Latest News: OOTP 13 Announced with Screenshots & Feature List! Pre-Order Now! - OOTP Baseball 12 Available! - iOOTP Baseball 2011 Available! - Title Bout Championship Boxing 2.5 released! - Inside the Park Baseball Patch 1.03 released, DEMO now available

Pre-Order OOTP 13, Save & Win! | OOTP 12 Off-Season Special, just $19.99!

Go Back   OOTP Developments Forums > Earlier versions of Out of the Park Baseball > Earlier versions of OOTP: Online Leagues > Earlier versions of OOTP: Commissioner's Corner

Earlier versions of OOTP: Commissioner's Corner Want to run an online league? Want to learn about the 'ins' and 'outs' of being a commish? This is the place!

Reply
 
LinkBack Thread Tools Display Modes
Old 12-03-2008, 08:34 PM   #81 (permalink)
All Star Reserve
 
Join Date: Feb 2007
Posts: 891
Thanked 7x in 7 posts
The link to the patch is a few posts above yours in one of KQ76's posts. I'd say the cat is out of the bag now....
gollum65 is offline   Reply With Quote
Old 12-03-2008, 08:50 PM   #82 (permalink)
Hall Of Famer
 
Cooleyvol's Avatar
 
Join Date: Dec 2001
Location: Woodland Mills, TN
Posts: 5,796
Thanked 456x in 272 posts
Understood, but are we to just happen across the link?
__________________

Cooleyvol is offline   Reply With Quote
Old 12-03-2008, 08:55 PM   #83 (permalink)
All Star Reserve
 
Join Date: Feb 2007
Posts: 891
Thanked 7x in 7 posts
If you're asking if it's going to be "officially published as a patch file", I can't answer that, and I've mentioned before that I also don't understand why it's not been. Only the OOTP Dev Team can answer that.

And btw, we need a Mac version. I have GMs in my league who are Mac users.
gollum65 is offline   Reply With Quote
Old 12-03-2008, 09:23 PM   #84 (permalink)
Minors (Double A)
 
BoofBonser26's Avatar
 
Join Date: Dec 2007
Location: Chicago
Posts: 158
Has anyone successfully exported a file using the new version? I'm getting errors and can't tell if the problem is me or the patch.
__________________
owner, West Virginia Alleghenies (PEBA)

2007: 82-80, 4th place (Dixie Division)
2008: 90-72, 2nd place (Dixie Division)
2009: 76-86, 4th place (Dixie Division)
2010: 76-86, 5th place (Dixie Division)
2011: 97-65, 3rd place (Dixie Division) -
IL Wildcard #2
2012: 77-85, 4th place (Dixie Division)
2013: 79-83, 3rd place (Dixie Division)

2014: 76-66, 3rd place (Dixie Division)

we define mediocrity

BoofBonser26 is offline   Reply With Quote
Old 12-03-2008, 09:56 PM   #85 (permalink)
All Star Starter
 
Corsairs's Avatar
 
Join Date: Aug 2007
Posts: 1,904
Thanked 381x in 202 posts
Quote:
Originally Posted by BoofBonser26 View Post
Has anyone successfully exported a file using the new version? I'm getting errors and can't tell if the problem is me or the patch.
For the record, Boof's trouble exporting isn't related to the patch. We just changed our FTP password. Didn't want anyone upgrading to be afraid that the new version caused export issues.
__________________
Commissioner of the Planetary Extreme Baseball Alliance (PEBA) and the League of the Rising Sun (LRS)
Premiere OOTP fictional leagues where creativity counts and imagination is your only limitation
Check for openings - contact us today!
Corsairs is offline   Reply With Quote
Old 12-03-2008, 11:18 PM   #86 (permalink)
All Star Starter
 
Corsairs's Avatar
 
Join Date: Aug 2007
Posts: 1,904
Thanked 381x in 202 posts
One thing I'm uncertain of: Are we still concerned about a potential security hole in Getch's online utilities? This news of a security hole in OOTP would seem to vindicate the utilities, but f.montoya indicated to me in an email tonight that there may still be a separate vulnerability there.

