XF 1.x maintainance

HWS

Well-known member
For several reasons (often the high costs of upgrading the theme, the add-ons and the server admin work time and cost needed) we still run 2 Xenforo sites using the most recent (and last) version of 1.5 of the software.

Because that version is no longer maintained by the XF team since a long time, there may be security problems with that old software. For example, recently we received an email by an unknown person titled "Vulnerability Report-Broken Authentication" regarding one of our XF 1.5 forums who wants a "bounty" for finding that vulnerability.

I do not want to include the whole text of the message here, but he writes that the session management of XF 1.5 is broken and it is possible to change a session (in detail the authentication password) for a user from another, different browser within the same access IP address. So it looks like the session is stored at the server with a user_id key only and no check for the client used with that session. I don't know if that report is true but I also do not see that issue as very problematic if true. If someone knows the password he can always do what he wants.

Regardless of that possible issue and since I know that some people here still use version 1 of the software I want to ask if there would be any interest in creating some kind of XF 1.5 user interest group where any existing or future security concerns with XF 1.5 could be handled and financed to be rolled out at our old forums.

I know that upgrading to the most recent XF 2 version would be the best solution, but -again- for some of us this is simply not possible at the moment for different reasons.

So XF 1 users, where are you and what problems have you found and maybe already needed to be patched with XF 1.5?
 
For example, recently we received an email by an unknown person titled "Vulnerability Report-Broken Authentication" regarding one of our XF 1.5 forums who wants a "bounty" for finding that vulnerability.
I also get these emails occasionally for my various pages. Sometimes for email server settings etc. In my opinion, they just want your money.

But, as you already said, upgrade to XF 2 when possible.
 
  • Like
Reactions: HWS
I would ignore the bounty seekers - I get those emails occasionally too.

The value of hacking most forums is pretty low - so I wouldn't be overly concerned. That's not a reason to not upgrade - just trying to be pragmatic about the risks.

I've still got two sites on 1.5 - I've not had any problems other than being forced to keep those servers on PHP 7.3 which is causing problems for some of the other software I want to run on them which requires PHP 8.x ... and that's only going to get worse.

I'm close to being ready to upgrade one of my sites - the other is going to take a few more months of work before I'll be ready.

My goal is to have both sites upgraded to 2.3 (or 2.4!!) by the end of Q2 2025.
 
Back
Top Bottom