|
|||||||
| Earlier versions of OOTP: Commissioner's Corner Want to run an online league? Want to learn about the 'ins' and 'outs' of being a commish? This is the place! |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|
#61 (permalink) |
|
Hall Of Famer
Join Date: Nov 2004
Posts: 5,712
Thanked 140x in 68 posts
|
Forgot to mention that 3 sites of mine got hit. Spent 3+ hours cleaning up the mess.
__________________
Fidel Montoya Asahi2 Baseball Commissioner(Historical League Since 2004) www.allsimbaseball.com (OOTP web hosting - Customized sites for online leagues - Sign up, Connect OOTP and Play!) Share Your Mods - Free, unlimited and easy to upload to share your Mods instantly(free site registration required) |
|
|
|
|
|
#63 (permalink) | |
|
Hall Of Famer
Join Date: Nov 2004
Posts: 5,712
Thanked 140x in 68 posts
|
Quote:
Even if you use a limited FTP account, the ****** can still get into the OOTP reports. If this happens, you run the risk of allowing a trojan type virus to get into several league members' computers.
__________________
Fidel Montoya Asahi2 Baseball Commissioner(Historical League Since 2004) www.allsimbaseball.com (OOTP web hosting - Customized sites for online leagues - Sign up, Connect OOTP and Play!) Share Your Mods - Free, unlimited and easy to upload to share your Mods instantly(free site registration required) |
|
|
|
|
|
|
#65 (permalink) | |
|
Global Moderator
|
Quote:
I don't think I've ever used an ****** - is it something you can get browsers to not show as it seems quite a big security risk on any site? I think point 2 is still valid though. |
|
|
|
|
|
|
#66 (permalink) |
|
Hall Of Famer
Join Date: Nov 2004
Posts: 5,712
Thanked 140x in 68 posts
|
If you just want to make sure your index files are clean, download them to your hard drive and open them with a text editor. If you see anything in any of your index files like...
Code:
< ****** ...BLAH, Blah, BLAH.../******>
__________________
Fidel Montoya Asahi2 Baseball Commissioner(Historical League Since 2004) www.allsimbaseball.com (OOTP web hosting - Customized sites for online leagues - Sign up, Connect OOTP and Play!) Share Your Mods - Free, unlimited and easy to upload to share your Mods instantly(free site registration required) Last edited by Tony M; 12-03-2008 at 01:03 PM. Reason: put some codes round it |
|
|
|
|
|
#67 (permalink) | |
|
Global Moderator
|
Quote:
|
|
|
|
|
|
|
#68 (permalink) |
|
Hall Of Famer
Join Date: Nov 2004
Posts: 5,712
Thanked 140x in 68 posts
|
Thanks Tony.
I thought I was going to get banned for knocking off the OOTP forums with an ****** sample.
__________________
Fidel Montoya Asahi2 Baseball Commissioner(Historical League Since 2004) www.allsimbaseball.com (OOTP web hosting - Customized sites for online leagues - Sign up, Connect OOTP and Play!) Share Your Mods - Free, unlimited and easy to upload to share your Mods instantly(free site registration required) |
|
|
|
|
|
#72 (permalink) |
|
Hall Of Famer
|
Well considering I was the one who emailed you, you probably won't believe that I confirm it but I'm sure someone else will soon.
__________________
From the wise mind of Davey Eckstein[/SIZE] "Now all you need is a signature. A quote or initial, perhaps." |
|
|
|
|
|
#73 (permalink) |
|
Major Leagues
Join Date: Nov 2006
Posts: 310
|
The link that was sent to us was for the 9.2.7 patch (?). However, that patch was put up on November 17, which was before you guys figured out what the hole was. So I'm a bit dubious that the patch would solve anything.
|
|
|
|
|
|
#75 (permalink) |
|
All Star Starter
Join Date: Aug 2007
Posts: 1,904
Thanked 381x in 202 posts
|
Is there a Mac version of the patch available? The mailing I received only pointed to a PC version. Several of my owners use Macs.
__________________
Commissioner of the Planetary Extreme Baseball Alliance (PEBA) and the League of the Rising Sun (LRS) Premiere OOTP fictional leagues where creativity counts and imagination is your only limitation Check for openings - contact us today! |
|
|
|
|
|
#76 (permalink) |
|
Global Moderator
Join Date: Nov 2002
Location: Vancouver
Posts: 7,524
Thanked 303x in 166 posts
|
Is this patch going to be publicly announced? It sounds like it is only being spread privately and I don't understand why that would be. If it fixes an exploit surely it should be announced like any other patch so as many people can know about it as possible rather than just talked about here and in private.
EDIT: I was just passed the link to the aforementioned patch. I don't know why it wasn't publicly posted, but unless someone can tell me why it shouldn't be I'll be linking to it here and in the online league board's stickied thread.
__________________
Useful Links: Manuals | Downloads | Newsletters | Knowledge Base | New Tech Support | Updated Forum Rules Interactive Online League Directory - find or advertise a league today! Canadian Baseball League - uses OOTP11, running steadily since April 2002 |
|
|
|
|
|
#77 (permalink) | ||
|
Global Moderator
Join Date: Nov 2002
Location: Vancouver
Posts: 7,524
Thanked 303x in 166 posts
|
Quote:
Quote:
__________________
Useful Links: Manuals | Downloads | Newsletters | Knowledge Base | New Tech Support | Updated Forum Rules Interactive Online League Directory - find or advertise a league today! Canadian Baseball League - uses OOTP11, running steadily since April 2002 |
||
|
|
|
|
|
#78 (permalink) | |
|
Hall Of Famer
Join Date: Dec 2004
Location: Bay Area, CA
Posts: 3,984
Thanked 21x in 16 posts
|
Quote:
|
|
|
|
|
|
|
#79 (permalink) |
|
All Star Reserve
Join Date: Feb 2007
Posts: 891
Thanked 7x in 7 posts
|
I've kept my toungue privately on this all morning. I cannot for the life of me understand why a patch was made to address a security hole in OOTP without being released to the public. I'm not stupid. I'm not going to say that I know 100% for sure that my site was hacked due to an exploit of this security hole, but I'd say it's a good bet that it was. And even if it wasn't, for the OOTP developers to sit there and watch as numerous sites were hacked over the past month and not do anything to circulate this patch file is inexcusable to me, and it's causing me serious doubts as to whether I want to buy OOTP 10 when it comes out.
It's one thing to fix an issue that isn't a major security hole and wait to release it in a cummulative patch. It's quite another to fix a major security hole and not release an "emergency patch" when you know your customers are being victimized, regardless if you think the security hole is the problem or not. |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|