Patch

Talk about everything else besides Stratovarius here in English. Please try to put more serious topics here, and silly topics in the Spam section.
Locked
User avatar
JensJohansson
Administrator
Posts:1490
Joined:Thu Feb 28, 2002 10:45 pm
Contact:
Patch

Post by JensJohansson » Tue Dec 14, 2004 6:28 pm

I had to patch a few board files due to a security issue. I did the critical ones manually since they seemed to bundle some less useful stuff. Might do it later.

Thanks to Kaoru for pointing out that there was a bulletin.

Any irregularities -> contact me via email.

Nothing else to report at this time.
Jens.

================================
"Koskenkorva is very good."
-Ronald Reagan
================================

User avatar
Electric Eye
Sr. Member
Posts:441
Joined:Thu Apr 29, 2004 7:26 pm

Re: Patch

Post by Electric Eye » Tue Dec 14, 2004 9:04 pm

JensJohansson wrote:Nothing else to report at this time.
What a pity... :(
So where does the power come from to see the race to its end?
From within.

User avatar
So Death May Die
Member
Posts:122
Joined:Thu Dec 09, 2004 8:50 pm
Location:FL, USA
Contact:

Re: Patch

Post by So Death May Die » Tue Dec 14, 2004 9:20 pm

Electric Eye wrote:
JensJohansson wrote:Nothing else to report at this time.
What a pity... :(
:cry: :cry: :cry: :cry: :cry:

Oh well... at least the underpopulated forum is getting fixed somewhat.
Can you see the sky?
It's filtering like a murder...

User avatar
JensJohansson
Administrator
Posts:1490
Joined:Thu Feb 28, 2002 10:45 pm
Contact:

Re: Patch

Post by JensJohansson » Tue Dec 14, 2004 10:38 pm

So Death May Die wrote: Oh well... at least the underpopulated forum is getting fixed somewhat.
Oh it's not really getting fixed, I mean it will look the same.

If there was some sort of compromise because of this I have just about decided I will probably just delete it. Enough already.

SQL injection on the strato site would be Very Very Bad. Tero tied mysql into almost everything. I like static pages me, call me a dinosaur. What the fuck is a filesystem if not just another database??!??

I am grepping the logs as we type. I tell you, if some goblin got in I really will wash my hands of this phpbb forum shit, this bug ridden viper's nest, this fucking shit piñata..

But lets hope for the best!

EDIT:

Well this time we all were lucky. The closest thing to a breach was some romanian trying to execute a file. Wrong binary format.... :lol: Other people just drifting by and looking around. "w;uname -a;id" etc.

Somehow the apparent battle of egos about this whole exploit doesn't give me a warm feeling about phpBB... no offense.

http://www.phpbb.com/phpBB/viewtopic.ph ... sc&start=0

I do wonder what other holes are in this piece of shit.
Jens.

================================
"Koskenkorva is very good."
-Ronald Reagan
================================

User avatar
browneyedgirl
Sr. Member
Posts:27239
Joined:Thu Aug 29, 2002 6:00 pm
Location:Starfall
Contact:

Re: Patch

Post by browneyedgirl » Wed Dec 15, 2004 12:29 pm

I Was able to change my profile! YIPPPPPPPEEEEEEEEE!!!!:rvd:

Thanks, Jens!!!!Hope it stays clear----I like variety in my sig&avatar. I like to change it ever so often! :D
:leapfrog: :jump2: :crazy2:

HEEEHEEEEHEEEE! ;)
Last edited by browneyedgirl on Wed Dec 15, 2004 12:44 pm, edited 1 time in total.
"Your life is yours, and yours alone. Rise up and live it!"

Bob: I don't believe in God.
Archangel Michael: That's OK, Bob, because He doesn't believe in you, either!~Legion~

hatescream
Jr. Member
Posts:10
Joined:Tue Oct 26, 2004 1:49 pm
Location:Padua, Italy
Contact:

Re: Patch

Post by hatescream » Wed Dec 15, 2004 12:43 pm

JensJohansson wrote:
So Death May Die wrote: Oh well... at least the underpopulated forum is getting fixed somewhat.
Oh it's not really getting fixed, I mean it will look the same.

