Page 1 of 1

Patch

Posted: Tue Dec 14, 2004 6:28 pm
by JensJohansson
I had to patch a few board files due to a security issue. I did the critical ones manually since they seemed to bundle some less useful stuff. Might do it later.

Thanks to Kaoru for pointing out that there was a bulletin.

Any irregularities -> contact me via email.

Nothing else to report at this time.

Re: Patch

Posted: Tue Dec 14, 2004 9:04 pm
by Electric Eye
JensJohansson wrote:Nothing else to report at this time.
What a pity... :(

Re: Patch

Posted: Tue Dec 14, 2004 9:20 pm
by So Death May Die
Electric Eye wrote:
JensJohansson wrote:Nothing else to report at this time.
What a pity... :(
:cry: :cry: :cry: :cry: :cry:

Oh well... at least the underpopulated forum is getting fixed somewhat.

Re: Patch

Posted: Tue Dec 14, 2004 10:38 pm
by JensJohansson
So Death May Die wrote: Oh well... at least the underpopulated forum is getting fixed somewhat.
Oh it's not really getting fixed, I mean it will look the same.

If there was some sort of compromise because of this I have just about decided I will probably just delete it. Enough already.

SQL injection on the strato site would be Very Very Bad. Tero tied mysql into almost everything. I like static pages me, call me a dinosaur. What the fuck is a filesystem if not just another database??!??

I am grepping the logs as we type. I tell you, if some goblin got in I really will wash my hands of this phpbb forum shit, this bug ridden viper's nest, this fucking shit piñata..

But lets hope for the best!

EDIT:

Well this time we all were lucky. The closest thing to a breach was some romanian trying to execute a file. Wrong binary format.... :lol: Other people just drifting by and looking around. "w;uname -a;id" etc.

Somehow the apparent battle of egos about this whole exploit doesn't give me a warm feeling about phpBB... no offense.

http://www.phpbb.com/phpBB/viewtopic.ph ... sc&start=0

I do wonder what other holes are in this piece of shit.

Re: Patch

Posted: Wed Dec 15, 2004 12:29 pm
by browneyedgirl
I Was able to change my profile! YIPPPPPPPEEEEEEEEE!!!!:rvd:

Thanks, Jens!!!!Hope it stays clear----I like variety in my sig&avatar. I like to change it ever so often! :D
:leapfrog: :jump2: :crazy2:

HEEEHEEEEHEEEE! ;)

Re: Patch

Posted: Wed Dec 15, 2004 12:43 pm
by hatescream
JensJohansson wrote:
So Death May Die wrote: Oh well... at least the underpopulated forum is getting fixed somewhat.
Oh it's not really getting fixed, I mean it will look the same.

If there was some sort of compromise because of this I have just about decided I will probably just delete it. Enough already.

SQL injection on the strato site would be Very Very Bad. Tero tied mysql into almost everything. I like static pages me, call me a dinosaur. What the fuck is a filesystem if not just another database??!??

I am grepping the logs as we type. I tell you, if some goblin got in I really will wash my hands of this phpbb forum shit, this bug ridden viper's nest, this fucking shit piñata..

But lets hope for the best!

EDIT:

Well this time we all were lucky. The closest thing to a breach was some romanian trying to execute a file. Wrong binary format.... :lol: Other people just drifting by and looking around. "w;uname -a;id" etc.

Somehow the apparent battle of egos about this whole exploit doesn't give me a warm feeling about phpBB... no offense.

http://www.phpbb.com/phpBB/viewtopic.ph ... sc&start=0

I do wonder what other holes are in this piece of shit.
maybe you could just erase the board and re-install it as new... :?:

Re: Patch

Posted: Sat Dec 25, 2004 4:39 pm
by Kaoru
JensJohansson wrote:Thanks to Kaoru for pointing out that there was a bulletin.
:D

Sorry , late to come here...

After I did automatic update, I rewrote manually of mine.:)

BTW
Some days ago , Google bot came to my forum in many times in many days.
It used about the half of my server's Bandwidth.
(Maybe by Santy???)
I denied their IP. :lol:

Re: Patch

Posted: Sat Dec 25, 2004 4:46 pm
by Kaoru
hatescream wrote:maybe you could just erase the board and re-install it as new... :?:
I think it's not easy.
and even if Jens did re-install , but is not solved only with it in case of using PHP CGI etc.

Re: Patch

Posted: Sat Dec 25, 2004 7:06 pm
by cliff
Kaoru wrote:[Some days ago , Google bot came to my forum in many times in many days.
It used about the half of my server's Bandwidth.
(Maybe by Santy???)
I denied their IP. :lol:
Good thing !
Google is the biggest spyware u could ever find around.
I still can't understand why Strato team put that stupid ad banner here.
Of course there was one "good" thing in it, but still, one thing against many bad ones...

Re: Patch

Posted: Sat Dec 25, 2004 7:22 pm
by Kaoru
cliff wrote:
Kaoru wrote:[Some days ago , Google bot came to my forum in many times in many days.
It used about the half of my server's Bandwidth.
(Maybe by Santy???)
I denied their IP. :lol:
Good thing !
Google is the biggest spyware u could ever find around.
I still can't understand why Strato team put that stupid ad banner here.
Of course there was one "good" thing in it, but still, one thing against many bad ones...
I think Google is not bad for some purpose.
I usually don't deny them.
But at now , It is not usual.
They come too much!
So I denied them.

banner?
I think I looked it once , but it is not visible to me.
Is it still visible to you?

Re: Patch

Posted: Sat Dec 25, 2004 7:39 pm
by cliff
Kaoru wrote:[banner?
I think I looked it once , but it is not visible to me.
Is it still visible to you?
not anymore.
They probably forgot to put it back with the new Php code.
or perhaps removed it in purpose, en tiedä.