View Single Post
  #19  
Old November 6, 2006, 06:10 PM
Dien Rice Dien Rice is offline
Onwards and upwards!
 
Join Date: Aug 2006
Posts: 3,369
Default The vulnerabilities of WebBBS (the "old forum" software)...

Hi John,

I agree with many of your points... I think it's a bit of give and take, since there's also more on offer now too (eg. the ability to create a poll, etc.), in addition to the points you raise...

I did a check, and this new forum has averaged 19 new posts a day since we started - which doesn't seem too bad to me! (I haven't checked what the average was at the "old" forum, but I'm sure it was probably similar...)

As I mentioned before, the reason we had to change was because of Denial-of-Service attacks. The flaw in WebBBS (the old forum software) which permitted this has been documented - you can read about it here... http://www3.ca.com/securityadvisor/v....aspx?ID=19240. In a nutshell, people (who know what they're doing) can attack WebBBS to "consume system resources" - which means they'll crash the server (which is what happened with the old Sowpub forum about 3 times).

I know other people are still using WebBBS - they're lucky nobody has so far wanted to attack them. However, to continue using WebBBS means they remain vulnerable to these attacks if anyone decides to perform one. (They don't have to do it for any reason - sometimes people do these kinds of things just to see if they can.)

Unfortunately, there's no other forum software "out there" which I've seen which is exactly like WebBBS in how it operates... I've tried to go with the best I could find!

- Dien
Reply With Quote