Might we get an official word on this from Getch himself? We've removed the utilities from our server until we're sure they're safe, but we're itching to restore them.
__________________
Commissioner of the Planetary Extreme Baseball Alliance (PEBA) and the League of the Rising Sun (LRS)
Premiere OOTP fictional leagues where creativity counts and imagination is your only limitation
Check for openings - contact us today!
Corsairs is offline   Reply With Quote
Old 12-03-2008, 11:29 PM   #87 (permalink)
All Star Reserve
 
Join Date: Feb 2007
Posts: 891
Thanked 7x in 7 posts
As I posted earlier, I cannot say with 100% certainty how the hacker gained access. Sure, it's possible he got in through Getch's utilities. All that could be gleaned from the logs was the files that he altered and when he altered them.

Now, my personal opinion, given the facts that have come to light today, is that Getch's utilities are most likely safe, but that's just my opinion. I've never taken them offline in my league and unless it can be proven that they were a direct portal for an attack, I won't remove them.

All that said, Getch did post that he found a problem and was going to fix it.
gollum65 is offline   Reply With Quote
Old 12-04-2008, 01:20 AM   #88 (permalink)
DWK
All Star Reserve
 
DWK's Avatar
 
Join Date: Mar 2007
Location: Bluffton, South Carolina
Posts: 571
Thanked 12x in 11 posts
Quote:
Originally Posted by Cooleyvol View Post
So, can all commishes get this patch or is there a select few that are worthy of being protected against this?
Yeah I would Like to know this too
__________________
Hardball Chronicles - Milwaukee Braves
Major League Historical Baseball - Boston Red Sox
Diamond King Baseball - New York Yankees
Sabermetric Baseball - Detroit Tigers

DWK is offline   Reply With Quote
Old 12-04-2008, 01:49 AM   #89 (permalink)
Hall Of Famer
 
molarmite's Avatar
 
Join Date: Jul 2005
Location: Minnesota
Posts: 4,745
Blog Entries: 1
Thanked 75x in 48 posts
Markus said if you contact him, he will give it to you. So I assume it's for everyone. It's posted on the previous page if you want a link to it.
__________________
From the wise mind of Davey Eckstein[/SIZE]

"Now all you need is a signature. A quote or initial, perhaps."


molarmite is offline   Reply With Quote
Old 12-04-2008, 02:10 AM   #90 (permalink)
Hall Of Famer
 
satchel's Avatar
 
Join Date: Apr 2002
Location: Ft Smith AR
Posts: 2,680
Thanked 48x in 26 posts
My impulse is to start using the v9.2.7 patch, but I fear the effects on compatibility. If it's similar to the v9.2.3 patch, then all should be smooth. Still, I'm reluctant to go ahead before seeing others' results.
satchel is offline   Reply With Quote
Old 12-04-2008, 02:23 AM   #91 (permalink)
Hall Of Famer
 
molarmite's Avatar
 
Join Date: Jul 2005
Location: Minnesota
Posts: 4,745
Blog Entries: 1
Thanked 75x in 48 posts
I can tell that I've received exports using 9.2.7 while my owners used 9.2.3. Although Markus still suggests everyone patch up because the hacker can still get the info he needs for people's exports I believe.
__________________
From the wise mind of Davey Eckstein[/SIZE]

"Now all you need is a signature. A quote or initial, perhaps."


molarmite is offline   Reply With Quote
Old 12-04-2008, 02:44 AM   #92 (permalink)
All Star Starter
 
Corsairs's Avatar
 
Join Date: Aug 2007
Posts: 1,904
Thanked 381x in 202 posts
It might be good if Markus popped in here and explained things to us personally. I'd still like to know what to tell my owners who are using Macs. They can't use this patch. Like satchel, I'm worried about compatibility issues during the period where I'm using 9.2.7 and they're stuck using 9.2.3.
__________________
Commissioner of the Planetary Extreme Baseball Alliance (PEBA) and the League of the Rising Sun (LRS)
Premiere OOTP fictional leagues where creativity counts and imagination is your only limitation
Check for openings - contact us today!
Corsairs is offline   Reply With Quote
Old 12-04-2008, 03:08 AM   #93 (permalink)
Minors (Single A)
 
Join Date: Mar 2006
Posts: 95
Thanked 40x in 9 posts
Quote:
Originally Posted by Corsairs View Post
It might be good if Markus popped in here and explained things to us personally. I'd still like to know what to tell my owners who are using Macs. They can't use this patch. Like satchel, I'm worried about compatibility issues during the period where I'm using 9.2.7 and they're stuck using 9.2.3.
Not to mention that a few people in my league who have patched are having issues even getting the game to run. One person had no problems, another patched the .exe and can't even load up OOTP anymore without getting a runtime error, another says the game doesn't load on 9.2.7 but works fine if he uses the 9.2.2 .exe...

