Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
UBBDev.com
UBBWiki.com
Who's Online
2 registered (Gizmo, SteveS), 38 Guests and 14 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 06/07/07
Posts: 4
Top Posters (30 Days)
Ruben 50
DennyP 24
Gizmo 23
Dunny 15
SteveS 13
AllenAyres 12
dbremer 10
SD 10
drkknght00 9
doug 8
Latest Photos
OK Corral Shoot Out
Testing
Basildon Train Station
Basildon Town Centre looking from the rounderbout
Basildon Town Square
Page 1 of 4 1 2 3 4 >
Topic Options
#245828 - 09/24/11 09:28 AM IMPORTANT UBB.THREADS SECURITY UPDATE
UBBSystems Offline
Sysop
Registered: 06/02/11
Posts: 70
The UBB.threads development team has identified a serious exploit that can allow a standard user to obtain elevated permissions on UBB.threads forums and upload malicious files.

To protect yourself from the vulnerability, patches must be immediately applied if you are running version 7.3 and later. Patches for each version are now available for download in the member’s area of UBBCentral.com:

https://www.ubbcentral.com/members/members.php

To apply the patch upload the files provided in the patch to the appropriate directories in the UBB.threads installation on your server, overwriting the existing files.

Special thanks to Sirdude, gliderdad, Ruben and Gizmo for their assistance.


Edited by UBBSystems (09/24/11 11:15 AM)
Top
Express Hosting
Express Hosting "We are the official hosting company of UBB.threads. Ask us about our free migration services to migrate your UBB.threads installation."
#245829 - 09/24/11 09:41 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
driv Offline

Pooh-Bah
Registered: 01/10/04
Posts: 2377
EDIT - never mind - I downloaded the wrong folder wink


Edited by driv (09/24/11 09:43 AM)
_________________________
Using version :: 7.5.6
Top
#245830 - 09/24/11 09:42 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
UBBSystems Offline
Sysop
Registered: 06/02/11
Posts: 70
No full upgrade, just upload the files over the old ones.....
Top
#245841 - 09/24/11 11:37 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Mike L Offline
journeyman
Registered: 06/05/06
Posts: 88
Patched. grin

Thanks.
Top
#245845 - 09/24/11 12:03 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Iann128 Offline

enthusiast
Registered: 03/21/08
Posts: 234
Loc: Austin, AR
Patched our board a few min ago, Thanks!
_________________________
Ian
http://www.firstgenmc.com/ubbthreads

"Experience is a hard teacher because she gives the test first, the lesson afterwords."
Top
#245854 - 09/24/11 02:11 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
And thanks to our "identifying sites" for allowing us all to parade through their logs and test patches wink.

For those of you who had me install the patches for you, you're set, patched as issues where discovered. For those whom I provided DATA on HOW to patch, you'll need to apply the patch from the members area.
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#245863 - 09/24/11 03:02 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
ECNet Offline
journeyman
Registered: 03/13/07
Posts: 88
I downloaded 12-ubbthreads-7-5-6p1 (I have ver. 7.5.6) - Do I upload the _MACOSX Directory? (I don't have one now)

Bill
Top
#245876 - 09/24/11 03:34 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
gliderdad Offline
Registered: 06/08/06
Posts: 1466
Loc: NY
I dont see a _MACOSX Directory. There should be 4 directories: admin, languages, libs, and scripts
Top
#245879 - 09/24/11 03:37 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: ECNet]
Bjab Offline
stranger
Registered: 10/27/09
Posts: 15
Loc: Tilburg, Netherlands
Originally Posted By: ECNet
I downloaded 12-ubbthreads-7-5-6p1 (I have ver. 7.5.6) - Do I upload the _MACOSX Directory? (I don't have one now)

Bill


No, it's for MacOSX servers only wink
Top
#245880 - 09/24/11 03:39 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
UBBSystems Offline
Sysop
Registered: 06/02/11
Posts: 70
The _MACOSX can be ignored, we updated the downloads so it's not there anymore....
Top
#245881 - 09/24/11 03:39 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: gliderdad]
ECNet Offline
journeyman
Registered: 03/13/07
Posts: 88
Originally Posted By: gliderdad
I dont see a _MACOSX Directory. There should be 4 directories: admin, languages, libs, and scripts
I count 3 .DS_Store files.. Are those needed?


