Previous Thread
Next Thread
Print Thread
Rate Thread
#84177 06/10/2002 4:05 AM
Joined: Mar 2001
Posts: 326
Member
Member
Offline
Joined: Mar 2001
Posts: 326
I'm one of those who dislikes the idea of very minor updates, however I can still understand their relivance especially when there's an obvious security hole.

I've often been attacked for disliking minor updates, even by InfoPop (in a friendly way =]), yet I'm now somewhat confused as to where v6.3.0.1 has gone given that there's such a strong feeling toward having them?

Only the most familiar UBB users will be aware of the custom fix for that MASSIVE security breach in 6.3 with the search function. I've also seen new exploits on IRC now that allow people to directly access the topics thanks to being able to ID them through the search in the first place.

These days I can still surf onto most UBB v6.3 using sites and see all the private topic titles, somebody with one of the new exploits could thus hack in and view these. So why the fux hasn't the key v6.3.0.1 update come out?

This is a major security problem and not everybody mods their UBB and most won't be aware of it, so why are InfoPop being so idle as to allow this problem to continue? I'm currently going around as many v6.3 boards as I can find that aren't modded and helping them to temp-fix the search bug, but why should I be doing this?

No minor update takes a full month and so I assume v6.3.1 is now next on the list, although for those already hacked v6.3 forums it'll be too late.

Sponsored Links
Joined: May 2001
Posts: 6,708
Member
Member
Offline
Joined: May 2001
Posts: 6,708
Most of my members don't even know about the bug so I can be patient.

Joined: Mar 2001
Posts: 326
Member
Member
Offline
Joined: Mar 2001
Posts: 326
That's not the point though is it =).

#84180 06/10/2002 11:01 AM
Joined: Apr 2001
Posts: 218
Member
Member
Offline
Joined: Apr 2001
Posts: 218
Theres a MASSIVE security problem in V6.3?? I am using V6.3 and spent all weekend hacking it!
If I have to redo the whole thing again I am going to be really upset.

#84181 06/10/2002 11:10 AM
Joined: Mar 2001
Posts: 7,394
LK Offline
Admin / Code Breaker
Admin / Code Breaker
Offline
Joined: Mar 2001
Posts: 7,394
No, there is no massive bug, it just lets people see topic NAMES (not contents) from private forums and search for words in private forums.

Sponsored Links
#84182 06/10/2002 11:42 AM
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
Admin Emeritus
Joined: Jan 2000
Posts: 5,073
It has been on hold due to another, much more important security issue and another bug with major impact dealing with COPPA registrations.

We will release it when we feel all three fixes are completed properly.


UBB.classic: Love it or hate it, it was mine.
Joined: Oct 2000
Posts: 2,223
Veteran
Veteran
Offline
Joined: Oct 2000
Posts: 2,223
"We will release it when we feel all three fixes are completed properly."

Or we can do three small releases and Mark99 can express his dislike and then after that I can attack him in a friendly way. =] tipsy

Did I ever attack you in a friendly way? I mean... excepting this post of course? wink


Picture perfect penmanship here.
Joined: May 2001
Posts: 6,708
Member
Member
Offline
Joined: May 2001
Posts: 6,708
Take all the time in the world on it! Don't let these people rush you in any way. tipsy

The Private forum bug isn't that big of a deal, just don't put important titles on threads in Private forums. tipsy

Joined: Mar 2001
Posts: 326
Member
Member
Offline
Joined: Mar 2001
Posts: 326
I can't believe so many of you don't see how serious such a breach is. UBBDev visitors may be ok, we all have a more intimate knowledge of the software and use it in safer ways, yet not everybody does.

Somewhere out there are hundreds, if not thousands, running v6.3 forums that could seriously suffer from this security hole. It's no good saying not to put certain topic titles, I already know - we all do - HERE, but nobody has issued an official update to the thousands that don't visit UBBDev or InfoPop's forum.