This is truly a mess. So if I want to patch my game to protect my site from this hacker, I have to potentially lock out a number of owners from being able to export since they can't get the .exe file to work correctly?

We need some kind of word from up on high. The people in the middle have done an admirable job doing their best to see this gets fixed, but they can only do so much. I'd say that some direct communication is long overdue for the people who have suffered through a lot of trouble dealing with this issue.
Buane is offline   Reply With Quote
Old 12-04-2008, 03:29 AM   #94 (permalink)
Minors (Rookie Ball)
 
Join Date: Sep 2004
Posts: 23
Quote:
Originally Posted by MustangLM View Post
Suicide Squeeze has been hacked several times recently by john mohov. We changed web hosts, but after a few days the hack returned. Our forum runs on SMF 1.17 currently.

Tech support advised me that my global permissions were set to allow files to be written to. They fixed the permissions for me and installed a back up. At the time we were running SMF 1.16 and as soon as the site came back up, I upgraded to SMF 1.17. Two days later we were hacked again. Hopefully that's not the case for you Paul, but don't be surprised if it happens again.

I contacted tech support again and they did some additional digging. They claimed someone had stolen my ftp user name and password and hacked the site. They recommended I do a virus scan on my end, change my password and reinstall SMF. I ran the scan, but it came up empty. I even picked up another virus software package just to be certain the one I was using hadn't missed something. No virus found. I then changed my ftp password and got the site running again yesterday. It's been running for 24 hrs so far with no issues.

I'm not sure how they are getting my password, but one thing I noticed when I first installed OOTP 9 was that when I entered my ftp data for online play, the password was fully visible. At the time I remember thinking that was odd, but thought nothing of it. Maybe it was the same in previous versions, but I seem to remember it always being hidden. I know you need the commissioner password to view those features, but I'm curious if there isn't some security issue with that portion of OOTP. I've never had any issues in past versions of OOTP, just since using this one. Perhaps it's just a coincidence, but I'm curious now.
Our league was ha cked as well. All of the index files had ****** codes written into them that fortunately did not direct the users to another site as planned but instead made the site inoperative. I changed the FTP pw and 2 weeks to the day later we were hacked identically again. MY provider gave me the ftp logs and it shows that the hacker simply logged in, so somehow he is hacking the pw (perhaps from the league file?). I changed the PW again to a random mix of upper and lower case letters and numbers, and symbols... we will see if he attacks again.
Morgan1963 is offline   Reply With Quote
Old 12-04-2008, 03:31 AM   #95 (permalink)
Hall Of Famer
 
mikev's Avatar
 
Join Date: Dec 2004
Location: Bay Area, CA
Posts: 3,984
Thanked 21x in 16 posts
Quote:
Originally Posted by Corsairs View Post
It might be good if Markus popped in here and explained things to us personally. I'd still like to know what to tell my owners who are using Macs. They can't use this patch. Like satchel, I'm worried about compatibility issues during the period where I'm using 9.2.7 and they're stuck using 9.2.3.
No, it might be good for a public release of the patch to be issued and notification given to the whole community, rather than letting a few people know about it. That's how software patching works normally, ESPECIALLY when it's a security issue.

But, as usual, online leagues get the short end of the stick even when it comes to potentially compromising entire leagues because of a security exploit... Gotta hurry up and add more sounds!
__________________
70% of the earth's surface is covered by water. The other 30% is taken care of by Patrick Willis.


Global Unified Baseball Association - Vice Commish and California Crusaders GM
mikev is offline   Reply With Quote
Old 12-04-2008, 03:35 AM   #96 (permalink)
Hall Of Famer
 
molarmite's Avatar
 
Join Date: Jul 2005
Location: Minnesota
Posts: 4,745
Blog Entries: 1
Thanked 75x in 48 posts
Quote:
Originally Posted by Morgan1963 View Post
Our league was ha cked as well. All of the index files had ****** codes written into them that fortunately did not direct the users to another site as planned but instead made the site inoperative. I changed the FTP pw and 2 weeks to the day later we were hacked identically again. MY provider gave me the ftp logs and it shows that the hacker simply logged in, so somehow he is hacking the pw (perhaps from the league file?). I changed the PW again to a random mix of upper and lower case letters and numbers, and symbols... we will see if he attacks again.
We found out it is the league file so you need to patch or it will happen again.
__________________
From the wise mind of Davey Eckstein[/SIZE]

