#84177
06/10/2002 4:05 AM
|
Joined: Mar 2001
Posts: 326
Member
|
Member
Joined: Mar 2001
Posts: 326 |
I'm one of those who dislikes the idea of very minor updates, however I can still understand their relivance especially when there's an obvious security hole.
I've often been attacked for disliking minor updates, even by InfoPop (in a friendly way =]), yet I'm now somewhat confused as to where v6.3.0.1 has gone given that there's such a strong feeling toward having them?
Only the most familiar UBB users will be aware of the custom fix for that MASSIVE security breach in 6.3 with the search function. I've also seen new exploits on IRC now that allow people to directly access the topics thanks to being able to ID them through the search in the first place.
These days I can still surf onto most UBB v6.3 using sites and see all the private topic titles, somebody with one of the new exploits could thus hack in and view these. So why the fux hasn't the key v6.3.0.1 update come out?
This is a major security problem and not everybody mods their UBB and most won't be aware of it, so why are InfoPop being so idle as to allow this problem to continue? I'm currently going around as many v6.3 boards as I can find that aren't modded and helping them to temp-fix the search bug, but why should I be doing this?
No minor update takes a full month and so I assume v6.3.1 is now next on the list, although for those already hacked v6.3 forums it'll be too late.
|
|
|
#84178
06/10/2002 6:07 AM
|
Joined: May 2001
Posts: 6,708
Member
|
Member
Joined: May 2001
Posts: 6,708 |
Most of my members don't even know about the bug so I can be patient.
|
|
|
#84179
06/10/2002 9:34 AM
|
Joined: Mar 2001
Posts: 326
Member
|
Member
Joined: Mar 2001
Posts: 326 |
That's not the point though is it =).
|
|
|
#84180
06/10/2002 11:01 AM
|
Joined: Apr 2001
Posts: 218
Member
|
Member
Joined: Apr 2001
Posts: 218 |
Theres a MASSIVE security problem in V6.3?? I am using V6.3 and spent all weekend hacking it! If I have to redo the whole thing again I am going to be really upset.
|
|
|
#84181
06/10/2002 11:10 AM
|
Joined: Mar 2001
Posts: 7,394
Admin / Code Breaker
|
Admin / Code Breaker
Joined: Mar 2001
Posts: 7,394 |
No, there is no massive bug, it just lets people see topic NAMES (not contents) from private forums and search for words in private forums.
|
|
|
#84182
06/10/2002 11:42 AM
|
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
|
Admin Emeritus
Joined: Jan 2000
Posts: 5,073 |
It has been on hold due to another, much more important security issue and another bug with major impact dealing with COPPA registrations.
We will release it when we feel all three fixes are completed properly.
UBB.classic: Love it or hate it, it was mine.
|
|
|
#84183
06/10/2002 9:21 PM
|
Joined: Oct 2000
Posts: 2,223
Veteran
|
Veteran
Joined: Oct 2000
Posts: 2,223 |
"We will release it when we feel all three fixes are completed properly." Or we can do three small releases and Mark99 can express his dislike and then after that I can attack him in a friendly way. =] Did I ever attack you in a friendly way? I mean... excepting this post of course? 
Picture perfect penmanship here.
|
|
|
#84184
06/11/2002 1:30 AM
|
Joined: May 2001
Posts: 6,708
Member
|
Member
Joined: May 2001
Posts: 6,708 |
Take all the time in the world on it! Don't let these people rush you in any way. The Private forum bug isn't that big of a deal, just don't put important titles on threads in Private forums. 
|
|
|
#84185
06/11/2002 5:03 AM
|
Joined: Mar 2001
Posts: 326
Member
|
Member
Joined: Mar 2001
Posts: 326 |
I can't believe so many of you don't see how serious such a breach is. UBBDev visitors may be ok, we all have a more intimate knowledge of the software and use it in safer ways, yet not everybody does.
Somewhere out there are hundreds, if not thousands, running v6.3 forums that could seriously suffer from this security hole. It's no good saying not to put certain topic titles, I already know - we all do - HERE, but nobody has issued an official update to the thousands that don't visit UBBDev or InfoPop's forum.
