Go Back   vb.org Archive > Community Central > Community Lounge
  #1  
Old 05-23-2014, 02:56 PM
OldSchoolDSL OldSchoolDSL is offline
 
Join Date: Oct 2010
Posts: 1,196
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default IMPORTANT --- Security Flaw in TapaTalk

If you're site is using TapaTalk, update now! There was a security flaw found in TapaTalk and they decided NOT to inform anyone or advise anyone to update their files.

I did not find out until today, when I just happen to scroll over and found a post about it.

They even publicly admit to patching it silently, but NOT issuing a release or any notice telling people they should replace their files (because they did not even bother changing the version number either).

So I can only imagine how many sites are using the other copy without knowing they have a problem. This is completely irresponsible.

Quote:
Originally Posted by TapaTalk
Hi,

This issue has been addressed in April 26th, 9 days before this site published the issue. However, since this is a low risk item - we have simply replaced all the plugins that are affected. If this is concerning you and If you have updated the plugin after April 26th, you are not affected.
Source: https://support.tapatalk.com/threads...9/#post-131407

attached screenshot to confirm
Reply With Quote
4 благодарности(ей) от:
CAG CheechDogg, ForceHSS, RichieBoy67, tbworld
  #2  
Old 05-23-2014, 03:20 PM
blind-eddie's Avatar
blind-eddie blind-eddie is offline
 
Join Date: Apr 2006
Location: Michigan
Posts: 2,310
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Nice....
Reply With Quote
Благодарность от:
OldSchoolDSL
  #3  
Old 05-23-2014, 10:22 PM
CharlieDelta CharlieDelta is offline
 
Join Date: Apr 2010
Posts: 616
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Just another reason I am glad I do not use their plugin.
Reply With Quote
Благодарность от:
OldSchoolDSL
  #4  
Old 05-24-2014, 10:56 AM
RichieBoy67's Avatar
RichieBoy67 RichieBoy67 is offline
 
Join Date: Apr 2004
Location: CT - Down in a hole..
Posts: 3,057
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

There are updates for that plug in every couple weeks. It is very simple to update normally but it gets irritating especially when most of the updates offer no features or anything.
Reply With Quote
  #5  
Old 05-24-2014, 11:37 AM
CAG CheechDogg's Avatar
CAG CheechDogg CAG CheechDogg is offline
 
Join Date: Feb 2012
Location: Riverside, California USA
Posts: 1,080
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I use tapatalk and I haven't had any problems with it ... I actually check quite frequently to see if the file versions have changed...I did notice the version of the file change when this happened and I updated ..I didn't know why it changed but I updated right away ....

It's not just the responsibility of tapatalk to let us know when something like this happens ...they deemed it was not necessary to put out a notice about this but I noticed it so I updated ...

We have to be careful ourselves and also make sure that we monitor what plugins we use and not always rely on these 3rd parties to notify us of threats ...sometimes "we" have to do our part ....
Reply With Quote
  #6  
Old 05-24-2014, 12:02 PM
RichieBoy67's Avatar
RichieBoy67 RichieBoy67 is offline
 
Join Date: Apr 2004
Location: CT - Down in a hole..
Posts: 3,057
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by CAG CheechDogg View Post
I use tapatalk and I haven't had any problems with it ... I actually check quite frequently to see if the file versions have changed...I did notice the version of the file change when this happened and I updated ..I didn't know why it changed but I updated right away ....

It's not just the responsibility of tapatalk to let us know when something like this happens ...they deemed it was not necessary to put out a notice about this but I noticed it so I updated ...

We have to be careful ourselves and also make sure that we monitor what plugins we use and not always rely on these 3rd parties to notify us of threats ...sometimes "we" have to do our part ....
Very true. I have not had any issues with it either and have had it on sites for years. I see so many emails though from Tapatalk I often ignore them and just check the site every so often for an update.

I would love to use the paid version but I just cannot see spending another monthly fee on it right now.

One thing I have never figured out though is how to get sites listed higher up with in their search engine. One of my sites has had Tapatalk since it came out and it is still not very high up. I think maybe the premium users get listed higher.

Good warning though..I would not have updated this quickly had I not read this thread.
Reply With Quote
  #7  
Old 05-24-2014, 12:12 PM
CAG CheechDogg's Avatar
CAG CheechDogg CAG CheechDogg is offline
 
Join Date: Feb 2012
Location: Riverside, California USA
Posts: 1,080
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by RichieBoy67 View Post
Very true. I have not had any issues with it either and have had it on sites for years. I see so many emails though from Tapatalk I often ignore them and just check the site every so often for an update.

I would love to use the paid version but I just cannot see spending another monthly fee on it right now.

One thing I have never figured out though is how to get sites listed higher up with in their search engine. One of my sites has had Tapatalk since it came out and it is still not very high up. I think maybe the premium users get listed higher.

Good warning though..I would not have updated this quickly had I not read this thread.

And Richie that is also a problem, a lot of people don't actually check their emails like you just said, you ignore them and some even use emails that they don't even have active anymore and these important updates go unnoticed quite often.

I don't use the paid version and I don't see a need to either. I didn't even know there was a list within their search of the sites ! lol ...Most of the traffic now that comes to my forums is through tapatalk and I easily have over 200-300 posts per day on my forums. They just love tapatalk because they can stay updated and post where ever they go.

And yes good warning, I actually checked to see if the file version had changed and it was still the same so im good to go.....
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 06:31 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04432 seconds
  • Memory Usage 2,258KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (7)post_thanks_box
  • (6)post_thanks_box_bit
  • (7)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (3)post_thanks_postbit
  • (7)post_thanks_postbit_info
  • (7)postbit
  • (3)postbit_attachment
  • (7)postbit_onlinestatus
  • (7)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_attachment
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete