Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Welcome to our Forum

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 12-14-2007
Paul's Avatar
Paul Paul is offline
Moderator
 

Join Date: Feb 2007
Location: wicklow mts
Posts: 9,495
Paul is on a distinguished road
Thanks: 0
Thanked 0 Times in 0 Posts
Welcome to our Forum
We've now restarted forum.f-secure.com. Meanwhile we've received some questions from our readers asking for more information about what happened and what we did to fix it so that others won't end up in the same situation.



The forum software we run is based on Snitz Forums 2000. While it has most basic features, the one we use has been extended into a version called Image Forums 2001. It is essentially the basic software plus modifications to support our needs such as user groups and private messages.

To cut a long story short, the group behind Snitz only maintains the basic package. On the 1st of December a security patch was announced and was withdrawn almost immediately to again be announced on the 4th of December.

We immediately implemented the patch. However, what we didn't know at the time was that a discussion was ongoing in the development forum. Not only was an improved fix recommended but there was also discussion that potential extensions to the forum might be vulnerable as well.

Turns out that's exactly what happened to us. While the main forum itself was patched it was the private messaging module that made the defacement possible. (Exploit code for this vulnerability is publically available.) We have now patched that too, and have checked through all other extensions to ensure that they are okay, and as said, the server is up and running again. No information was disclosed, the guy defaced the page and moved on not to be seen again. Typical of a Turkish defacement gang…

If you're running a discussion forum, make sure you're not only patching the main software but also any extensions you might have installed.

Come see me in the forum!
Patrik On 14/12/07 At 01:33 PM


More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Welcome to the Political Forum Opra Winfrey microsoft.public.windows.vista.general 3 06-26-2007 06:13
IE7 forum? Sheila Hoffman microsoft.public.windows.vista.general 4 06-18-2007 21:23
Forum Dominator 2.21 Netsoft Internet & Network Software Feed 0 05-04-2007 06:05
Forum Fortunes 3.0 Netsoft Internet & Network Software Feed 0 05-03-2007 00:29
Hi there, nice forum JohnP Introduce Yourself 1 02-11-2007 15:35


All times are GMT +1. The time now is 05:53.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119