Recently, the National Computer Virus Emergency Treatment center monitoring found that many of the Internet use of dynamic Web technology to create a forum with a large number of loopholes. A malicious attacker could exploit these vulnerabilities to attack the forum for access to the Forum's administrative authority.
In response to the National Computer Virus Emergency Management center of the monitoring Report, sing, CEO Dai in the acceptance of Tencent technology, said the loophole in fact, has existed for many years, the harm is not very big.
"Forum vulnerabilities generally have three kinds, the first is related to the server, the virus can directly attack the server, the second is the vulnerability crisis site itself database, the third is a Web page hanging horse." "Dai said.
In his view, the Emergency Processing Center issued a forum loophole should belong to the third, the vulnerability of the main forum visitors pose a security threat. However, if the visitor's computer is patched and the anti-virus software is installed, there will not be much problem.
According to Jinshan Poison PA safety expert Tiejun said, the domestic current most forum uses is phpwind and Discuz forum product, these two product architecture is relatively safe, should not exist this flaw problem. In addition, the commercial large-scale forum uses the Linux architecture more, therefore the administrative privilege will not be obtained by the attacker.
"At present, almost all forums, including blogs, use dynamic Web pages, so the vulnerability has been in effect for many years." If the Discuz forum really encounters a serious flaw, we will send SMS reminders to users. "Dai said.
Sing company mainly provides Internet community products and services, community forum (BBS) software products discuz! is the core products, with six years of development history, is the largest user use, coverage of the most extensive community BBS software.
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.