Welcome, Guest. Please Login or Register.
April 26, 2024, 07:53:57 AM
Home Help Search Log in Register
News: If you are still using YaBB SE, please consider upgrading to SMF as soon as possible.

YaBB SE Community  |  YaBB SE Info  |  News From the YaBB SE Team  |  SECURITY FIX! Users using any version prior to 1.5.1 « previous next »
Pages: 1 ... 3 4 [5] 6 7 ... 12 Reply Ignore Print
Author Topic: SECURITY FIX! Users using any version prior to 1.5.1  (Read 96316 times)
Jeff Lewis
Global Moderator
YaBB God
*****
Posts: 10149


I'm a llama!

WWW
Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #60 on: February 02, 2003, 09:38:08 PM »
Reply with quote

Don't feel terrible, it was an accident on our part and our fault. It can be annoying but some people are acting like their life is going to end because they received an email about a security fix 7-10 times...

Just make sure you patch your install ;)
« Last Edit: February 02, 2003, 09:38:34 PM by Jeff Lewis » Logged

Sergio
Noobie
*
Posts: 21


WWW
Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #61 on: February 02, 2003, 09:38:35 PM »
Reply with quote

Thanks for the advise, I have fixed it.

I'm glad that there were 9 or 10 emails, because I use some strong email filters, and the filter program has considered them as spam, as (I think) "sent to nobody".

But with nine equal subjects in the report I have noticed them.

Uuuhhh, pherhaps I'm not so clear  ;), however...

THANKS !  :D
Logged
Overseer
Sr. Member
****
Posts: 455


Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #62 on: February 02, 2003, 09:52:07 PM »
Reply with quote

Quote from: Jeff Lewis on February 02, 2003, 09:16:04 PMThanks Snoopy. Not sure why Overseer is so mad...his messages table got seriously corrupted this week and he should ask Corey who was helping fix it...so a few extra emails by accident shouldn't be too hard to swallow :)

umm unrelated but.. i'm very grateful to him and I will continue to bring him customers (4 to my knowledge so far).

lol jeff i'm not mad. i was just saying that (before it was pointed out it was a bug) it was weird to have those mails and  if it were on purpose that I thought it was out of order.  am just shocked that some people think thats a legit way to highlight the issue to people and that they'd leap to defend such an action.

now for some irony ;)

just an idea. but it might be a good idea to do one more which explains about the email problem and the security fix because of those 'bad mails' which lead to a now deleted post.
Logged

I learned that from the G's, a G is an Overseer, the Overseer sees.
More than you do 'cause he gets experienced - Snoop on Daz's OG

Supreme exalted, universal leader, Descendent of the kings and queens, the Overseer
The overlord, cream of the crop, creme de la creme - Gang Starr  Royalty
sensovision
Full Member
***
Posts: 100


WWW
Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #63 on: February 02, 2003, 10:05:58 PM »
Reply with quote

It's nice to see that many people to pay attention to fix now, so I believe that this bug in this case were good as it's force people to pay attention for security measures... I carefully read all anouncements but I didn't get this announcement... maybe it was becasue it's sended less or more in the time when problem have major slowdown across the web due to worm attack, so anyway I'm sure that I didn't get first announcement and second was from some person who I never heard about...
so I believe 10 or more mails is good price to pay for saving you and your members from hackers attacks.
Logged

Denis

Are you good with the graphic? check out our design logo contest!
Jeff Lewis
Global Moderator
YaBB God
*****
Posts: 10149


I'm a llama!

WWW
Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #64 on: February 02, 2003, 10:07:30 PM »
Reply with quote

Yes, I've heard from at least 12 people already that ignored the first announcement on this...
Logged

acf [delete me]!
YaBB God
*****
Posts: 521


la especialidad de grafic

WWW
Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #65 on: February 02, 2003, 10:29:41 PM »
Reply with quote

I've pluged the hole :D

thanx yabb team  8)

And stop spamming in this tread about the many mails you get. Beter to have a lot of mails then to have board that is cracked.

peace  ;)
Logged

UKA_Bart
Noobie
*
Posts: 7


Wisdom quote #16523: "No."

bart@kluitman.nl WWW
Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #66 on: February 03, 2003, 12:42:18 AM »
Reply with quote

Quote from: Jeff Lewis on February 02, 2003, 08:48:09 PMIf the little problem with the extra emails saves at least one persons forum I'm fine with that.
I agree. Send me as many warningmails as you (or your script :-)  likes. I don't mind. As long as I'm warned about something that potentially makes me lose my forum all together.

