1: This happens with every board, and usually takes a week at the least.Hitakashi said:well install a blank SMF on a random domain and within 1 day you will get spam post, even if you never give the domain out, bots find SMF and post on it
plus i never trust it anymore since the sql injections
Kirisute Gomen said:Both have been fixed in the security updates however.Hitakashi said:Thing is both 1.1.x and 2.x has had this problem too
Overall
1.1.10 - They sql injected and made everyone member's, deleted post, deleted theme settings, and made the forum title say "HACKED"
2.0 - Same thing except they couldn't touch the member's part haha
And it wasn't a SQL injection anyway. It had to do with how the files were hashed.Kirisute Gomen said:If you're using 1.1.11 or 2.0 RC3 and that still happens, I suggest posting on the SMF.org boards. I think it was patched in 1.1.10 or 1.1.11 though.Hitakashi said:It actually all happened on my friends forum, we had a hated (ex-staff) and some how he was able to do something with SMF, via a SQL injection to delete all post, change the boards name, description, change everyone to member's and change the themes settings. They SAY (SMF) its a picture SQL injection (people naming EXE's as Pics and uploading then running them to gain access) but i patched it via a post a staff member made (i don't know where it was) but even when i did that it didn't work and they still were able to change everything
Wow... I smell fanboyism ..House said:Freeforums.org
SMF, MyBB
Since 2007, Forum Promotion has specialized in providing advertising solutions to webmasters looking to promote their communities. We pride ourselves in being the bridge that connects forum administrators, bloggers, and more.
We use essential cookies to make this site work, and optional cookies to enhance your experience.