City Builder Games Forums
February 07, 2012, 06:38:59 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: CityBuilderGames.com is a gaming community made up of city building game enthusiasts that love such games as SimCity 4, Cities XL 2011, Anno 1701 and Anno 1404, all of the Tropico series of games and more.

Come discuss your favorite City Building game in our message forums that we have setup for all of the games listed above and so many more.  Registration is free and only takes a couple of minutes.
 
  Home CITY JOURNALS   Forum   Help Search Login Register   *
Welcome, Guest. Please login or register.
Did you miss your activation email?
February 07, 2012, 06:38:59 PM

Login with username, password and session length
Recent Topics
[February 07, 2012, 10:21:26 AM]

[February 06, 2012, 06:44:23 AM]

[February 05, 2012, 09:40:45 PM]

[February 03, 2012, 02:20:54 PM]

[February 02, 2012, 05:38:01 PM]

[February 02, 2012, 05:27:55 PM]

[February 01, 2012, 06:32:34 PM]

[February 01, 2012, 02:16:06 PM]

[January 29, 2012, 10:34:20 PM]

[January 29, 2012, 05:53:03 AM]
Click the plus on this block if you did not receive your activation email when registering on this site
If you registered for membership on this site but have not yet received the confirmation activation email, there are 3 main reasons.

1. It ended up in your junk or spam folder, please look there to see if it's in there.

2. You did not enter your correct email address.  Please register with a new username and the correct email address and try again.

3. Your IP address and or your Email Address is listed in the Stop Forum Spam (spam protection) database as a known spammer and when either your IP address and or your email address appears in that database, your account can not be approved.  As such if you are a spammer, please move along, our community is too small for you to bother with.  If you are NOT a spammer, contact the owners of Stop Forum Spam and get your information removed from their database and register a new account.
Permissions

Members
Total Members: 3044
Latest: stephen1995
Stats
Total Posts: 28364
Total Topics: 2433
Online Today: 50
Online Ever: 273
(March 26, 2011, 05:00:14 AM)
Users Online
Users: 1
Guests: 38
Total: 40
CityBuilderGames.com! When you need a break from games of destruction, come here to discuss games of construction!

No matter the name of the game, we've got you covered here at City Builder Games.  Forums, downloads and much more are awaiting you here at the Citybuildergames.com

Pages: [1]   Go Down
  Print  
Author Topic: Exploit in forum revealed and fixed.  (Read 366 times)
0 Members and 1 Guest are viewing this topic.
City Builder
City Governor
Governor
City Mayor
*****

Reputation: +57/-770
Offline Offline

Gender: Male
Posts: 5651


-=R.I.P. Weston=-


WWW
« on: July 15, 2009, 06:36:49 AM »

After the past couple months of peoples avatars disappearing, and all that I tried to fix it, I finally had to break down and contact the developers of the forum software for help.

Apparently there was an exploit discovered in the forum software that has now been patched out so that it can't happen again.  However, about 300+ files were infected but have since been cleaned.  I have removed all files that were suggested by the cleaner that might contain exploit code, as well as (literally) over 12,000 files that were created in just a couple days in some obscure directory on our server where we would never think to look had it not been for this avatar disapearance magic act.

Let me stress that there is no danger of catching anything from this exploit of the forum software, it can and could only infect the files that run the forum software and nothing else.

However, I am still going through all the attachements to ensure that they scan clean and ask that you don't "download" any attachments to messages until I post my findings.  Clicking on screenshot thumbnails to view a larger version of the screenshot is perfectly safe.  Just do not download any message attachments that are .exe .zip .ace, or any other compression file.

As far as has been reported this exploit only attacked the files that run the forum itself and out of the hundreds of thousands of users that run this forum package, no other files have been affected, and with the exploit that was used, it couldn't do any harm to your computer if it did as all the exploit did was to write an extra header to those files that run the forum that basically injected some code that is only exploitable on the Operating system that our forums run on (which is NOT a windows based server).

I will let you know when I have scanned any archive files that are stored on our server but even after I do, I still suggest now as I have always suggested that you scan any file that you download from our site or any site on the internet.

The forum has been updated with the latest updates now and we may have lost some custom functionality in the process, but this is the price I pay to have custom mods and then have to update the forum software, all the mods have to be rewritten to make them usable again with newer forum software.  Well, some of them do anyway.

I'll keep in touch.
Logged

"Meat is Murder" - tasty tasty murder!


-= RIP Weston =-
Nov 26, 2005 - July 15, 2010
City Builder
City Governor
Governor
City Mayor
*****

Reputation: +57/-770
Offline Offline

Gender: Male
Posts: 5651


-=R.I.P. Weston=-


WWW
« Reply #1 on: July 15, 2009, 06:50:23 AM »

Ok, there was only 695 files to download and having my anti virus scanner scan them only takes about 10 seconds.  Im happy to announce all attachements that I have downloaded and scanned were clean of any malicious code.

Never the less, I still suggest scanning any file you download regardless if it comes from this website, or email, or any other website on the net.  Better safe than sorry.
Logged

"Meat is Murder" - tasty tasty murder!


-= RIP Weston =-
Nov 26, 2005 - July 15, 2010
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.13 | SMF © 2006-2011, Simple Machines LLC
TinyPortal v0.9.8 © Bloc
Valid XHTML 1.0! Valid CSS!
Page created in 0.485 seconds with 29 queries.

Google visited last this page February 06, 2012, 07:08:08 AM