Fortress Forever

Go Back   Fortress Forever > Off Topic > Tech

Reply
 
Thread Tools Display Modes
Old 08-01-2008, 11:53 PM   #1
~kev~
pmagnvs
 
~kev~'s Avatar
 
Join Date: Mar 2007
Location: East Texas
Class/Position: Engineer - D
Gametype: Free for all CTF - no stupid clan rules
Posts Rated Helpful 0 Times
Update your Simple machines forum (SMF)

If anyone here is running any version of SMF less then 1.1.5, you might want to update.

A hacker has found a mysql injection flaw. To use the exploit, the hacker registers an account, then uses the injection flaw to promote their selves to administrator.

He/she is making the rounds hacking smf with all versions < 1.1.4. The ONLY fix is to update to smf 1.1.5.

Related thread - http://www.simplemachines.org/commun...topic=252536.0

Before someone post "fortress-forever is using VBulletin" - I already know this. I run 2 vbulletin forums and one smf forum.

I also know that some of the members here have their own forums and some are using SMF. So check your version number and get updated. Download the latest version of smf here - http://download.simplemachines.org/
~kev~ is offline   Reply With Quote


Old 08-02-2008, 01:08 AM   #2
Ihmhi
[AE] 0112 Ihmhi *SJB
Wiki Team
Fortress Forever Staff
 
Ihmhi's Avatar
 
Join Date: Mar 2007
Location: Newark, NJ, United States
Class/Position: A little bit o' everythin'
Gametype: Also a little bit o' everythin'
Affiliations: [AE] Asseater, *SJB Straight Jacket Brigade
Posts Rated Helpful 3 Times
Send a message via AIM to Ihmhi Send a message via MSN to Ihmhi Send a message via Yahoo to Ihmhi
Thanks ~kev~, I appreciate this warning and I'm going to sticky it for now as it's pretty damned important. Admin on your boards means they can be nuked, not to mention all the data like user info and e-mails.
__________________
Support FF:
Anime: The Thread: Reloaded
The one and only anime thread on these here forums.

Select the pistol, and then, select your horse.
Ihmhi is offline   Reply With Quote


Old 11-07-2008, 03:14 AM   #3
~kev~
pmagnvs
 
~kev~'s Avatar
 
Join Date: Mar 2007
Location: East Texas
Class/Position: Engineer - D
Gametype: Free for all CTF - no stupid clan rules
Posts Rated Helpful 0 Times
A security flaw has been found in the most recent version of the SMF software, version 1.1.6. As of this time, a patch has not been released. The SMF developers are aware of the issue and are working on a solution.


Thread on the exploit - http://www.simplemachines.org/commun...topic=272393.0


There is a quick fix, but its not a permanent fix -

http://www.simplemachines.org/commun...614#msg1783614

If you are running an SMF forum, get your site backed up - just in case.
~kev~ is offline   Reply With Quote


Old 11-10-2008, 02:36 AM   #4
~kev~
pmagnvs
 
~kev~'s Avatar
 
Join Date: Mar 2007
Location: East Texas
Class/Position: Engineer - D
Gametype: Free for all CTF - no stupid clan rules
Posts Rated Helpful 0 Times
The simple machines developers have released an update that addresses the security flaw. Get your forums updated to version 1.1.7.

Link to the SMF website with more details - http://www.simplemachines.org/commun...topic=272861.0
~kev~ is offline   Reply With Quote


Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 03:06 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.