by Takarious » Sat Dec 11, 2004 7:36 pm
If it's a real big issue, split your server into two seperate FTP accounts and place the forum on one. Giving the forum full-scale 777 access and letting it make, edit, and delete files as the script deems fit allows any exploits to be abused to the fullest extent of the attackers imagination. This is all just heresay, I have no personal experience with PHPBB2, so I have no idea what kind of attack was performed. Whether it involved taking control of a gaining informatino through a faulty MySQL database and tracking upward, or simply just a flaw in code. All 3rd party forums I use are generally Invision board. And along time ago I'd use Ikonboard for Perl based boards.