corsasport.co.uk
 

Corsa Sport » Message Board » Off Day » Geek Day » phpBB forums and security


New Topic

New Poll
  Subscribe | Add to Favourites

You are not logged in and may not post or reply to messages. Please log in or create a new account or mail us about fixing an existing one - register@corsasport.co.uk

There are also many more features available when you are logged in such as private messages, buddy list, location services, post search and more.


Author phpBB forums and security
Balling
Premium Member

Avatar

Registered: 7th Apr 04
Location: Denmark
User status: Offline
20th Dec 13 at 09:41   View Garage View User's Profile U2U Member Reply With Quote

How secure is a standard phpBB forum?

Reason I ask is that our supply and logistics department has just opened a phpBB forum for internal communication.

Now aside from the fact that the whole idea behind having a forum is insane, how secure is this thing?

We'll be discussing a lot of very confidential matters, and it's beyond important that nothing ends up being indexed by Google or is somehow accessible to outsiders.


ed
Member

Registered: 10th Sep 03
User status: Offline
20th Dec 13 at 09:53   View User's Profile U2U Member Reply With Quote

Keep it on your intranet and it's as secure as you like.
John
Member

Registered: 30th Jun 03
User status: Offline
20th Dec 13 at 09:58   View User's Profile U2U Member Reply With Quote

Sounds like the sort of thing they could probably use sharepoint for.
Balling
Premium Member

Avatar

Registered: 7th Apr 04
Location: Denmark
User status: Offline
20th Dec 13 at 10:00   View Garage View User's Profile U2U Member Reply With Quote

quote:
Originally posted by ed
Keep it on your intranet and it's as secure as you like.
It's on the internet.


ed
Member

Registered: 10th Sep 03
User status: Offline
20th Dec 13 at 10:15   View User's Profile U2U Member Reply With Quote

I don't think that's a very good idea. Is it through a PHPbb provider? If it is then the t&c's will most likely be incompatible with your needs. I.E. they'll own the data e.t.c.
pow
Premium Member

Avatar

Registered: 11th Sep 06
Location: Hazlemere, Buckinghamshire
User status: Offline
20th Dec 13 at 10:17   View Garage View User's Profile U2U Member Reply With Quote

Disaster. Internally on an internal only web server fine (as long as the network is secure!?!)
Balling
Premium Member

Avatar

Registered: 7th Apr 04
Location: Denmark
User status: Offline
20th Dec 13 at 10:21   View Garage View User's Profile U2U Member Reply With Quote

I'm not sure, but I don't think it is.

It's installed on our own server, which is externally hosted.

All users need to be approved by admin before they can see threads.

John - Nobody would ever agree on who should pick up the bill, so anything not free (or very cheap) isn't going to happen.

Either way, I'm not about to tell them what to do or how to solve it.
I was mostly just curious as the phpBB forum initially struck me as an unprofessional and potentially unsafe solution.


John
Member

Registered: 30th Jun 03
User status: Offline
20th Dec 13 at 10:37   View User's Profile U2U Member Reply With Quote

Sharepoint foundation is free if you've got a server to stick it on.
Balling
Premium Member

Avatar

Registered: 7th Apr 04
Location: Denmark
User status: Offline
20th Dec 13 at 10:55   View Garage View User's Profile U2U Member Reply With Quote

Oh, in that case it'll probably be ideal.

Will never happen, though. I suspect the IT guy has spent most of the week setting up a BB forum and thinks it's probably amongst the first of its kind on the internet.


Root
Member

Registered: 28th Dec 08
User status: Offline
20th Dec 13 at 12:56   View User's Profile U2U Member Reply With Quote

All forums have security exploits at some point or another.

I'd be more concerned about hosting the server remotely, rather than what software the forum is using
John
Member

Registered: 30th Jun 03
User status: Offline
20th Dec 13 at 12:57   View User's Profile U2U Member Reply With Quote

Nothing inherently wrong or insecure about hosting a server remotely, that has no bearing on it being accessible to the internet.
Dom
Member

Registered: 13th Sep 03
User status: Offline
20th Dec 13 at 13:33   View User's Profile U2U Member Reply With Quote

quote:
Originally posted by Balling
initially struck me as an unprofessional....


It could be locked down to hide it from the internet but i personally don't see how forum software fits into a corporate environment (as mentioned, Sharepoint is a better option) - what's wrong with emails?


quote:
Originally posted by Balling
John - Nobody would ever agree on who should pick up the bill, so anything not free (or very cheap) isn't going to happen.


(Going from previous threads) I'm guessing money isn't an issue if they're happy to purchase Apple hardware?
Sounds like someone needs a slap.
Balling
Premium Member

Avatar

Registered: 7th Apr 04
Location: Denmark
User status: Offline
20th Dec 13 at 14:25   View Garage View User's Profile U2U Member Reply With Quote

quote:
Originally posted by Dom
It could be locked down to hide it from the internet but i personally don't see how forum software fits into a corporate environment (as mentioned, Sharepoint is a better option) - what's wrong with emails?
Well to not go in to too much unnecessary (and boring) detail, it's a new logistics setup that's still a work in progress, so at the moment there's a lot of questions being asked.
As the people involved are horrible at providing proper information, they're now drowning in emails with all the same questions.
As a band aid for an open head wound they've requested that everyone post their questions on a forum, so they don't have to waste time replying to the same emails and can continue more prudent work, while still avoiding to provide proper information.

And I agree, there shouldn't be anything wrong with emails. This whole forum setup is a reflection of the issue, not a solution for it.[/rant]

quote:
Originally posted by Dom
(Going from previous threads) I'm guessing money isn't an issue if they're happy to purchase Apple hardware?
Sounds like someone needs a slap.
It's not actually the same company. Though within the same family, logistics is a completely different company.


VrsTurbo
Premium Member

Registered: 8th Jun 10
User status: Offline
20th Dec 13 at 14:33   View Garage View User's Profile U2U Member Reply With Quote

i personally don't see an issue with a forum... Sharepoint has a forum feature. I know of 2 massive companies that use forums (yes bespoke ones) but none the less its there
Balling
Premium Member

Avatar

Registered: 7th Apr 04
Location: Denmark
User status: Offline
20th Dec 13 at 14:38   View Garage View User's Profile U2U Member Reply With Quote

It was mostly the security of this specific forum software that concerned me.



 
New Topic

New Poll

  Related Threads Author Forum Replies Views Last Post
How to make a forum like corsasport? Keithie General Chat 6 758
18th Aug 04 at 10:13
by blundey
 
phpbb users Drew Geek Day 6 877
26th Dec 04 at 20:18
by Joff
 
Forums Andrew Geek Day 4 859
17th Dec 06 at 00:16
by James_DT
 
question about forums (phpbb) and SQL Bart Geek Day 4 366
5th Nov 07 at 00:12
by Ian
 
phpBB / myPHP forum question - help required ASAP please Rich H Geek Day 7 229
29th Oct 09 at 16:14
by Rich H
 

Corsa Sport » Message Board » Off Day » Geek Day » phpBB forums and security 29 database queries in 0.0159540 seconds