Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Community Forums
 Community Discussions (All other subjects)
 F-Secure claims "silent"
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

SiSL
Average Member

Turkey
671 Posts

Posted - 29 December 2007 :  07:48:57  Show Profile  Visit SiSL's Homepage
http://www.f-secure.com/weblog/archives/00001336.html

"but the web forum software had an unannounced security patch silently released by the vendor nine days ago" it says...

CHIP Online Forum

My Mods
Select All Code | Fix a vulnerability for your private messages | Avatar Categories W/ Avatar Gallery Mod | Complaint Manager
Admin Level Revisited | Merge Forums | No More Nested Quotes Mod

MarcelG
Retired Support Moderator

Netherlands
2625 Posts

Posted - 29 December 2007 :  08:02:47  Show Profile  Visit MarcelG's Homepage
quote:
[...]Not only was an improved fix recommended but there was also discussion that potential extensions to the forum might be vulnerable as well.

Turns out that's exactly what happened to us. While the main forum itself was patched it was the private messaging module that made the defacement possible. (Exploit code for this vulnerability is publically available.) We have now patched that too, and have checked through all other extensions to ensure that they are okay, and as said, the server is up and running again.
Ehm...is this the 'normal' private messages mod ? Perhaps Image can shed some light on this, as the guys at F-Secure are using Image Forums 2001.

I'm quite keen on finding out what leak is available in the PM mod.

portfolio - linkshrinker - oxle - twitter
Go to Top of Page

Podge
Support Moderator

Ireland
3776 Posts

Posted - 29 December 2007 :  08:23:01  Show Profile  Send Podge an ICQ Message  Send Podge a Yahoo! Message
Same here.

Podge.

The Hunger Site - Click to donate free food | My Blog | Snitz 3.4.05 AutoInstall (Beta!)

My Mods: CAPTCHA Mod | GateKeeper Mod
Tutorial: Enable subscriptions on your board

Warning: The post above or below may contain nuts.
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 29 December 2007 :  08:33:46  Show Profile  Send ruirib a Yahoo! Message
Maybe f_secure needs to subscribe to the security announcements here... It was hardly silent, but they needed to be listening.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 29 December 2007 :  08:40:54  Show Profile  Send ruirib a Yahoo! Message
Regarding the PM mod, it's quite easy to find leaks... just search for all Request statements and handle it from there.

The mods issues are serious, because who is responsible for them? Who posts issues about them? We deal only with base code forums. Who tells us which mod version Image code uses? Image is so keen on bashing our code here, but just doesn't handle his own security fixes...


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page

MarcelG
Retired Support Moderator

Netherlands
2625 Posts

Posted - 29 December 2007 :  09:16:21  Show Profile  Visit MarcelG's Homepage
Mmmm, I recall that oxle was hacked some time ago, also via the PM mod....I think I triplechecked all request statements back then, but I'll start over again....just to be sure.

Just wondering : isn't there a piece of software that can perform this task ? Simply checking the sourcecode and checking for leaks...?

portfolio - linkshrinker - oxle - twitter
Go to Top of Page

ruirib
Snitz Forums Admin

Portugal
26364 Posts

Posted - 29 December 2007 :  09:19:06  Show Profile  Send ruirib a Yahoo! Message
I don't know of any code that does this, I do it manually.

Check the discussion on the Dev Team forum.


Snitz 3.4 Readme | Like the support? Support Snitz too
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.48 seconds. Powered By: Snitz Forums 2000 Version 3.4.07