NSFCD

Generally Speaking => Power On => Topic started by: JMV on May 08, 2009, 08:50:15 PM

Title: what
Post by: JMV on May 08, 2009, 08:50:15 PM
What happened >=(
Title: Re: what
Post by: Super on May 08, 2009, 08:51:19 PM
We installed SMF 2.0 RC1.
Title: Re: what
Post by: on May 08, 2009, 08:52:23 PM
There was a death.
Title: Re: what
Post by: JMV on May 08, 2009, 08:52:41 PM
Quote from: Super on May 08, 2009, 08:51:19 PM
We installed SMF 2.0 RC1.
I know that.

Customrobo left Silver a facebook message and I thought something happened :robotangry:
Title: Re: what
Post by: Super on May 08, 2009, 08:55:01 PM
Supposedly, a bot came in and messed with all of the PHP files.

So many things were intercourse ed up that we had to reinstall the forums and other things.

But we're back in black.
Title: Re: what
Post by: Kierou on May 08, 2009, 08:57:30 PM
And it wasn't even Silver's fault!
Title: Re: what
Post by: SkyMyl on May 08, 2009, 08:58:22 PM
Quote from: Kierou on May 08, 2009, 08:57:30 PM
And it wasn't even Silver's fault!
That's still being speculated.
Title: Re: what
Post by: JMV on May 08, 2009, 09:02:40 PM
Quote from: Super on May 08, 2009, 08:55:01 PM
Supposedly, a bot came in and messed with all of the PHP files.

So many things were intercourse ed up that we had to reinstall the forums and other things.

But we're back in black.
Bots just don't "mess" with PHP files.

I'm guessing some idiot ignored my thread a few weeks ago about not upgrading to 1.1.8.
http://www.nsfcd.com/forums/index.php?topic=31064.msg460862

Oh look, what is this?
Quote from: JMV on April 02, 2009, 05:23:50 AM
It fixes a XSS vulnerability if I recall correctly.

What did Vaatix say the problem was?


Quote from: VaatixGanon on May 02, 2009, 03:46:37 AM
Somehow, and I don't know how, a vulnerability was exploited in SMF that allowed an off-site script to be run which injected malicious code in to most files on our account. As a result of not being able to pinpoint the exact location of the vulnerability, I was forced to make a decision - Leave the forum half working with a possible vulnerability, or overwrite the files with a replacement set...


hurp durp ignore JMV he doesn't know what he's talking about.
Title: Re: what
Post by: L10 on May 08, 2009, 10:27:34 PM
The arcade is missing!

>:(
Title: Re: what
Post by: Friendly Hostile on May 08, 2009, 10:31:04 PM
See the announcment board.  And IIRC, we did upgrade to 1.1.8 and still got intercourse ed.
Title: Re: what
Post by: Macawmoses on May 08, 2009, 11:06:48 PM
Yes, we were on 1.1.8 at the time of the malicious code "infection". So JMV didn't prove anything.