|
Joined: Jun 2011
Posts: 112
Sysop
|
Sysop
Joined: Jun 2011
Posts: 112 |
The UBB.threads development team has identified a serious exploit that can allow a standard user to obtain elevated permissions on UBB.threads forums and upload malicious files. To protect yourself from the vulnerability, patches must be immediately applied if you are running version 7.3 and later. Patches for each version are now available for download in the member’s area of UBBCentral.com: https://www.ubbcentral.com/members/members.phpTo apply the patch upload the files provided in the patch to the appropriate directories in the UBB.threads installation on your server, overwriting the existing files. Special thanks to Sirdude, gliderdad, Ruben and Gizmo for their assistance.
Last edited by UBBSystems; 09/24/2011 11:15 AM.
|
|
|
|
Joined: Jan 2004
Posts: 2,474 Likes: 3
Pooh-Bah
|
Pooh-Bah
Joined: Jan 2004
Posts: 2,474 Likes: 3 |
EDIT - never mind - I downloaded the wrong folder 
Last edited by driv; 09/24/2011 9:43 AM.
|
|
|
|
Joined: Jun 2011
Posts: 112
Sysop
|
Sysop
Joined: Jun 2011
Posts: 112 |
No full upgrade, just upload the files over the old ones.....
|
|
|
|
Joined: Jun 2006
Posts: 81
member
|
member
Joined: Jun 2006
Posts: 81 |
Patched.  Thanks.
|
|
|
|
Joined: Mar 2008
Posts: 262
enthusiast
|
enthusiast
Joined: Mar 2008
Posts: 262 |
Patched our board a few min ago, Thanks!
|
|
|
|
Joined: Jun 2006
Posts: 16,378 Likes: 129
|
Joined: Jun 2006
Posts: 16,378 Likes: 129 |
And thanks to our "identifying sites" for allowing us all to parade through their logs and test patches  . For those of you who had me install the patches for you, you're set, patched as issues where discovered. For those whom I provided DATA on HOW to patch, you'll need to apply the patch from the members area.
|
|
|
|
Joined: Mar 2007
Posts: 307 Likes: 3
Enthusiast
|
Enthusiast
Joined: Mar 2007
Posts: 307 Likes: 3 |
I downloaded 12-ubbthreads-7-5-6p1 (I have ver. 7.5.6) - Do I upload the _MACOSX Directory? (I don't have one now)
Bill
|
|
|
|
Joined: Jun 2006
Posts: 1,344
veteran
|
veteran
Joined: Jun 2006
Posts: 1,344 |
I dont see a _MACOSX Directory. There should be 4 directories: admin, languages, libs, and scripts
|
|
|
|
Joined: Oct 2009
Posts: 20
stranger
|
stranger
Joined: Oct 2009
Posts: 20 |
I downloaded 12-ubbthreads-7-5-6p1 (I have ver. 7.5.6) - Do I upload the _MACOSX Directory? (I don't have one now)
Bill No, it's for MacOSX servers only 
|
|
|
|
Joined: Jun 2011
Posts: 112
Sysop
|
Sysop
Joined: Jun 2011
Posts: 112 |
The _MACOSX can be ignored, we updated the downloads so it's not there anymore....
|
|
|
|
Joined: Mar 2007
Posts: 307 Likes: 3
Enthusiast
|
Enthusiast
Joined: Mar 2007
Posts: 307 Likes: 3 |
I dont see a _MACOSX Directory. There should be 4 directories: admin, languages, libs, and scripts I count 3 .DS_Store files.. Are those needed? Nevermind, looks like a new version has just been posted without the _MACOSX directory and .DS_Store Files.  Bill
Last edited by ECNet; 09/24/2011 3:47 PM. Reason: added last part
|
|
|
|
Joined: Mar 2007
Posts: 307 Likes: 3
Enthusiast
|
Enthusiast
Joined: Mar 2007
Posts: 307 Likes: 3 |
The _MACOSX can be ignored, we updated the downloads so it's not there anymore.... Thanks, I missed seeing your post before. 
|
|
|
|
Joined: Dec 2003
Posts: 6,633 Likes: 85
|
Joined: Dec 2003
Posts: 6,633 Likes: 85 |
The _MACOSX can be ignored, we updated the downloads so it's not there anymore.... Thanks, I missed seeing your post before.  Bill, they cleaned up the patch files. So just ftp them up to your site and overwrite the script files by folder. It is just a couple.
Blue Man Group There is no such thing as stupid questions. Just stupid answers
|
|
|
|
Joined: Feb 2007
Posts: 1,294 Likes: 2
Veteran
|
Veteran
Joined: Feb 2007
Posts: 1,294 Likes: 2 |
Well, It would be nice if I still HAD access to the members area since my subscription ran out waiting for the NEW RELEASE of v8!!!
|
|
|
|
Joined: Jun 2006
Posts: 1,344
veteran
|
veteran
Joined: Jun 2006
Posts: 1,344 |
Well, It would be nice if I still HAD access to the members area since my subscription ran out waiting for the NEW RELEASE of v8!!! You should still be able to login and get the patch if your subscription ran out!
|
|
|
|
Joined: Apr 2007
Posts: 120
member
|
member
Joined: Apr 2007
Posts: 120 |
Naw, I also had to pay up, to get to the files. And am now awaiting a bit of help, as I'm part way through the upgrade. 
