vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   ibProArcade Archive (https://vborg.vbsupport.ru/forumdisplay.php?f=174)
-   -   ibProArcade v2.7.2+ coming (https://vborg.vbsupport.ru/showthread.php?t=279033)

MrZeropage 02-23-2012 07:51 AM

ibProArcade v2.7.2+ coming
 
This version fixes the security-problem and will be released within the next 24 hours, after the staff here verified it is ok :)

stangger5 02-23-2012 11:02 AM

Thanks !!!

Mark.B 02-23-2012 11:32 AM

Many thanks.

Could we also get the patch instructions so that those on older versions can patch up, like last time?

rpgamersnet 02-23-2012 12:01 PM

Can you please provide a list of changes made with 2.7.2+ for those of us with heavily-customized arcades? I would like to just fix the security holes if possible :) Thanks for the quick response to the bugs too!

MentaL 02-23-2012 12:22 PM

good stuff.

Alecsmith 02-23-2012 02:40 PM

For now i disabled ibPro arcade i have tried to uninstall but seem to be not working anyways looking forward for new release ASAP :)

garyb12001 02-23-2012 03:58 PM

Great, thanks!

Schoelle 02-23-2012 04:11 PM

Thanks for the upcoming update.
Could you please explain what the exploit was and what could have happended to our boards?
Are passwords unsecure now or could some code be on our pages?
Please let us know what we can do to be sure that we are unaffected.

Thank you!

MentaL 02-23-2012 06:34 PM

Quote:

Originally Posted by Schoelle (Post 2302710)
Thanks for the upcoming update.
Could you please explain what the exploit was and what could have happended to our boards?
Are passwords unsecure now or could some code be on our pages?
Please let us know what we can do to be sure that we are unaffected.

Thank you!

injection on arcade.php. Allowed a user to gain the MD5 and salt of any user it requested. best way to check if you are infected is to search for the following in your logs

Code:

Arcade&do=stats&comment=a&s_id=
If you find injection then follow it up.

JacquiiDesigns 02-23-2012 06:46 PM

...And just when I'd upgraded to 2.7.1 LOL
Anyway - thanks for the quick response Zero = looking forward to install the new version :)

J.

BirdOPrey5 02-23-2012 07:15 PM

Quote:

Originally Posted by MentaL (Post 2302745)
injection on arcade.php. Allowed a user to gain the MD5 and salt of any user it requested. best way to check if you are infected is to search for the following in your logs

Code:

Arcade&do=stats&comment=a&s_id=
If you find injection then follow it up.

For those not as tech minded it means a hacker could crack the password for any user on your site.

It would be a good idea to change the passwords of all admin accounts on your site if you had this mod installed.

viper357 02-23-2012 07:21 PM

Quote:

Originally Posted by MentaL (Post 2302745)
injection on arcade.php. Allowed a user to gain the MD5 and salt of any user it requested. best way to check if you are infected is to search for the following in your logs

Code:

Arcade&do=stats&comment=a&s_id=
If you find injection then follow it up.

Sorry for the noob question but which logs must we look at and where do we find them? Thanks.

MentaL 02-23-2012 07:47 PM

Quote:

Originally Posted by viper357 (Post 2302756)
Sorry for the noob question but which logs must we look at and where do we find them? Thanks.

web server logs, cpanel users can find them in /home/username/logs

Schoelle 02-23-2012 07:49 PM

Thanks MentaL.
No entries in my logs.

garyb12001 02-24-2012 04:06 PM

Any updates as to when the new version might be released? Thanks!

Mark.B 02-24-2012 10:37 PM

Once again we have no updates to a critical modification. Mr Zeropage implies that the update is with vBulletin.org staff for verification. Could we at least have an update regarding timescales? If there's an issue than fair enough, but as usual with vb these days, we are simply left in the dark.

PossumX 02-25-2012 01:02 AM

Anxiously awaiting update :) Customer of mine is having a coronary over this, more so, his members ...

Mark.B 02-25-2012 12:47 PM

It would be nice for someone to update us on what on Earth is going on here.

I am not criticising the mod author here incidentally.

A statement has been made telling us to pull the most popular modification by many multiples. This then cripples many of our sites, or puts us at risk of being hacked.

A further statement is made stating that a patch has been made and will be released within 24 hours.

Two and a half days later - no patch, no further statement, abject silence from everyone.

If there's a delay in the patch because an issue has been found, then fine - but please tell us.

Instead, it seems everyone is content to hammer further nails into the coffin of forums, many of whom are already losing members to Facebook hand over fist.

We all gave our members an update and now WE look like we're the ones ignoring THEM, because vbulletin.org is ignoring US.

I am not complaining about the lack of a patch - I am complaining about the lack of updates.

durruti 02-25-2012 02:54 PM

Quote:

Originally Posted by MentaL (Post 2302769)
web server logs, cpanel users can find them in /home/username/logs

Noob question, I can't really find what you're referring to but are you referring to Raw Access Logs?