"Now all you need is a signature. A quote or initial, perhaps."


molarmite is offline   Reply With Quote
Old 12-04-2008, 04:18 AM   #97 (permalink)
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 6,078
Blog Entries: 3
Thanked 299x in 172 posts
It is fixed in 9.2.7, but if a Mac or Linux user downloads a 9.2.7 league they won't be able to connect because what it believes is the connection settings will not work.

Until a Mac or Linux 9.2.7 patch comes out, I don't believe that they will be able to access 9.2.7 leagues, but we'd need word from up high as to whether this is true.
Tony M is offline   Reply With Quote
Old 12-04-2008, 05:36 AM   #98 (permalink)
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 6,078
Blog Entries: 3
Thanked 299x in 172 posts
Quote:
Originally Posted by f.montoya View Post
Even that doesn't solve this issue. I've seen 2 of my sites with altered (OOTP generated) index.html pages with an ****** inserted. The hole you saw is EXACTLY how the bad guy is getting in. He either plays OOTP or spent enough time around here to get enough info on how to do this.

Even if you use a limited FTP account, the ****** can still get into the OOTP reports. If this happens, you run the risk of allowing a trojan type virus to get into several league members' computers.
Been having a bit more of a think about this, and I think the following is something that should be seriously considered for OOTP10

The Online leagues work on a two-way FTP system and both the commish and the GMs have 'access' to the FTP settings (access defined as the means of getting hold of them)

The only need a GM has for FTP is really to upload their team export. There isn't necessarily a need to have an FTP download - it should be possible to do it via HTTP.

The game should have two FTPs - one for the commish and one for the GMs - and when the commish runs a sim and creates the .tar.gz file for the league it just strips out all the information pertaining to the commish FTP so the only FTP information that gets passed to the GM is the details he needs to export his team.

Then this export FTP can be given access to just one directory and there's nothing in there that can be exploited as it is just basically team_nnn.ootp files.
Tony M is offline   Reply With Quote
Old 12-04-2008, 06:43 AM   #99 (permalink)
Hall Of Famer
 
Bluenoser's Avatar
 
Join Date: Mar 2002
Location: Canada
Posts: 5,263
Thanked 372x in 244 posts
Quote:
Originally Posted by Tony M View Post
Been having a bit more of a think about this, and I think the following is something that should be seriously considered for OOTP10

The Online leagues work on a two-way FTP system and both the commish and the GMs have 'access' to the FTP settings (access defined as the means of getting hold of them)

The only need a GM has for FTP is really to upload their team export. There isn't necessarily a need to have an FTP download - it should be possible to do it via HTTP.

The game should have two FTPs - one for the commish and one for the GMs - and when the commish runs a sim and creates the .tar.gz file for the league it just strips out all the information pertaining to the commish FTP so the only FTP information that gets passed to the GM is the details he needs to export his team.

Then this export FTP can be given access to just one directory and there's nothing in there that can be exploited as it is just basically team_nnn.ootp files.
I would not want to see it go to http, it would greatly slow down owner downloads.

Anyway, the issue has bee addressed and fixed - http://www.ootpdevelopments.com/boar...ming-soon.html
__________________
It takes neither courage nor intelligence to cheer for a team only when that team wins. The true test of a fan's mettle is the same as it is for a player: Were you there when you were needed?
Bluenoser is offline   Reply With Quote
Old 12-04-2008, 06:50 AM   #100 (permalink)
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 6,078
Blog Entries: 3
Thanked 299x in 172 posts
Quote:
Originally Posted by BruceM View Post
I would not want to see it go to http, it would greatly slow down owner downloads.

Anyway, the issue has bee addressed and fixed - http://www.ootpdevelopments.com/boar...ming-soon.html
OK. Maybe if the league download and the exports were all in the same directory the idea above would still work as that would still be the only directory that a GM would need access to, and the Commish could have access to the other folders for report uploading.
Tony M is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 01:27 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Search Engine Friendly URLs by vBSEO 3.6.0
Copyright © 2009 Out of the Park Developments