The worst thing is that it's obvious and you'd never know if it had occurred. What if a security service using your forum is compromised because of it? Sorry if I sound pushy on this because I prefer major updates to minor ones, love my UBB and have already fixed the problem, but I'm not speaking for me, that's the whole point.

There needs to be an official update about this, that’s all I want to see, acknowledgement to the mass-public via customer E-Mail so they can at least take steps to avoid problems. PLEASE!

Joined: May 2001
Posts: 6,708
Member
Member
Offline
Joined: May 2001
Posts: 6,708
I know it may be important, and if your that desperate I think LK had made a fix for Dev before it went to 6.3.0.1 so maybe he's willing to share it?

Sponsored Links
#84187 06/18/2002 12:02 AM
Joined: Mar 2000
Posts: 21,079
Likes: 3
I type Like navaho
I type Like navaho
Joined: Mar 2000
Posts: 21,079
Likes: 3
F5!!!

F5!!!

F5!!!


- Allen wavey
- What Drives You?
#84188 06/18/2002 12:26 AM
Joined: Apr 2001
Posts: 299
Member / MultiHacker
Member / MultiHacker
Offline
Joined: Apr 2001
Posts: 299
I was just going to post that it was out. heh

Joined: May 2001
Posts: 6,708
Member
Member
Offline
Joined: May 2001
Posts: 6,708
F5 Does something. tipsy

Woo. tipsy

Joined: Dec 2001
Posts: 699
Member
Member
Offline
Joined: Dec 2001
Posts: 699
Two weeks too late... frown

Joined: Jun 2001
Posts: 2,849
Spotlight Winner
Spotlight Winner
Offline
Joined: Jun 2001
Posts: 2,849
Great upgrade, it hits alot of files but beyond compare hooked me up again.

Joined: May 2001
Posts: 794
Content Queen
Content Queen
Offline
Joined: May 2001
Posts: 794
Does anyone know off the top of his/her head how many files are altered?! eek


Sue
adwoff.com
Joined: Jun 2001
Posts: 2,849
Spotlight Winner
Spotlight Winner
Offline
Joined: Jun 2001
Posts: 2,849
Looks like 25 in the cgi-bin and a quite a few noncgi.

Joined: Mar 2001
Posts: 7,394
LK Offline
Admin / Code Breaker
Admin / Code Breaker
Offline
Joined: Mar 2001
Posts: 7,394
Sue, what I do is to check the $Id in the end of every file - if it's the same, it's not updated.

#84195 06/19/2002 12:36 PM
Joined: May 2001
Posts: 794
Content Queen
Content Queen
Offline
Joined: May 2001
Posts: 794
quote:
Originally posted by LK:
Sue, what I do is to check the $Id in the end of every file - if it's the same, it's not updated.

Thanks, XPert & LK. I'll look into this weekend ... or next! tipsy


Sue
adwoff.com
#84196 06/19/2002 12:37 PM
Joined: Jan 2000
Posts: 5,073
Admin Emeritus
Admin Emeritus
Joined: Jan 2000
Posts: 5,073
For minor releases, it is NEVER safe to go by the CVS ID alone, as I will often not check in the changes made to avoid unwanted branches - always go by the timestamp.


UBB.classic: Love it or hate it, it was mine.
Joined: May 2001
Posts: 6,708
Member
Member
Offline
Joined: May 2001
Posts: 6,708
quote:
Originally posted by XPerT:
Looks like 25 in the cgi-bin and a quite a few noncgi.

Alot more then I expected for a bug upgrade.


Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
AllenAyres
AllenAyres
Texas
Posts: 21,079
Joined: March 2000
Forum Statistics
Forums63
Topics37,573
Posts293,925
Members13,849
Most Online5,166
Sep 15th, 2019
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,833
Greg Hard 4,625
Top Posters(30 Days)
Top Likes Received
isaac 82
Gizmo 20
Brett 7
WebGuy 2
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2024 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20221218)