Quantcast

Jump to content


Photo

Security Bug Patched


  • Please log in to reply
20 replies to this topic

#1 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 17 May 2006 - 11:25 AM

Hello everyone. :p

I just patched the board with the security update recently released at IPS. This security fix fixes some exploits that have been brought up :). Here is the official post:

This post outlines the steps required to update your IPB 2.0.x or IPB 2.1.x for this security update.
If you've downloaded IPB 2.1.6 since the time of this post, there is no need to update your installation as the main download has been updated.


It has come to our attention that Invision Power Board 2.0.x and Invision Power Board 2.1.x contains two areas where malicious code could be executed. One area requires moderator access and other other requires a carefully crafted POST or GET request. Even though we've not been successful in expoiting IPB 2.1.6 using these methods in our own trials, we felt it best to strengthen security in these areas.

This discovery is based on research from Gulftech.org, a leading security company, and as such has not had full public disclosure.

This security update has a full version number of: 21012.60516.s.
Please read our KB article on how to locate your full version number.

Enjoy :).

If you find any problems, please let me know and i will try to fix them immediately :).

#2 Freddy

Freddy
  • 5500 posts


Users Awards

Posted 17 May 2006 - 11:50 AM

Hydro is always on it. :p

I think Cata was telling me something about this how he got through and told some admin at codex or something like that. Anyways, nice work Hydrogen, keep us safe. :p

#3 X23X

X23X
  • 389 posts

Posted 17 May 2006 - 12:07 PM

Wtf is cata doing to know abou that come on bow nice find though your right hydros always on it

#4 Silk

Silk
  • 6906 posts


Users Awards

Posted 17 May 2006 - 12:10 PM

Yaaay! Nice one Hydro!

#5 travis

travis
  • 5408 posts


Users Awards

Posted 17 May 2006 - 01:32 PM

Hmph, too bad that search exploit is still there.

Edited by Travis, 17 May 2006 - 02:05 PM.


#6 Cory

Cory
  • Dinnerbone'd

  • 7487 posts


Users Awards

Posted 17 May 2006 - 01:33 PM

There where two post about it from cata. I guess I am glad to see it get fixed, even though I dont have a clue what it was about. I think I read that it had something to do with the search function. I dont know though.

Good job invision / hyrdo / cata.

#7 Guest_Xth Cannon_*

Guest_Xth Cannon_*

Posted 17 May 2006 - 01:43 PM

Nice work Hydrogen :)

#8 Krnsaber

Krnsaber
  • 3583 posts

Posted 17 May 2006 - 01:46 PM

Invisions always updating :p

#9 pyke

pyke
  • 13686 posts


Users Awards

Posted 17 May 2006 - 01:48 PM

Spiffeh. The more, the merrier xD

#10 Harley

Harley
  • 3138 posts

Posted 17 May 2006 - 01:50 PM

ooooOOooOOoOOoOOOOOO a bug. Big bird will eat it.

#11 redlion

redlion
  • I don't exist!

  • 12072 posts


Users Awards

Posted 17 May 2006 - 01:51 PM

Invisions always updating :p

Would you rather they didn't? :p

Personally I'm glad we use invision and not some shitty, super exploitable board. Yay for IPB!

#12 Harley

Harley
  • 3138 posts

Posted 17 May 2006 - 01:52 PM

Yah for IPB! Big bird gulps redlion.

#13 Mr. Hobo

Mr. Hobo
  • 8152 posts


Users Awards

Posted 17 May 2006 - 02:04 PM

Hmph, too bad that search exploit is <b>still there</b>.


Why didn't it bold your text? o.0

Good job Hydro.

#14 Harley

Harley
  • 3138 posts

Posted 17 May 2006 - 02:05 PM

Why didn't it bold your text? o.0

Good job Hydro.


Cus thats html guv'

Bbcode is the way to go!

Even big bird knew that.

#15 travis

travis
  • 5408 posts


Users Awards

Posted 17 May 2006 - 02:05 PM

I used html and not bbcode:p

#16 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 17 May 2006 - 02:07 PM

Everyone, please do not be confused. The exploit I found is still working. IPB has not seen fit to patch it yet. I am going to submit a formal bug report tomorrow since today is my birthday. Gonna drink Bicardi like it's my birthday! (Cuz it is)

#17 Harley

Harley
  • 3138 posts

Posted 17 May 2006 - 02:08 PM

Oooo my birthdays is in twop days. Happy birthday ctalistisiei!1

#18 Raui

Raui
  • 5687 posts


Users Awards

Posted 17 May 2006 - 03:12 PM

awesome going there dro ;) you seem to always be ontop of these security bugs

#19 ShadowLink64

ShadowLink64
  • 16735 posts


Users Awards

Posted 17 May 2006 - 04:53 PM

Good job Hydro; didn't even notice there was a fix available. :p

#20 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 17 May 2006 - 10:51 PM

Good job Hydro; didn't even notice there was a fix available. :p

i subscribe to their rss :p

#21 Harley

Harley
  • 3138 posts

Posted 17 May 2006 - 10:57 PM

-Big bird hits hydrogen and drags his body into the closet-


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users