Jump to content


Alex K.

Member Since 07 Nov 2008
Offline Last Active Today, 12:20 AM
*****

Posts I've Made

In Topic: does this ipb save from hacker, cracker or malware code or sound fear for online

05 December 2011 - 12:31 AM

View PostForgoten Dynasty, on 01 December 2011 - 01:08 AM, said:

More like a month. 3.2 - 3.2.2 all had a very severe xss flaw which would allow an attacker to perform any front end action including all moderator actions. The only thing which actually remains secure is the acp and that said your only protection stopping an attacker from getting your plain text password is the browser being smart enough to not auto fill credentials.

That said in a disaster scenario where the administrator was using an outdated browser which was exploitable to some kind of auto complete xss (safari seems to have a bad track record for this) then plain text passwords could be extracted.
The acp link could be extracted given that there was a link visible to administrators.
and any .htaccess can be bypassed.

Could you give me a link to this? I wasn't able to find any mention of it in the announcements forum or tracker, and hotfixes are usually released for any significant security issues.
Also, how would a properly formed htaccess be bypassable?

In Topic: does this ipb save from hacker, cracker or malware code or sound fear for online

30 November 2011 - 08:25 PM

More to the point: IPB is extremely secure, and it would be very difficult (if not impossible) to find a more secure piece of forum software: To my knowledge, it's been literally years since a major security vulnerability was found. As said, you shouldn't assume that it will keep the rest of your site safe, but assuming your server and any other software that you use are well-secured, you should be completely fine. Many major companies use IPB and have had no issues with it.

In Topic: Why Buying IPBoard?

13 October 2011 - 03:09 PM

Most of this has already been mentioned, but to put everything in one post:
-Faster updates and development. SMF (one of the most popular free forums), for example, took four years to go from 2.0 Beta 1 to 2.0 Final. About four years ago, IPB 2.3.0 was released, and in that time IPS developed and released 3.0.x, 3.1.x, and 3.2.x, each of which was a major version upgrade with many new features (3.0.x was even a complete rewrite). Who knows how much more time was taken to develop SMF 2.0 from the beginning... Other free software frequently follows similar slow release schedules: phpBB (another popular free forum) has been on 3.0.x (its most recent major version) for almost four years as well, and has added very few new features since then. In contrast, as stated earlier, IPB has a full-time development team working constantly to bring out updates, and the results are self-evident.
-More features. Many of IPB's standard features are either unavailable in free software or require third-party mods to accomplish (which often don't work very well).
-Better design. IPB's administrator panel is literally years ahead of those of free software, and the same thing goes for the end-user interface. IPB is by far the best-looking and easiest to use forum software out there.
-Security. IPS can afford full security audits of the software, so there are no known security issues. If I remember correctly, it's been literally years since any major security holes were found in IPB.
-Support. With your license, you get ticket support with a guaranteed response time of two days (much faster for critical issues), and most issues generally see a reply in several hours assuming it's during the work week. I've used it a number of times, and the responses have always been prompt, professional and extremely helpful, which I'm sure other members will be able to confirm.
-Addons developed by the same company. If you need a blog, gallery, CMS, download manager, chat room, or e-commerce solution for other forums, virtually none have good ones that aren't third-party, but these addons for IPB are 1) reasonably cheap and 2) extremely high-quality. If you're running anything more than a small hobbyist site, then it's a no-brainer.
-If you want a new skin but don't know how to code one yourself, the built-in visual skin editor will be extremely helpful (unlike other forums, which force you to edit the skin code manually, use a low-quality free skin, or hire someone to make a skin for you).

In Topic: Building 1st Forum, have some questions.

12 October 2011 - 05:06 PM

View Postdennykyser, on 12 October 2011 - 04:39 PM, said:

Also, can you imbed photos, and video (youtube) on these forums?
Yes:
[media]http://www.youtube.com/watch?v=dQw4w9WgXcQ[/media]
produces:


[img]http://community.invisionpower.com/public/style_images/master/logo.png[/img]
produces:
Posted Image

Alternately, if you don't want to manually type the bbcodes, click the 'special bbcode' tag (third from the top left) and select Media to insert media from most major sources (not just Youtube), and click the Image button (around the middle of the second editor bar) to insert an image.

In Topic: Considering the switch from vB 4.1 - some questions

27 September 2011 - 06:24 AM

http://www.devfuse.c...r-action-alert/