Nevermind, looks like a new version has just been posted without the _MACOSX directory and .DS_Store Files.

smile
Bill


Edited by ECNet (09/24/11 03:47 PM)
Edit Reason: added last part
Top
#245891 - 09/24/11 04:01 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
ECNet Offline
journeyman
Registered: 03/13/07
Posts: 88
Originally Posted By: UBBSystems
The _MACOSX can be ignored, we updated the downloads so it's not there anymore....

Thanks,

I missed seeing your post before.

laugh
Top
#245892 - 09/24/11 04:16 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: ECNet]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
Originally Posted By: ECNet
Originally Posted By: UBBSystems
The _MACOSX can be ignored, we updated the downloads so it's not there anymore....

Thanks,

I missed seeing your post before.

laugh

Bill, they cleaned up the patch files. So just ftp them up to your site and overwrite the script files by folder. It is just a couple.
_________________________
Blue Man Group
Top
#245893 - 09/24/11 04:31 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
Well, It would be nice if I still HAD access to the members area since my subscription ran out waiting for the NEW RELEASE of v8!!!
Top
#245895 - 09/24/11 04:34 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: JAISP]
gliderdad Offline
Registered: 06/08/06
Posts: 1466
Loc: NY
Originally Posted By: JAISP
Well, It would be nice if I still HAD access to the members area since my subscription ran out waiting for the NEW RELEASE of v8!!!


You should still be able to login and get the patch if your subscription ran out!
Top
#245896 - 09/24/11 04:35 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Andrew Bienhaus Offline
member
Registered: 04/10/07
Posts: 135
Loc: Binbrook, Ontario, Canada
Naw, I also had to pay up, to get to the files.

And am now awaiting a bit of help, as I'm part way through the upgrade. smile
_________________________
...usin' da classic UBB, since the beginning of time.
wink
Top
#245898 - 09/24/11 04:37 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
JAISP Offline
old hand
Registered: 02/10/07
Posts: 1144
Never had been able to in the past. If your subscription ran out you had zero access. Now if it was so important they should just make that file available to those whom they emailed by clicking a link in the email just as they had a link for the members area.
Top
#245912 - 09/24/11 06:01 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Dunny Offline
addict
Registered: 01/16/08
Posts: 460
Loc: DE USA
updated here.
_________________________
Dunny

Removed link due to bleedover spammers

Dawn of Iskirra
Top
#245933 - 09/25/11 12:41 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
usrbingeek Offline
member
Registered: 06/05/06
Posts: 105
Loc: Burlington, VT
Once I found it, it was smooth as silk.

(Look for the patch on the right side of the member area download page. Not the left! :face palm:)
_________________________
All my best,
BowlingCommunity.com
Steve (@usrbingeek)

My Wishlist
Top
#245942 - 09/25/11 05:41 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
KuKuKaChu Offline
member
Registered: 12/24/05
Posts: 122
Loc: Jakarta, Indonesia
ahem:

Code:
UBB Message
We encountered a problem. The reason reported was

Database error only visible to forum administrators

Please click back to return to the previous page. 

my system is now dead.
_________________________
JakChat.com -- Forums for Indonesia's English-speaking community
Ubuntu-Indonesia.com -- Forums for Indonesia's Ubuntu Users
Top
#245943 - 09/25/11 09:57 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
UBBSystems Offline
Sysop
Registered: 06/02/11
Posts: 70
send a support ticket in....
Top
#245971 - 09/25/11 08:28 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
KuKuKaChu Offline
member
Registered: 12/24/05
Posts: 122
Loc: Jakarta, Indonesia
Originally Posted By: UBBSystems
send a support ticket in....

i would, except (a) my membership seems to have been foreshortened by a year, and (b) i fixed it myself. mind you, i can think of better things to do with my time while sitting on the beach in Kuta, Bali.
_________________________
JakChat.com -- Forums for Indonesia's English-speaking community
Ubuntu-Indonesia.com -- Forums for Indonesia's Ubuntu Users
Top
#245974 - 09/25/11 11:48 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
SteveS Online   content

addict
Registered: 03/22/07
Posts: 416
Loc: Massachusetts
Patched.
_________________________
Steve
crownvic.net
UBB.classic from 2000-2003
UBB.threads from 2003-present!
Top
#245984 - 09/26/11 02:20 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
UBBSystems Offline
Sysop
Registered: 06/02/11
Posts: 70
After further research and review we have issued a p2 patch to further enhance security. Owners that have not patched yet can use the p2 patch directly. If you have already patched using p1, please update to p2 the same way you applied p1.

