vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   ibProArcade Archive (https://vborg.vbsupport.ru/forumdisplay.php?f=174)
-   -   ibProArcade v2.7.2+ coming (https://vborg.vbsupport.ru/showthread.php?t=279033)

MrZeropage 02-23-2012 07:51 AM

ibProArcade v2.7.2+ coming
 
This version fixes the security-problem and will be released within the next 24 hours, after the staff here verified it is ok :)

stangger5 02-23-2012 11:02 AM

Thanks !!!

Mark.B 02-23-2012 11:32 AM

Many thanks.

Could we also get the patch instructions so that those on older versions can patch up, like last time?

rpgamersnet 02-23-2012 12:01 PM

Can you please provide a list of changes made with 2.7.2+ for those of us with heavily-customized arcades? I would like to just fix the security holes if possible :) Thanks for the quick response to the bugs too!

MentaL 02-23-2012 12:22 PM

good stuff.

Alecsmith 02-23-2012 02:40 PM

For now i disabled ibPro arcade i have tried to uninstall but seem to be not working anyways looking forward for new release ASAP :)

garyb12001 02-23-2012 03:58 PM

Great, thanks!

Schoelle 02-23-2012 04:11 PM

Thanks for the upcoming update.
Could you please explain what the exploit was and what could have happended to our boards?
Are passwords unsecure now or could some code be on our pages?
Please let us know what we can do to be sure that we are unaffected.

Thank you!

MentaL 02-23-2012 06:34 PM

Quote:

Originally Posted by Schoelle (Post 2302710)
Thanks for the upcoming update.
Could you please explain what the exploit was and what could have happended to our boards?
Are passwords unsecure now or could some code be on our pages?
Please let us know what we can do to be sure that we are unaffected.

Thank you!

injection on arcade.php. Allowed a user to gain the MD5 and salt of any user it requested. best way to check if you are infected is to search for the following in your logs

Code:

Arcade&do=stats&comment=a&s_id=
If you find injection then follow it up.

JacquiiDesigns 02-23-2012 06:46 PM

...And just when I'd upgraded to 2.7.1 LOL
Anyway - thanks for the quick response Zero = looking forward to install the new version :)

J.


All times are GMT. The time now is 10:03 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01093 seconds
  • Memory Usage 1,728KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_code_printable
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete