Welcome Guest Search | Active Topics | Log In | Register

2 Pages 12>
YAF v1.9.1 FINAL for .NET v2.0 Framework (Dated 9/1/2007) Options · View
Jaben
#1 Posted : Tuesday, September 04, 2007 12:42:01 PM

Rank: YAF Head Dude



Joined: 10/10/2004
Posts: 2,761
Location: Honolulu, HI
YAF v1.9.1 FINAL (Dated 9/1/2007)

This version is no longer available for download.
"Honesty may be the best policy, but it’s important to remember that apparently, by elimination, dishonesty is the second-best policy." -- George Carlin

ina
#2 Posted : Wednesday, September 05, 2007 9:07:26 AM

Rank: YAF Forumling


Joined: 9/5/2007
Posts: 7
Location: Tübingen, Germany
you forgot Intelligencia.UrlRewriter.dll in the BIN distribution ...
Jaben
#3 Posted : Thursday, September 06, 2007 3:52:29 AM

Rank: YAF Head Dude



Joined: 10/10/2004
Posts: 2,761
Location: Honolulu, HI
Oops! I'll fix that immediately.
"Honesty may be the best policy, but it’s important to remember that apparently, by elimination, dishonesty is the second-best policy." -- George Carlin

Jaben
#4 Posted : Thursday, September 06, 2007 8:32:14 AM

Rank: YAF Head Dude



Joined: 10/10/2004
Posts: 2,761
Location: Honolulu, HI
Please download again as the .dll is in the distribution now.
"Honesty may be the best policy, but it’s important to remember that apparently, by elimination, dishonesty is the second-best policy." -- George Carlin

Jaben
#5 Posted : Friday, September 07, 2007 8:41:50 AM

Rank: YAF Head Dude



Joined: 10/10/2004
Posts: 2,761
Location: Honolulu, HI
Distributions have been updated with new UrlRewriter.config files to fix the issue with moderated forums.
"Honesty may be the best policy, but it’s important to remember that apparently, by elimination, dishonesty is the second-best policy." -- George Carlin

LaB
#6 Posted : Friday, September 07, 2007 1:53:01 PM

Rank: YAF Camper


Joined: 8/8/2006
Posts: 16
You might want to address the fact that netdevilz.org have hacked forum.yetanotherforum.net, and are currently spamming all members...

so much for "Stable and secure enough for a production environment" Sad
filip_cmr
#7 Posted : Friday, September 07, 2007 2:07:19 PM

Rank: YAF Lover




Joined: 2/13/2006
Posts: 44
Location: Romania
there is a meta tag : <META HTTP-EQUIV="Refresh" CONTENT="0; url=http://netdevilz.org/yet.html">. I think there is missing a check for meta tags.
Ederon
#8 Posted : Friday, September 07, 2007 2:08:09 PM

Rank: YAF Developer



Joined: 1/8/2007
Posts: 1,077
Location: Heart of Europe
Quote:
so much for "Stable and secure enough for a production environment" Sad

It's too early to judge. There are few possibilities how this happen - one is bug in YAF, another is stolen/broken identity. My guess it the second.
When I post FP:Ederon in a topic, I'm leaving my footprint there so I can track it once I get into coding/supporting.
LaB
#9 Posted : Friday, September 07, 2007 3:21:44 PM

Rank: YAF Camper


Joined: 8/8/2006
Posts: 16
Ederon wrote:
It's too early to judge. There are few possibilities how this happen - one is bug in YAF, another is stolen/broken identity. My guess it the second.


So they stole the main admin account? They must have to fit your theory, since the forums have been renamed as well...
Jaben
#10 Posted : Saturday, September 08, 2007 4:16:32 AM

Rank: YAF Head Dude



Joined: 10/10/2004
Posts: 2,761
Location: Honolulu, HI
I've evaluated the logs. They weren't really trying to be sneaky or anything. They didn't change my password or reset admin account. Still investigating.
"Honesty may be the best policy, but it’s important to remember that apparently, by elimination, dishonesty is the second-best policy." -- George Carlin

Jaben
#11 Posted : Saturday, September 08, 2007 4:58:03 AM

Rank: YAF Head Dude



Joined: 10/10/2004
Posts: 2,761
Location: Honolulu, HI
Remember folks: account passwords are hashed. I looked at their access and they only went to the admin_mail section (that's why everyone got e-mails) and modified the one forum ("lol"Wink. They didn't get e-mail addresses or usernames.

That wasn't their goal: They were just here to demonstrate that they hacked the site.

Of course, admin passwords have been changed.
"Honesty may be the best policy, but it’s important to remember that apparently, by elimination, dishonesty is the second-best policy." -- George Carlin

Exiton
#12 Posted : Sunday, September 09, 2007 2:13:45 AM
Rank: Member




Joined: 4/13/2007
Posts: 10
Location: Moldova
Can that happen with any other YAF.NET forum?
Hooter girls dig me!
Ederon
#13 Posted : Sunday, September 09, 2007 9:44:07 AM

Rank: YAF Developer



Joined: 1/8/2007
Posts: 1,077
Location: Heart of Europe
Exiton wrote:
Can that happen with any other YAF.NET forum?

Yes, as long as you leave out of box machine key setting in web.config as it is. You should always generate your own, so hackers (or any potential attackers) does not have key to your secret chambers.
When I post FP:Ederon in a topic, I'm leaving my footprint there so I can track it once I get into coding/supporting.
Jaben
#14 Posted : Tuesday, September 11, 2007 10:11:55 AM

Rank: YAF Head Dude



Joined: 10/10/2004
Posts: 2,761
Location: Honolulu, HI
Exiton wrote:
Can that happen with any other YAF.NET forum?

Please download and install v1.9.1.1. It fixes a few different security issues.
"Honesty may be the best policy, but it’s important to remember that apparently, by elimination, dishonesty is the second-best policy." -- George Carlin

Exiton
#15 Posted : Sunday, September 16, 2007 12:37:49 AM
Rank: Member




Joined: 4/13/2007
Posts: 10
Location: Moldova
Upgraded.

Thank you.
Hooter girls dig me!
Users browsing this topic
Guest
2 Pages 12>
Forum Jump  
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

YAFPro Theme Created by Jaben Cargman (Tiny Gecko)
Powered by YAF 1.9.3 RC1 | YAF © 2003-2008, Yet Another Forum.NET
This page was generated in 0.101 seconds.

SourceForge.net Logo Powered by ASP.NET v2.0 411ASP.NET