PDA

View Full Version : Why did YAAS get quarentined?


GrossKopf
05-16-2010, 12:50 PM
I just got an email that Yet Another Awards System mod (https://vborg.vbsupport.ru/showthread.php?t=232684) was "quarentined". Why is that? I checked and didn't see anything in the thread about it.

vijayninel
05-16-2010, 12:58 PM
CypherSTL would be the best person to answer that. Perhaps its due to a security flaw found in the mod.

we_are_borg
05-16-2010, 01:29 PM
Well would be lovely when a websites does something like this they give a reason why now we no shit and don't know whats wrong. It can be a couple of problems and we don't now the severity of it.

Next time if vb.org does this say in the email at least what for.

GrossKopf
05-16-2010, 01:33 PM
Well would be lovely when a websites does something like this they give a reason why now we no shit and don't know whats wrong. It can be a couple of problems and we don't now the severity of it.

Next time if vb.org does this say in the email at least what for.

...or post the reason in the thread... I thought maybe the author disappeared, or there was a major problem with it, but I browsed the last couple pages and didn't see anything.

trackpads
05-16-2010, 02:18 PM
They are probably not telling because it would give a hacker a heads up on how to exploit the security issue with the hack. I am sure it will be fixed, it is a fantastic mod and the author is good.

I would like to know if it was with the recent update, I didn't apply it so I am assuming the previous version is safe.

-Jason

GrossKopf
05-16-2010, 02:28 PM
They are probably not telling because it would give a hacker a heads up on how to exploit the security issue with the hack. I am sure it will be fixed, it is a fantastic mod and the author is good.

I would like to know if it was with the recent update, I didn't apply it so I am assuming the previous version is safe.

-Jason

Even if they just said THAT, it would be fine.. I believe I'm also using an older version. I haven't been updating anything on my forums lately.

we_are_borg
05-16-2010, 07:33 PM
...or post the reason in the thread... I thought maybe the author disappeared, or there was a major problem with it, but I browsed the last couple pages and didn't see anything.

Security by obscurity is not security, if there is something wrong most properly the hackers will know this long before us.

trackpads
05-16-2010, 07:46 PM
Security by obscurity is not security

Its nice that the phrase rhymes but it is not even a maority of cases. Obscurity is a basic security principle. Everything from NAT to direct obfuscation of internal networks and more. Even basic encryption and obfuscation on your home network is recommended, while it wouldn't survive true attacks it does in fact keep most folks legal.

In this case it was probably noticed by the coder himeself or another. If a hacker had done anything to get noticed over this I am sure we would have heard about it on the site or from the affected site owner.

-Jason

Paul M
05-16-2010, 10:16 PM
A security flaw was reported, and the mod quarantined as per our procedures.

The author has now updated the code and the mod has been restored. Case Closed.

Marco van Herwaarden
05-17-2010, 08:19 AM
Our policy on vulnerabilites can be found at Mod Exploit Guidelines (https://vborg.vbsupport.ru/info.php?do=security)