Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
2 registered (Gizmo, SteveS), 38 Guests and 14 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 06/07/07
Posts: 4
Top Posters (30 Days)
Ruben 50
DennyP 24
Gizmo 23
Dunny 15
SteveS 13
AllenAyres 12
dbremer 10
SD 10
drkknght00 9
doug 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Page 1 of 4 1 2 3 4 >
Topic Options
#245828 - 09/24/11 09:28 AM IMPORTANT UBB.THREADS SECURITY UPDATE
UBBSystems Offline
Sysop
Registered: 06/02/11
Posts: 70
The UBB.threads development team has identified a serious exploit that can allow a standard user to obtain elevated permissions on UBB.threads forums and upload malicious files.

To protect yourself from the vulnerability, patches must be immediately applied if you are running version 7.3 and later. Patches for each version are now available for download in the member’s area of UBBCentral.com:

https://www.ubbcentral.com/members/members.php

To apply the patch upload the files provided in the patch to the appropriate directories in the UBB.threads installation on your server, overwriting the existing files.

Special thanks to Sirdude, gliderdad, Ruben and Gizmo for their assistance.


Edited by UBBSystems (09/24/11 11:15 AM)
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#245829 - 09/24/11 09:41 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
driv Offline

Pooh-Bah
Registered: 01/10/04
Posts: 2377
EDIT - never mind - I downloaded the wrong folder wink


Edited by driv (09/24/11 09:43 AM)
_________________________
Using version :: 7.5.6
Top
#245830 - 09/24/11 09:42 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
UBBSystems Offline
Sysop
Registered: 06/02/11
Posts: 70
No full upgrade, just upload the files over the old ones.....
Top
#245841 - 09/24/11 11:37 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Mike L Offline
journeyman
Registered: 06/05/06
Posts: 88
Patched. grin

Thanks.
Top
#245845 - 09/24/11 12:03 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Iann128 Offline

enthusiast
Registered: 03/21/08
Posts: 234
Loc: Austin, AR
Patched our board a few min ago, Thanks!
_________________________
Ian
http://www.firstgenmc.com/ubbthreads

"Experience is a hard teacher because she gives the test first, the lesson afterwords."
Top
#245854 - 09/24/11 02:11 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
And thanks to our "identifying sites" for allowing us all to parade through their logs and test patches wink.

For those of you who had me install the patches for you, you're set, patched as issues where discovered. For those whom I provided DATA on HOW to patch, you'll need to apply the patch from the members area.
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#245863 - 09/24/11 03:02 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
ECNet Offline
journeyman
Registered: 03/13/07
Posts: 88
I downloaded 12-ubbthreads-7-5-6p1 (I have ver. 7.5.6) - Do I upload the _MACOSX Directory? (I don't have one now)

Bill
Top
#245876 - 09/24/11 03:34 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
gliderdad Offline
Registered: 06/08/06
Posts: 1466
Loc: NY
I dont see a _MACOSX Directory. There should be 4 directories: admin, languages, libs, and scripts
Top
#245879 - 09/24/11 03:37 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: ECNet]
Bjab Offline
stranger
Registered: 10/27/09
Posts: 15
Loc: Tilburg, Netherlands
Originally Posted By: ECNet
I downloaded 12-ubbthreads-7-5-6p1 (I have ver. 7.5.6) - Do I upload the _MACOSX Directory? (I don't have one now)

Bill


No, it's for MacOSX servers only wink
Top
#245880 - 09/24/11 03:39 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
UBBSystems Offline
Sysop
Registered: 06/02/11
Posts: 70
The _MACOSX can be ignored, we updated the downloads so it's not there anymore....
Top
Page 1 of 4 1 2 3 4 >



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Temporary Password email not being received
by
05/24/12 10:02 PM
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Forum Stats
10492 Members
36 Forums
33842 Topics
181709 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image