BirdOPrey5 02-25-2012 04:06 PM

There was an SQL injection exploit identified for this mod.

After confirming it I quarantined the mod.

I have discussed the exploit with the mod author and am waiting for him to upload a fixed version.

I am keeping a close eye on this and hope to approve the update as quickly as I can once I get it.

Schoelle 02-25-2012 04:12 PM

Thanks for the update. Let's hope the author will update it.

sbelle731 02-25-2012 05:41 PM

Quote:

Originally Posted by durruti (Post 2303269)
Noob question, I can't really find what you're referring to but are you referring to Raw Access Logs?

I'm also having some problems finding this. Any help would be greatly appreciated!

Schoelle 02-25-2012 06:00 PM

Quote:

Originally Posted by sbelle731 (Post 2303337)
I'm also having some problems finding this. Any help would be greatly appreciated!

You have to search for your webserver log file. e.g. access.log
It depends on your webhost where to find this file.

In this file the webserver logs every call to a file on your server. There you need to search for the text posted by MentaL.
If you don't know where to look ask your provider!

sbelle731 02-25-2012 06:12 PM

^Found it. Thanks!

PossumX 02-25-2012 06:18 PM

Oh well, customers don't like to wait ... converted away from IBProArcade, no more waiting.

Hippy 02-25-2012 07:06 PM

Everything has been looked over and Mrzeropage will release it.
If anyone has a arcade that I have worked on ( There are lots of you guys ).. DO NOT OVER WRITE , Contact me and we will edit them manually .. or all the work that has been done will be lost!
If you know how to compare files you can do it yourself..
compare version v2.7.1+ with v2.7.2+ to find the code that needs to be added..

stangger5 02-26-2012 12:51 AM

Quote:

Originally Posted by BirdOPrey5 (Post 2303295)
waiting for him to upload a fixed version.

MrZ was waiting on you (vb staff) to verified it is ok,, before uploading a new version..

:confused:

BirdOPrey5 02-26-2012 01:21 AM

Quote:

Originally Posted by stangger5 (Post 2303436)
MrZ was waiting on you (vb staff) to verified it is ok,, before uploading a new version..

:confused:

I am waiting for him to upload a version with the fix he proposed. Once he does that I can (hopefully) approve it.

If he has a question he should respond in the quarantine thread or PM me.

Schoelle 02-26-2012 10:48 AM

So now everyone is waiting. The coder vor vB, vB for the the coder and we all for both :D

Hippy 02-26-2012 12:31 PM

all good things come to people who wait ;)

will be release as soome and MrZ has a sec ..
life comes first..
then coding

Kirkus 02-26-2012 07:36 PM

I don't mind waiting. My members understand. In fact, one of my members told me that since I disabled the Arcade her house has never been cleaner. :)

rpgamersnet 02-26-2012 10:54 PM

No problem waiting for a fix as long as it makes my site secure :) Gotta fix all those evil holes!

MentaL 02-27-2012 01:45 PM

<a href="http://www.rfxn.com/projects/linux-malware-detect/" target="_blank">http://www.rfxn.com/projects/linux-malware-detect/</a>

install this btw if you want to scan for shells. Will do setups and scans for a fee. Need root access though.

JacquiiDesigns 02-27-2012 08:00 PM

Any update on the new release?

J.

MrZeropage 02-27-2012 09:20 PM

just waiting for approval, should be ok within the next hours ...

sorry for the delay, had technical problems and was offline *damn*
now everything back on rails again

BirdOPrey5 02-27-2012 09:32 PM

Approved and restored.

MrZeropage 02-27-2012 09:56 PM

thanks :)

JacquiiDesigns 02-27-2012 11:35 PM

Sweet! I'd just finished adding a ton of games and made a new module block for my forum's newsletter:

https://vborg.vbsupport.ru/external/2012/02/12.png

And then BAMN! Arcade modification graveyarded = It was a bit frustrating to be sure.
At anyrate - thanks so much! Much appreciation for your fabulous work with this modification MrZeropage!!!
Upgrading momentarily...

J.

BirdOPrey5 02-27-2012 11:40 PM

Quote:

Originally Posted by JacquiiDesigns (Post 2304042)
Sweet! I'd just finished adding a ton of games and made a new module block for my forum's newsletter:

https://vborg.vbsupport.ru/external/2012/02/12.png

And then BAMN! Arcade modification graveyarded = It was a bit frustrating to be sure.
At anyrate - thanks so much! Much appreciation for your fabulous work with this modification MrZeropage!!!
Upgrading momentarily...

J.

No angry birds?!?!?!?

stangger5 02-28-2012 10:03 AM

Quote:

Originally Posted by BirdOPrey5 (Post 2304043)
No angry birds?!?!?!?


Hey Jacquii,,if you dont have angry birds,,I know where you can get it.. ;)


All times are GMT. The time now is 06:35 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01479 seconds
  • Memory Usage 1,817KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (3)bbcode_code_printable
  • (11)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete