Welcome to the E-Blah Community!
We would like to welcome you to our community and invite you to register an account or login.
Being a registered member is important, as it gives you several advantages over the normal Guest status. After registering you will be able to download files and images, post messages, and access member-only portions of the forum - just to name a few. Registration is quick and simple, and only takes about a minute of your time.

E-Blah Community    Informational    News  ›  Major Security Flaw Found
Users Browsing Forum
Alexa and 7 Guests

Major Security Flaw Found  This thread currently has 2,436 views. Print
1 Pages 1 Recommend Thread
Justin
December 24, 2005, 3:57pm Report to Moderator Report to Moderator

The E-Blah Developer
E-Blah Programmer
Posts: 15,015
Gender: Male
Posts Per Day: 6.75
Reputation: 93.40%
Reputation Score: +297 / -21
Time Online: 36 days 17 hours 45 minutes
Location: Tallassee, AL
Age: 21
This effects every version of E-Blah.  This fix should fix all newer versions of E-Blah.  By not patching, you open your forum up to a security flaw that can occur by HTML tags being allowed in certain sections of the member center (ie: ICQ).  This will fix that.

Apply this patch by installing it into your Modification Center.  Then install.  You can also download the attached modification file and upload it to your Mods directory.  Platinum 9.6 will be patched and reuploaded shortly.  If anyone has any questions, let me know.  Thanks goes to this user for bringing this to my attention earlier today.

Sorry about the problem.  Have a very Merry Christmas!



This post contains attachments; to download them you must login.



I do installs for $25 and upgrades for $20.
Technical support is always free.

  Donate to E-Blah!  

My Websites: Revolution Reality (My Blog)  |  MinistryTalk.com  |  Portfolio

"But you, O Lord, are a compassionate and gracious God, slow to anger, abounding in love and faithfulness." — Psalm 86:15 NIV


Revision History (2 edits)
admin  -  December 30, 2005, 11:19pm
admin  -  December 30, 2005, 11:19pm
Logged Offline
Site Site Private Message Private message
Scottie_Too_Hottie7
December 24, 2005, 4:03pm Report to Moderator Report to Moderator

E-Blah Member
Posts: 216
Gender: Male
Posts Per Day: 0.13
Reputation: 76.92%
Reputation Score: +10 / -3
Time Online: 1 days 10 hours 23 minutes
Age: 17
well ive uploaded the mod - to be honest i never found any problem but hey, what justin says goes!  





Please Increase My Reputation
Remember


NOTE : You may notice me not being on these forums for long times on end.
Logged Offline
Private Message Private message YIM YIM Windows Live Messenger WLM Reply: 1 - 5
Justin
December 24, 2005, 4:08pm Report to Moderator Report to Moderator

The E-Blah Developer
E-Blah Programmer
Posts: 15,015
Gender: Male
Posts Per Day: 6.75
Reputation: 93.40%
Reputation Score: +297 / -21
Time Online: 36 days 17 hours 45 minutes
Location: Tallassee, AL
Age: 21
There's not much of a problem ... unless you have someone come to your forum wanting to cause trouble.

They could easily put in </table> in the ICQ space, for instance, and then you'd have a badly messed up page.  


I do installs for $25 and upgrades for $20.
Technical support is always free.

  Donate to E-Blah!  

My Websites: Revolution Reality (My Blog)  |  MinistryTalk.com  |  Portfolio

"But you, O Lord, are a compassionate and gracious God, slow to anger, abounding in love and faithfulness." — Psalm 86:15 NIV

Logged Offline
Site Site Private Message Private message Reply: 2 - 5
Ol
December 26, 2005, 1:39am Report to Moderator Report to Moderator
E-Blah Member
Posts: 5
Posts Per Day: 0.01
Reputation: 100.00%
Time Online: 3 hours 12 minutes
The problem is only half-fixed.
Please note, that fix Justin released only prevent insering HTML code, but have nothing to do with already inserted.

To feel safe, check all your user accounts agains wrong data.
Logged Offline
Private Message Private message Reply: 3 - 5
Severe
December 27, 2005, 12:19pm Report to Moderator Report to Moderator
E-Blah Member
Posts: 18
Posts Per Day: 0.01
Time Online: 11 hours 50 minutes
Did P9.6 get patched and re-upped?  I was going to upgrade and noticed the date stamp on P9.6 pre-dated the bug fix.

Thanks
Logged Offline
Private Message Private message Reply: 4 - 5
Justin
December 27, 2005, 12:23pm Report to Moderator Report to Moderator

The E-Blah Developer
E-Blah Programmer
Posts: 15,015
Gender: Male
Posts Per Day: 6.75
Reputation: 93.40%
Reputation Score: +297 / -21
Time Online: 36 days 17 hours 45 minutes
Location: Tallassee, AL
Age: 21
ProfileEdit.pl was dated 12/24/05.  You may have to clear your cache (if you downloaded the old version).


I do installs for $25 and upgrades for $20.
Technical support is always free.

  Donate to E-Blah!  

My Websites: Revolution Reality (My Blog)  |  MinistryTalk.com  |  Portfolio

"But you, O Lord, are a compassionate and gracious God, slow to anger, abounding in love and faithfulness." — Psalm 86:15 NIV

Logged Offline
Site Site Private Message Private message Reply: 5 - 5
1 Pages 1 Recommend Thread
Print

E-Blah Community    Informational    News  ›  Major Security Flaw Found