon as possible, and<br />

releases a new version quickly. The phpBB Group, attempting to learn from previous failures, performed a codebase<br />

security audit before the release of 2.0.18. [62] The phpBB3 codebase received an external security audit in September<br />

2007, which was done by SektionEins. [63] The sixth release candidate of phpBB3 was published following the<br />

results of the security audit. [17]<br />

Additionally, many things have been changed in phpBB2 to avoid problems in the future, including many features<br />

backported from the phpBB3 codebase. Among those is a re-authentication system for the administration panel<br />

(introduced after a cookie verification issue allowed attackers to gain administrator access). [64]<br />

In November 2005, the phpBB Group announced a new Incident Investigation Team (IIT), a sub-team of their<br />

Support Team, which is responsible for assisting users in the cleanup and repair of an attacked phpBB installation<br />

and investigating reports of new exploits. [65] The team announced a tracker the following January where<br />

administrators of attacked bulletin boards could report an attack and receive support from the IIT.<br />

The CAPTCHA system in phpBB2 has proven vulnerable to automated registrations, with numerous phpBB-based<br />

forums being swamped by spam registrations. Due to the feature freeze, the antispam solutions have to be installed<br />

separately. The phpBB team has published recommendations [66] on protecting the boards from spam. At the<br />

moment, the best method is to use a question-answer challenge, implemented by Textual Confirmation or<br />

Registration Auth Code MODs. phpBB3 has a much stronger CAPTCHA system, however during the phpBB3<br />

development/beta phase it was frequently criticised for being difficult to read. [67] The development team has been<br />

working on improving its readability prior to phpBB3's final release.<br />

Additionally, the teams have announced that each minor release of phpBB3 (3.0.1, 3.0.2, etc.) will be preceded by<br />

individual release candidates in an effort to prevent instances where subsequent releases would be only days apart (as<br />

happened a couple of times during the 2.0.x line). [68]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!