If there was some sort of compromise because of this I have just about decided I will probably just delete it. Enough already.

SQL injection on the strato site would be Very Very Bad. Tero tied mysql into almost everything. I like static pages me, call me a dinosaur. What the fuck is a filesystem if not just another database??!??

I am grepping the logs as we type. I tell you, if some goblin got in I really will wash my hands of this phpbb forum shit, this bug ridden viper's nest, this fucking shit piñata..

But lets hope for the best!

EDIT:

Well this time we all were lucky. The closest thing to a breach was some romanian trying to execute a file. Wrong binary format.... :lol: Other people just drifting by and looking around. "w;uname -a;id" etc.

Somehow the apparent battle of egos about this whole exploit doesn't give me a warm feeling about phpBB... no offense.

http://www.phpbb.com/phpBB/viewtopic.ph ... sc&start=0

I do wonder what other holes are in this piece of shit.
maybe you could just erase the board and re-install it as new... :?:
---
told you not to fuck around!

User avatar
Kaoru
Sr. Member
Posts:469
Joined:Fri Jun 13, 2003 7:56 am
Location:Tokyo, Japan
Contact:

Re: Patch

Post by Kaoru » Sat Dec 25, 2004 4:39 pm

JensJohansson wrote:Thanks to Kaoru for pointing out that there was a bulletin.
:D

Sorry , late to come here...

After I did automatic update, I rewrote manually of mine.:)

BTW
Some days ago , Google bot came to my forum in many times in many days.
It used about the half of my server's Bandwidth.
(Maybe by Santy???)
I denied their IP. :lol:

User avatar
Kaoru
Sr. Member
Posts:469
Joined:Fri Jun 13, 2003 7:56 am
Location:Tokyo, Japan
Contact:

Re: Patch

Post by Kaoru » Sat Dec 25, 2004 4:46 pm

hatescream wrote:maybe you could just erase the board and re-install it as new... :?:
I think it's not easy.
and even if Jens did re-install , but is not solved only with it in case of using PHP CGI etc.

User avatar
cliff
Sr. Member
Posts:3362
Joined:Fri Apr 19, 2002 10:38 pm
Location:Tampere

Re: Patch

Post by cliff » Sat Dec 25, 2004 7:06 pm

Kaoru wrote:[Some days ago , Google bot came to my forum in many times in many days.
It used about the half of my server's Bandwidth.
(Maybe by Santy???)
I denied their IP. :lol:
Good thing !
Google is the biggest spyware u could ever find around.
I still can't understand why Strato team put that stupid ad banner here.
Of course there was one "good" thing in it, but still, one thing against many bad ones...
<b>This is wrong</b>

User avatar
Kaoru
Sr. Member
Posts:469
Joined:Fri Jun 13, 2003 7:56 am
Location:Tokyo, Japan
Contact:

Re: Patch

Post by Kaoru » Sat Dec 25, 2004 7:22 pm

cliff wrote:
Kaoru wrote:[Some days ago , Google bot came to my forum in many times in many days.
It used about the half of my server's Bandwidth.
(Maybe by Santy???)
I denied their IP. :lol:
Good thing !
Google is the biggest spyware u could ever find around.
I still can't understand why Strato team put that stupid ad banner here.
Of course there was one "good" thing in it, but still, one thing against many bad ones...
I think Google is not bad for some purpose.
I usually don't deny them.
But at now , It is not usual.
They come too much!
So I denied them.

banner?
I think I looked it once , but it is not visible to me.
Is it still visible to you?

User avatar
cliff
Sr. Member
Posts:3362
Joined:Fri Apr 19, 2002 10:38 pm
Location:Tampere

Re: Patch

Post by cliff » Sat Dec 25, 2004 7:39 pm

Kaoru wrote:[banner?
I think I looked it once , but it is not visible to me.
Is it still visible to you?
not anymore.
They probably forgot to put it back with the new Php code.
or perhaps removed it in purpose, en tiedä.
<b>This is wrong</b>

Locked