The worst thing is that it's obvious and you'd never know if it had occurred. What if a security service using your forum is compromised because of it? Sorry if I sound pushy on this because I prefer major updates to minor ones, love my UBB and have already fixed the problem, but I'm not speaking for me, that's the whole point.
There needs to be an official update about this, that’s all I want to see, acknowledgement to the mass-public via customer E-Mail so they can at least take steps to avoid problems. PLEASE!
|
|
|
#84186
06/11/2002 6:32 AM
|
Joined: May 2001
Posts: 6,708
Member
|
Member
Joined: May 2001
Posts: 6,708 |
I know it may be important, and if your that desperate I think LK had made a fix for Dev before it went to 6.3.0.1 so maybe he's willing to share it?
|
|
|
#84187
06/18/2002 12:02 AM
|
Joined: Mar 2000
Posts: 21,079 Likes: 3
I type Like navaho
|
I type Like navaho
Joined: Mar 2000
Posts: 21,079 Likes: 3 |
|
|
|
#84188
06/18/2002 12:26 AM
|
Joined: Apr 2001
Posts: 299
Member / MultiHacker
|
Member / MultiHacker
Joined: Apr 2001
Posts: 299 |
I was just going to post that it was out. heh
|
|
|
#84189
06/18/2002 1:48 AM
|
Joined: May 2001
Posts: 6,708
Member
|
Member
Joined: May 2001
Posts: 6,708 |
F5 Does something. Woo. 
|
|
|
#84190
06/18/2002 1:20 PM
|
Joined: Dec 2001
Posts: 699
Member
|
Member
Joined: Dec 2001
Posts: 699 |
Two weeks too late... 
|
|
|
#84191
06/18/2002 2:44 PM
|
Joined: Jun 2001
Posts: 2,849
Spotlight Winner
|
Spotlight Winner
Joined: Jun 2001
Posts: 2,849 |
Great upgrade, it hits alot of files but beyond compare hooked me up again.
|
|
|
#84192
06/18/2002 7:15 PM
|
Joined: May 2001
Posts: 794
Content Queen
|
Content Queen
Joined: May 2001
Posts: 794 |
Does anyone know off the top of his/her head how many files are altered?! 
Sue adwoff.com
|
|
|
#84193
06/18/2002 7:44 PM
|
Joined: Jun 2001
Posts: 2,849
Spotlight Winner
|
Spotlight Winner
Joined: Jun 2001
Posts: 2,849 |
Looks like 25 in the cgi-bin and a quite a few noncgi.
|
|
|
#84194
06/19/2002 8:25 AM
|
Joined: Mar 2001
Posts: 7,394
Admin / Code Breaker
|
Admin / Code Breaker
Joined: Mar 2001
Posts: 7,394 |
Sue, what I do is to check the $Id in the end of every file - if it's the same, it's not updated.
|
|
|
#84195
06/19/2002 12:36 PM
|
Joined: May 2001
Posts: 794
Content Queen
|
Content Queen
Joined: May 2001
Posts: 794 |
quote: Originally posted by LK: Sue, what I do is to check the $Id in the end of every file - if it's the same, it's not updated.
Thanks, XPert & LK. I'll look into this weekend ... or next! 
Sue adwoff.com
|
|
|
#84196
06/19/2002 12:37 PM
|
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
|
Admin Emeritus
Joined: Jan 2000
Posts: 5,073 |
For minor releases, it is NEVER safe to go by the CVS ID alone, as I will often not check in the changes made to avoid unwanted branches - always go by the timestamp.
UBB.classic: Love it or hate it, it was mine.
|
|
|
#84197
06/20/2002 1:45 AM
|
Joined: May 2001
Posts: 6,708
Member
|
Member
Joined: May 2001
Posts: 6,708 |
quote: Originally posted by XPerT: Looks like 25 in the cgi-bin and a quite a few noncgi.
Alot more then I expected for a bug upgrade.
|
|
|
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
|
|
badfrog
somewhere on the coast of Maine
Posts: 94
Joined: March 2007
|
|
Forums63
Topics37,575
Posts293,931
Members13,824
|
Most Online6,139 Sep 21st, 2024
|
|
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
|
|
|
|