Archive for December, 2007

Mihalism Multi Forum Host 3.0.x Remote File Inclusion Vulnerability

Sunday, December 30th, 2007

If you are running a version of Mihalism Multi Forum Host that was downloaded prior to December 30, 2007, then please download it again, and reupload the following files to fix a potential security risk within the forum loader.

  • source/includes/load_forum.php

The security risk would allow for a hacker to modify the root path that Mihalism Multi Forum Host uses and include a file that could potentially damage your site and server. If your PHP version is configured to disable the register_globals setting, then there is nothing to worry about, but it is still highly recommended to reupload.

To check if the register_globals setting is disabled on your server, download and upload to your server the attached file. Once uploaded, open the file in your web browser, and it will let you know if your server is secure. Don’t forget to delete the file once you have used it.

register_globals Checker: rg_check.php (Hypertext Preprocessor File)

If your site has been hacked:

If your website has been hacked due to this vulnerability, then contact a Mihalism staff member and we will provide for free a clean up for your site. This clean up will repair any damaged files and delete any weird files the hackers may have left behind.

Mihalism Multi Forum Host V3.0.0 Revision 1

Monday, December 24th, 2007

Today Mihalism, Inc. is releasing a revision of Mihalism Multi Forum Host v3.0.0. This is being done to fix some bugs within it. We chose not to wait until the next version because of the severity of some of the bugs. Shown below is a list of bugs fixed. We apologize to for this incident, and will try everything in our power to prevent it from happening again.

Bugs Fixed:

  • Cannot delete forum from remote database.
  • Cannot edit forum settings from remote database.
  • Cannot remove database.
  • Remote database connection not loading properly.
  • And a couple minor bugs.

If you are already running a 3.0.0 site, then just download a fresh copy of Mihalism Multi Forum Host, and reupload the list of files shown below, with the ones from the fresh download.

Changed Files:

  • admin.php
  • index.php
  • source/includes/database.php
  • soruce/includes/load_forum.php
  • phpBB3/includes/install/table_names.php
  • phpBB3/includes/acp/acp_styles.php
  • phpBB3/adm/styles/acp_styles.html

Mihalism Web Search v2.0.1

Friday, December 21st, 2007

Today Mihalism, Inc. is proud to introduce Mihalism Web Search v2.0.1. This new version is a complete rewrite of version 1.x. It has been rewritten to better improve its performance and to make some design changes. We hope you like the changes that have been made. Follow the link shown below for more information.

Download Now 

Mihalism Multi Forum Host v3.0.0 Final

Wednesday, December 19th, 2007

Mihalism, Inc. is releasing the first ever free, open source, and easy to use phpBB3 hosting script. Unlike our previous versions of Mihalism Multi Forum Host, that ran Invison Power Board, this script is completely built from the ground up, a system which will work for everyone. The new system uses a single URL rewrite statement to make short URLs, unlike the old way when we created forum files. In addition, the administrators now have more control over their hosted forums. An administrator can add another admin, manage directory categories, delete forums, etc. So download today, and enjoy the power that Mihalism Multi Forum Host can provide.

Download Now

Mihalism Multi Host Stats - November 2007

Wednesday, December 12th, 2007

Mihalism Multi Host has its very own built-in tracking system powered by Google Analytics which is used by us to track how many websites use it. The statistics shown below are a collection of all the stats collected since the first version that introduced the tracker, up to November 30, 2007. Also, you can find attached to this entry a copy of the top 500 ranked websites as-of the above mentioned date.

  • 7,631,888 Visits
  • 4,956,215 Absolute Unique Visitors
  • 23,401,502 Pageviews
  • 54.70% Bounce Rate
  • 64.98% New Visits
  • Top Browser: Internet Exploring 4,012,548 52.58%
  • 5,837 Total Websites

Traffic Sources:

  • Referring Sites 6,833,304 (89.54%)
  • Direct Traffic 747,428 (9.79%)
  • Search Engines 50,323 (0.66%)
  • Other 833 (0.01%)

Top 500 Sites: top5003.pdf (Portable Document Format File)