Quantcast

Jump to content


Photo

IPB Security Patch Applied


  • Please log in to reply
9 replies to this topic

#1 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 20 June 2006 - 04:33 PM

I have just patched the board with the latest of the security patches that IPS has released to the public. IPS releases security updates often when they find holes in their software or when knowledge of these holes is submitted to them by their users. The board has been completely patched and the security exploit that could have been executed on our forum is now fixed. Below is the official notice, quoted, from IPS' website.

As is the case with these types of situatoins, if there is anything malfunctioning on the board or anything that you need help with, please let us know in the board help and suggestions forum.

Thanks,
Neocodex Administration

This post outlines the steps required to update your IPB 2.1.x or IPB 2.1.x for this security update.
If you've downloaded IPB 2.1.6 since the time of this post, there is no need to update your installation as the main download has been updated.


It has come to our attention that changes in how regular expressions are executed in PHP 5 versus PHP 4 leave Invision Power Board 2.1.x vulnerable via injecting HTML into a post via hexidecimal HTML entities.

This security update has a full version number of: 21012.60619.s.
Please read our KB article on how to locate your full version number.

Invision Power Board 2.1.6 Update Package (21012.60516 to 21012.60619)
If you are running a version previous to 2.1.6, please update to 2.1.6 by downloading the main download zip.
Once you've performed the update, visit your ACP and click the link under the "Security Update Available" link to reset the image check.



#2 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 20 June 2006 - 04:37 PM

Good job on updating it. If META tags were injectable, cookies stealer hell!

#3 Cory

Cory
  • Dinnerbone'd

  • 7487 posts


Users Awards

Posted 20 June 2006 - 04:42 PM

Good job on updating it. If META tags were injectable, cookies stealer hell!

WHOOT WHOOT!!!...wait it looks just like it did before....ummm good job?

#4 Freddy

Freddy
  • 5500 posts


Users Awards

Posted 20 June 2006 - 04:50 PM

Chaosgfx.com got messed up. Glad you fixed it before something like that happened. Great job Hydro. I don't share cookies well. :p

#5 sockopen

sockopen
  • 1481 posts

Posted 20 June 2006 - 07:24 PM

Thanks for your hard work Cataliste. Great job.

#6 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 20 June 2006 - 07:27 PM

Great job SockOpen. Good thing you are ontop of things!

#7 Cory

Cory
  • Dinnerbone'd

  • 7487 posts


Users Awards

Posted 20 June 2006 - 07:35 PM

Good job Marine, Great thing your a head of the game..... O wait where not talking about pimpology?

How does that thing tell you that it was the meta tags?

#8 Raui

Raui
  • 5687 posts


Users Awards

Posted 20 June 2006 - 09:47 PM

Good job Raui for posting ?

Good job you staff for patching this

#9 Martin

Martin
  • User under investigation - Potential scammer

  • 772 posts

Posted 21 June 2006 - 12:31 PM

Noo! I can no longer initiate my super secret Codex killer! :devil: JK I could never destroy Codex :hug: Good job staff for addng the security patch! :D

Edited by Martin, 21 June 2006 - 12:31 PM.


#10 Warlord

Warlord
  • 3988 posts

Posted 21 June 2006 - 01:43 PM

HANDS OFF MY CHIPS-AHOY! :p

good job hydro :thumbsup:


1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users