To discuss upgrade and patching options, view this thread:

http://www.ubbcentral.com/forums/ubbthre...%20i#Post245968
Top
#245985 - 09/26/11 02:26 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
usrbingeek Offline
member
Registered: 06/05/06
Posts: 105
Loc: Burlington, VT
Up to date! Thanks!
_________________________
All my best,
BowlingCommunity.com
Steve (@usrbingeek)

My Wishlist
Top
#246002 - 09/26/11 06:45 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
SteveS Online   content

addict
Registered: 03/22/07
Posts: 416
Loc: Massachusetts
Re-patched!
_________________________
Steve
crownvic.net
UBB.classic from 2000-2003
UBB.threads from 2003-present!
Top
#246003 - 09/26/11 06:50 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Ruben Offline

Registered: 12/20/03
Posts: 4424
Loc: Lutz,FL
There was a lingering security hole that SD was not comfortable with.
So hence the second patch update.
I am happy to say paranoia does help on occasion.
_________________________
Blue Man Group
Top
#246004 - 09/26/11 08:10 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Iann128 Offline

enthusiast
Registered: 03/21/08
Posts: 234
Loc: Austin, AR
Re-Patched as well. Keep up the good work guys!

BTW is there anything we can see with this patch other than the updated version number at the bottom of the page?


Edited by Iann128 (09/26/11 08:11 PM)
_________________________
Ian
http://www.firstgenmc.com/ubbthreads

"Experience is a hard teacher because she gives the test first, the lesson afterwords."
Top
#246006 - 09/26/11 08:33 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
gliderdad Offline
Registered: 06/08/06
Posts: 1466
Loc: NY
What do you mean?
Top
#246007 - 09/27/11 07:43 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Dunny Offline
addict
Registered: 01/16/08
Posts: 460
Loc: DE USA
I re-patched but seems that it still says... 7.5.6p1... is that accurate even with the p2 patch?


Dunny
_________________________
Dunny

Removed link due to bleedover spammers

Dawn of Iskirra
Top
#246011 - 09/27/11 09:05 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
gliderdad Offline
Registered: 06/08/06
Posts: 1466
Loc: NY
You sure you patch it with the 7.5.6p2 and upload all the files?


Edited by gliderdad (09/27/11 09:19 AM)
Top
#246014 - 09/27/11 09:58 AM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: UBBSystems]
Gizmo Online   cat

Registered: 06/05/06
Posts: 14995
Loc: Portland, OR; USA
There aren't any "enhancements" to UBB.threads 7.5.6 other than the security fixes; which won't be visible as it's all backend.
_________________________
Forums: UGN Security & VNC Web Design & Development
UBB.Threads: UBB.Wiki, My UBBSkins, UBB.Sitemaps
Longtime UBB Supporter, UBB Beta Tester & Resident Post-A-Holic.
UBB Modifications, Styling, Coding Services, Disaster Recovery, and more!
Top
#246032 - 09/27/11 06:15 PM Re: IMPORTANT UBB.THREADS SECURITY UPDATE [Re: Gizmo]
Iann128 Offline

enthusiast
Registered: 03/21/08
Posts: 234
Loc: Austin, AR
Thanks Gizmo
_________________________
Ian
http://www.firstgenmc.com/ubbthreads

"Experience is a hard teacher because she gives the test first, the lesson afterwords."
Top
Page 1 of 4 1 2 3 4 >



Moderator:  AllenAyres, Harold, Ian, Ron M 
Shout Box

Today's Birthdays
No Birthdays
Recent Topics
Temporary Password email not being received
by
05/24/12 10:02 PM
Ability to "like" individual posts (not Facebook "likes)
by doug
05/23/12 09:03 AM
Island Permissions
by ThreadsUser
05/22/12 03:03 PM
streaming video
by prkrgrp
05/20/12 07:02 PM
New Posts Corrupted? Can someone help?
by PianoWorld
05/19/12 09:41 AM
Forum Stats
10492 Members
36 Forums
33842 Topics
181709 Posts

Max Online: 978 @ 06/24/07 11:19 PM
Random Image