Bingo. There's always the "shoulda woulda coulda" stance with security, but we've gotta be honest with ourselves here.
1. If we see an updated phpBB in the app vault soon, that doesn't fix current installations, I don't see an easy way for SW-Soft to implement that either, unless they make a "package" consisting of patchfiles. This is gonna trash custom stuff done to phpBBs though, so probabally not a good idea on a hosting box. I don't see a clean way to do mass automation of something so customizable and widely installed. What happens if a customer just installs it themselves, without the app vault? Ther'es no record, no easy way to update it, let alone know where and how it's installed.
2. as has been stated, the wget fix is nothing but duct tape. It's ghetto and I freely admit that, but as of right now, it's a bit of duct tape that has kept my servers from hammering out crazy amounts of bandwidth due to scans/DOSs and psyBNCs. You really have to look at the level of "expertise" of the people pulling off these "hacks". They're script kiddies. They ahve zero clue of what they're doing, they just know they can run a script and own a box. If their script doens't work, they keep on scanning. As of yet, I haven't seen anything that puts it's own wget binary on the server (I'm sure it's out there, just not widespread as of yet.)
We can either sit here and b*tch about what sw-soft should do, gripe about a fix not being "perfect" or we can do what we get paid to do and keep our boxes safe to the best of our abilities until something better comes along.
I dunno about you, but my boxes have been just fine lately and I can now work on a better way to deal with this instead of spending my time cleaning up /tmp and killing ./stealth and ./bind processes.
I apologize if I come off as harsh, but we really need to be realistic about these things and save the hate threads for when they're necessitated.