Sound Solution Dsp Audio Broadcast Processor code by Alessandro Tomassini
July 30, 2010, 06:53:08 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Foro en Espaņol
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: [NOTICE] Recent attacks SMF Forum  (Read 4336 times)
cornacchia
Administrator
Newbie
*****
Posts: 21


Email
« on: May 12, 2009, 06:38:09 PM »

Considering the recent mass attack on SMF forums over the past week, temporarily  attachment and  avatar uploads are locked,  until a patch is available.

I´m sorry for the inconvenience.
Logged
Sound Solution Dsp Audio Broadcast Processor code by Alessandro Tomassini
« on: May 12, 2009, 06:38:09 PM »

 Logged
jesseg
Total Audio Freq
Global Moderator
Sr. Member
*****
Posts: 309



« Reply #1 on: May 12, 2009, 06:40:42 PM »

Wow, where have I been?  Embarrassed

[edit]
http://www.simplemachines.org/community/index.php?topic=309717.0
ahh, good to know
[/edit]

[edit2]
-a- this is much too alarmist and generalized without linking to any information about the attacks.
-b- the recent attacks he's talking about only effect older versions of SMF v2.0 not v1.1.8... and only with certain combinations of older versions of Apache, PHP, and MySQL...  In most of the attacks, SMF was not the hole, just a victim of the payload. Wink

so even though attachments don't get used much around these parts, they don't have to be disabled. nor do avatars. there are currently zero known exploits for v1.1.8.

but his suggestion to have "Stop Spammer" mod is a good one.  I'm running it on several forums I admin and it's great.  reCaptcha isn't really needed if you set the already built in SMF captcha to it's highest strength.  I've only had maybe 3-4 spam-bots get by it, and they have all been caught by Stop Spammer. Smiley
[/edit2]

[edit3]
this looks really good Smiley
http://www.hardened-php.net/suhosin/
[/edit3]

[edit4]
ah, it appears that doesn't always help, and yes v1.1.8 was exploited, but through other holes.  i wonder if this is a botnet thing.  i don't see how one guy could be so dang busy. Wink
[/edit4]
« Last Edit: May 12, 2009, 07:55:05 PM by jesseg » Logged
cornacchia
Administrator
Newbie
*****
Posts: 21


Email
« Reply #2 on: May 12, 2009, 07:22:42 PM »

http://www.simplemachines.org/community/index.php?topic=309741.msg2054202#msg2054202



[edit2]
-a- this is much too alarmist and generalized without linking to any information about the attacks.
-b- the recent attacks he's talking about only effect older versions of SMF v2.0 not v1.1.8... and only with certain combinations of older versions of Apache, PHP, and MySQL...  In most of the attacks, SMF was not the hole, just a victim of the payload. Wink

....


Ok, jesseg
this "solution" is temporarily  just have time to monitor and analyze the server logs e search detailed information about  the attacks.
Logged
jesseg
Total Audio Freq
Global Moderator
Sr. Member
*****
Posts: 309



« Reply #3 on: May 12, 2009, 07:55:38 PM »

the problem could be solved by forcing avatars to resize and to use PNG.  that will use a PHP extension which will reject all non-images posing as images.  i'm notifying the SMF community about this because it's already built into SMF.

But I agree, it's best to just disable entirely for now since attachments are not used much here.
Logged
jesseg
Total Audio Freq
Global Moderator
Sr. Member
*****
Posts: 309



« Reply #4 on: May 21, 2009, 10:10:04 PM »

cornacchia, 1.1.9 is out...  you can do the hotpatch directly from the admin panel.
Logged
jesseg
Total Audio Freq
Global Moderator
Sr. Member
*****
Posts: 309



« Reply #5 on: May 30, 2009, 09:42:50 PM »

B-B-B-B-B-BUMP
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.8 | SMF © 2006-2008, Simple Machines LLC Valid XHTML 1.0! Valid CSS!