...usin' da classic UBB, since the beginning of time.
|
|
|
|
Joined: Feb 2007
Posts: 1,294 Likes: 2
Veteran
|
Veteran
Joined: Feb 2007
Posts: 1,294 Likes: 2 |
Never had been able to in the past. If your subscription ran out you had zero access. Now if it was so important they should just make that file available to those whom they emailed by clicking a link in the email just as they had a link for the members area.
|
|
|
|
Joined: Jan 2008
Posts: 514
addict
|
addict
Joined: Jan 2008
Posts: 514 |
|
|
|
|
Joined: Jun 2006
Posts: 106
member
|
member
Joined: Jun 2006
Posts: 106 |
Once I found it, it was smooth as silk.
(Look for the patch on the right side of the member area download page. Not the left! :face palm:)
|
|
|
|
Joined: Dec 2005
Posts: 122
member
|
member
Joined: Dec 2005
Posts: 122 |
ahem: UBB Message
We encountered a problem. The reason reported was
Database error only visible to forum administrators
Please click back to return to the previous page. my system is now dead.
|
|
|
|
Joined: Jun 2011
Posts: 112
Sysop
|
Sysop
Joined: Jun 2011
Posts: 112 |
send a support ticket in....
|
|
|
|
Joined: Dec 2005
Posts: 122
member
|
member
Joined: Dec 2005
Posts: 122 |
send a support ticket in.... i would, except (a) my membership seems to have been foreshortened by a year, and (b) i fixed it myself. mind you, i can think of better things to do with my time while sitting on the beach in Kuta, Bali.
|
|
|
|
Joined: Mar 2007
Posts: 522
Addict
|
Addict
Joined: Mar 2007
Posts: 522 |
Steve
UBB.classic from 2000-2003 UBB.threads from 2003-present!
|
|
|
|
Joined: Jun 2011
Posts: 112
Sysop
|
Sysop
Joined: Jun 2011
Posts: 112 |
After further research and review we have issued a p2 patch to further enhance security. Owners that have not patched yet can use the p2 patch directly. If you have already patched using p1, please update to p2 the same way you applied p1. To discuss upgrade and patching options, view this thread: https://www.ubbcentral.com/forums/u...to-upgrade-or-patch-that-is-the-question
|
|
|
|
Joined: Jun 2006
Posts: 106
member
|
member
Joined: Jun 2006
Posts: 106 |
|
|
|
|
Joined: Mar 2007
Posts: 522
Addict
|
Addict
Joined: Mar 2007
Posts: 522 |
Steve
UBB.classic from 2000-2003 UBB.threads from 2003-present!
|
|
|
|
Joined: Dec 2003
Posts: 6,633 Likes: 85
|
Joined: Dec 2003
Posts: 6,633 Likes: 85 |
There was a lingering security hole that SD was not comfortable with. So hence the second patch update. I am happy to say paranoia does help on occasion.
Blue Man Group There is no such thing as stupid questions. Just stupid answers
|
|
|
|
Joined: Mar 2008
Posts: 262
enthusiast
|
enthusiast
Joined: Mar 2008
Posts: 262 |
Re-Patched as well. Keep up the good work guys!
BTW is there anything we can see with this patch other than the updated version number at the bottom of the page?
Last edited by Iann128; 09/26/2011 8:11 PM.
|
|
|
|
Joined: Jun 2006
Posts: 1,344
veteran
|
veteran
Joined: Jun 2006
Posts: 1,344 |
|
|
|
|
Joined: Jan 2008
Posts: 514
addict
|
addict
Joined: Jan 2008
Posts: 514 |
I re-patched but seems that it still says... 7.5.6p1... is that accurate even with the p2 patch?
Dunny
|
|
|
|
Joined: Jun 2006
Posts: 1,344
veteran
|
veteran
Joined: Jun 2006
Posts: 1,344 |
You sure you patch it with the 7.5.6p2 and upload all the files?
Last edited by gliderdad; 09/27/2011 9:19 AM.
|
|
|
|
Joined: Jun 2006
Posts: 16,378 Likes: 129
|
Joined: Jun 2006
Posts: 16,378 Likes: 129 |
There aren't any "enhancements" to UBB.Threads 7.5.6 other than the security fixes; which won't be visible as it's all backend.
|
|
|
|
Joined: Mar 2008
Posts: 262
enthusiast
|
enthusiast
Joined: Mar 2008
Posts: 262 |
|
|
|
1 members (Gizmo),
103
guests, and
103
robots. |
Key:
Admin,
Global Mod,
Mod
|
|
|
|