Thanks!  ;)
Logged
phark
Sr. Member
****
Posts: 482


Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #67 on: February 03, 2003, 01:05:50 AM »
Reply with quote

Quote from: Overseer on February 02, 2003, 06:42:07 PMThats BS.. one is enuf.. anymore is just spam.

On something this important, I don't mind getting 10 emails.  Stop your crying.   :P
Logged

I'm not scared of dying, I just don't want to.
Agelmar
YaBB God
*****
Posts: 931


Takako Matsu = Goddess

Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #68 on: February 03, 2003, 01:30:34 AM »
Reply with quote

Just out of curiosity Jeff, was this a bug in NotifyUsersNewAnnouncement() that we all need to patch our installations for, or was this some outside script you coded to do announcements for YSE? (i.e. do I need to worry about infinite looping on my board, or is this a script not a part of YSE?)
Logged

Jeff Lewis
Global Moderator
YaBB God
*****
Posts: 10149


I'm a llama!

WWW
Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #69 on: February 03, 2003, 01:35:07 AM »
Reply with quote

I'm still trying to see if anyone messed with the announcement script. It was fine during our last announcement but we knew it needed work so someone may have screwed with it...
Logged

eknee
Noobie
*
Posts: 3


I'm a llama!

Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #70 on: February 03, 2003, 02:32:59 AM »
Reply with quote

I've been hacked by this.  I've made the update to Packages.php, but is there anyway to recover the database?

Where other user names and passwords in the MySQL database exposed?

Thanks,
Eric
Logged
Alex Rolko
Almighty
Global Moderator
YaBB God
*****
Posts: 4624


Fury of Me

Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #71 on: February 03, 2003, 02:35:27 AM »
Reply with quote

passwords are encrypted, so all passwords were safe.
Logged


ThinkGeek.com Wishlist | Just call me Xander...
I'm sorry but I don't answer support requests
eknee
Noobie
*
Posts: 3


I'm a llama!

Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #72 on: February 03, 2003, 02:43:31 AM »
Reply with quote

Ok.  Thank you.

In case you're collecting this type of info, here's an entry from my log file...

200.181.183.199 - - [02/Feb/2003:15:26:16 -0800] "GET /modules/forum/index.php H
TTP/1.1" 200 5984 "http://www.google.com.br/search?q=Powered+by+YaBB+SE+site:.or
g&hl=pt&lr=&ie=UTF-8&start=180&sa=N" "Mozilla/4.0 (compatible; MSIE 5.0; Windows
 98; DigExt)"
Logged
Jeff Lewis
Global Moderator
YaBB God
*****
Posts: 10149


I'm a llama!

WWW
Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #73 on: February 03, 2003, 02:46:00 AM »
Reply with quote

The same idiots going around and abusing this exploit...this is why we posted an announcement about it when it first came out...sadly not everyone has patched up.
Logged

Ichiban
Noobie
*
Posts: 6


Does this mawashi make me look fat?

Re:SECURITY FIX! Users using any version prior to 1.5.1
« Reply #74 on: February 03, 2003, 03:20:59 AM »
Reply with quote

Thanks for the update guys. Didn't mind the extra emails at all. Extremely small price to pay IMHO.

I kind of doubt my little personal board was exploited, but is there anything in particular that might indicate it was owned? Something in the access log perhaps or a likely modification that might be made via this vulnerability?

Just want to make sure everything is OK now that it's been patched. I think I understand what the hole was about, but I don't have a feel for the limits of the damage that might have been done.
Logged
Pages: 1 ... 3 4 [5] 6 7 ... 12 Reply Ignore Print 
YaBB SE Community  |  YaBB SE Info  |  News From the YaBB SE Team  |  SECURITY FIX! Users using any version prior to 1.5.1 « previous - next »
 


Powered by MySQL Powered by PHP YaBB SE Community | Powered by YaBB SE
© 2001-2003, YaBB SE Dev Team. All Rights Reserved.
SMF 2.1.4 © 2023, Simple Machines
Valid XHTML 1.0! Valid CSS

Page created in 0.050 seconds with 20 queries.