Quantcast

Jump to content


Photo

Security update applied


  • Please log in to reply
15 replies to this topic

#1 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 30 June 2006 - 07:51 PM

I have applied the latest IPS security update. We are now secure from this exploit. Here is a description of the security update and what exactly was changed:

Security Update


This post outlines the steps required to update your IPB 2.1.x for this security update.
If you've downloaded IPB 2.1.6 since the time of this post, there is no need to update your installation as the main download has been updated.


It has come to our attention that due to a flaw in the way Internet Explorer handles urlencoded data in URLs, it's possible to craft a malicious URL when adding an avatar to cause an XSS (cross site scripting) vulnerability where, at worst, cookie data can be taken. Additionally, an unrelated flaw may allow moderators to moderate forums that they do not have permission to moderate.

Solution
To prevent further attacks of this kind, we've increased security by checking any URL that is likely to be inserted in an <img> tag.

This security update has a full version number of: 21012.60629.s.
Please read our KB article on how to locate your full version number.

Enjoy :p.

#2 ShadowLink64

ShadowLink64
  • 16735 posts


Users Awards

Posted 30 June 2006 - 08:10 PM

Nice job Hydro, didn't even notice that IPS released another patch. :p

#3 Raui

Raui
  • 5687 posts


Users Awards

Posted 30 June 2006 - 08:55 PM

Well done Staff. Wooo !

#4 Ender

Ender
  • 4323 posts

Posted 30 June 2006 - 08:56 PM

Wow, do they have an update notification thing or something?

#5 Hydrogen

Hydrogen
  • Neocodex Co-Founder

  • 22213 posts


Users Awards

Posted 30 June 2006 - 08:57 PM

Wow, do they have an update notification thing or something?

They do in acp, but i also subscribe to their rss feed :p

#6 sockopen

sockopen
  • 1481 posts

Posted 30 June 2006 - 09:18 PM

Thanks for installing the security update Cataliste, your hard work is always appreciated.

#7 Warlord

Warlord
  • 3988 posts

Posted 30 June 2006 - 10:34 PM

More behind the scenes work.... good job guys :thumbsup:

#8 Eeyore

Eeyore
  • <img src ='http://i34.tinypic.com/2mecsg1.jpg'>

  • 7908 posts


Users Awards

Posted 30 June 2006 - 10:44 PM

Whoot!! Good to know things are all secure ^_^. Well done staff and anyone else that might have helped *covers all stops*.

#9 dolphinbomb

dolphinbomb
  • YAAAAAAYYYYY

  • 3758 posts

Posted 30 June 2006 - 10:53 PM

Thanks for installing the security update Cataliste, your hard work is always appreciated.

You pretty much said the same thing last time, too :p

#10 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 01 July 2006 - 06:04 AM

Way to be ontop of it Sockopen. Considering you found this flaw months ago, and ShadowLink patched it months ago.

Way to be on the ball Sock. :thumbsup:

#11 Ender

Ender
  • 4323 posts

Posted 01 July 2006 - 08:06 AM

O_o Um... am I missing something?

#12 Martin

Martin
  • User under investigation - Potential scammer

  • 772 posts

Posted 01 July 2006 - 06:38 PM

Good job staff! ~pats on on back~ :) Codex is now better protected!

#13 Cory

Cory
  • Dinnerbone'd

  • 7487 posts


Users Awards

Posted 01 July 2006 - 07:58 PM

O_o Um... am I missing something?


QFE!!!


I said that a few weeks back.

#14 Cataliste

Cataliste
  • Codex's Right Hand

  • 4662 posts


Users Awards

Posted 01 July 2006 - 08:15 PM

What are you misisng? Sockopen pointed this thing out months ago and SL supposedly patche dit....

#15 sockopen

sockopen
  • 1481 posts

Posted 02 July 2006 - 03:20 PM

Oh yea, I thought I reported this exact problem to ShadowLink like months ago.

#16 ShadowLink64

ShadowLink64
  • 16735 posts


Users Awards

Posted 02 July 2006 - 03:23 PM

Oh yea, I thought I reported this exact problem to ShadowLink like months ago.

Meh, I couldn't figure out how to restrict dynamic images but keep normal ones. :( Extensions wouldn't work or something.


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users