Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 07 Nov 2003 08:31:27 -0600
From:      Kirk Strauser <kirk@strauser.com>
To:        freebsd-stable@freebsd.org
Subject:   Re: hack ? - urgent - false FreeBSD alarm
Message-ID:  <8765hw8d34.fsf@strauser.com>
In-Reply-To: <20031107132650.H19165@voyager.zrcalo.si> (Miha Nedok's message of "Fri, 7 Nov 2003 13:30:50 %2B0100 (CET)")
References:  <20031107125529.R19165@voyager.zrcalo.si> <3FAB8B3A.7020908@remotelab.org> <20031107132650.H19165@voyager.zrcalo.si>

next in thread | previous in thread | raw e-mail | index | archive | help
--=-=-=
Content-Transfer-Encoding: quoted-printable

At 2003-11-07T12:30:50Z, Miha Nedok <mike@voyager.unix-systems.net> writes:

> I just did chmod 000 `find -name 'install.php'` for a workaround.

While I symphathize with what happened, that's what happens when you don't
follow instructions.  The pkg-message for the www/phpbb port says:

    After configuring phpBB2 and ensuring that it is operational, you MUST
    delete the following files manually for security purposes from
    /usr/local/www/data/phpBB2:

      /usr/local/www/data/phpBB2/install/install.php
      /usr/local/www/data/phpBB2/install/upgrade.php
      /usr/local/www/data/phpBB2/install/update_to_206.php

So, why don't you go ahead and do that before it's too late.
=2D-=20
Kirk Strauser

"94 outdated ports on the box,
 94 outdated ports.
 Portupgrade one, an hour 'til done,
 82 outdated ports on the box."

--=-=-=
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQA/q6zE5sRg+Y0CpvERAo7nAJ0TUvu+tGT6M4uZHNg+FC0NuVWtdACfQ/ny
XOTTtdUZQMkQHw4NQFeqDCI=
=HWrD
-----END PGP SIGNATURE-----
--=-=-=--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?8765hw8d34.fsf>