News:

Bored?  Looking to kill some time?  Want to chat with other SMF users?  Join us in IRC chat or Discord

Main Menu

Security of SMF compared to the other guys?

Started by Gizbeat, February 11, 2013, 07:27:32 AM

Previous topic - Next topic

Gizbeat

I've read some posts by theme makers that their site got hacked and injected... I realize it can happen to anyone, but what is the general consensus regarding how secure SMF is. Has your SMF forum been hacked?

Kindred

SMF has one of the best security records of all forum softwares.
We release security patches as soon as a vector is identified and patched and our package manager system makes patching your own forum much simpler than some of the others.


The only hack that ever hit any of my forum sites came in through a different software (ZenPhoto)
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Arantor

SMF itself is secure but there's an awful lot of bad practice attached to it, like making all your files writable by every process on the server in an attempt to install modifications.


Colin

"If everybody is thinking alike, then somebody is not thinking." - Gen. George S. Patton Jr.

Colin

ARG01

Quote from: Arantor on February 11, 2013, 11:13:40 AM
SMF itself is secure but there's an awful lot of bad practice attached to it, like making all your files writable by every process on the server in an attempt to install modifications.

I agree and this is why I insist on not using mods written by others. I also agree with the other comments as SMF seems to locate and repair or at least be aware of any possible risks before most software providers, including paid software.
No, I will not offer free downloads to Premium DzinerStuido themes. Please stop asking.

Arantor

Not exactly. It isn't because of the mods that make it secure, nor is it because of the mod authors doing a bad job (on the contrary, mods that get published on the official site do get checked)

It is because you have to make everything writable, a problem I've been trying to find a way around for years.

I would also note that if anyone wants a comparison, I picked up an IPB licence in November, there have been at least 4 security patches since then just for IP.Board, not to mention vulnerabilities in other components like IP.Gallery. vBulletin is currently on its 28th (no, that's not a typo) beta version of vB 5...

ARG01

Don't get me wrong. I have nothing personal against mods in general. I just don't like anything altering my files and/or permissions other than myself.
No, I will not offer free downloads to Premium DzinerStuido themes. Please stop asking.

Arantor

This is why I've been pushing for a system that doesn't require changing either permissions or files in the first place... ;)

Antechinus

Yebbut you can always 777 stuff to install a mod, then put it back to 644. Admittedly not totally n00b-proof, but hardly difficult either (assuming the user has some basic proficiency with FTP). So although it would certainly be nice to have it all handled automatically, personally I don't see it as a huge drawback.

Arantor

That's the problem... people *don't*. They get it working and leave it as it is because it 'works'.

Antechinus

Well it's not too bad as long as the host implements good server security, and as long as the admins are careful about securing their accounts and pooters.

If none of those things are taken care of, you're probably screwed anyway.

Advertisement: