Latest News: Updated Patch #4, version 10.4.31 available! - OOTP 10 RELEASED! - Title Bout Championship Boxing 2.5 released! - Inside the Park Baseball Patch 1.03 released, DEMO now available

Click here to download Out of the Park Baseball 10!

Go Back   OOTP Developments Forums

> OUT OF THE PARK BASEBALL 9 > OOTP 9 - Online Leagues > OOTP Commissioner's Corner


OOTP Commissioner's Corner Want to run an online league? Want to learn about the 'ins' and 'outs' of being a commish? This is the place!

Reply
 
LinkBack Thread Tools Display Modes
Old 12-03-2008, 11:52 AM   #61 (permalink)
Hall Of Famer
 
f.montoya's Avatar
 
Join Date: Nov 2004
Posts: 5,028
Thanked 13x in 6 posts
Forgot to mention that 3 sites of mine got hit. Spent 3+ hours cleaning up the mess.
__________________
Fidel Montoya

Asahi2 Baseball Commissioner(Historical League Since 2004)
www.allsimbaseball.com (OOTP web hosting - Customized sites for online leagues - No website knowledge necessary!)
Share Your Mods - Free, unlimited and easy to upload to share your Mods instantly(free site registration required)
f.montoya is offline   Reply With Quote
Old 12-03-2008, 11:55 AM   #62 (permalink)
Hall Of Famer
 
canadiancreed's Avatar
 
Join Date: Aug 2004
Posts: 10,531
Thanked 48x in 29 posts
Sorry if I've missed this, but how is OOTP9 files linked to being able to upload and comprimise sites? The only things that OOTP9 would have on a site is a zip or rar for the league file and basic html pages correct?
canadiancreed is offline   Reply With Quote
Old 12-03-2008, 12:01 PM   #63 (permalink)
Hall Of Famer
 
f.montoya's Avatar
 
Join Date: Nov 2004
Posts: 5,028
Thanked 13x in 6 posts
Quote:
Originally Posted by Tony M View Post
...

Until the emergency patch comes out there's nothing that can be done to prevent this potential way in, unless you are able to set up a separate FTP user that only has access to the OOTP directories and no access to forums...
Even that doesn't solve this issue. I've seen 2 of my sites with altered (OOTP generated) index.html pages with an ****** inserted. The hole you saw is EXACTLY how the bad guy is getting in. He either plays OOTP or spent enough time around here to get enough info on how to do this.

Even if you use a limited FTP account, the ****** can still get into the OOTP reports. If this happens, you run the risk of allowing a trojan type virus to get into several league members' computers.
__________________
Fidel Montoya

Asahi2 Baseball Commissioner(Historical League Since 2004)
www.allsimbaseball.com (OOTP web hosting - Customized sites for online leagues - No website knowledge necessary!)
Share Your Mods - Free, unlimited and easy to upload to share your Mods instantly(free site registration required)
f.montoya is offline   Reply With Quote
Old 12-03-2008, 12:02 PM   #64 (permalink)
All Star Reserve
 
Join Date: Feb 2007
Posts: 776
It's the actual OOTP league file that GMs download and install into OOTP.
gollum65 is offline   Reply With Quote
Old 12-03-2008, 12:04 PM   #65 (permalink)
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 5,161
Blog Entries: 2
Thanked 63x in 40 posts
Quote:
Originally Posted by f.montoya View Post
Even that doesn't solve this issue. I've seen 2 of my sites with altered (OOTP generated) index.html pages with an ****** inserted. The hole you saw is EXACTLY how the bad guy is getting in. He either plays OOTP or spent enough time around here to get enough info on how to do this.

Even if you use a limited FTP account, the ****** can still get into the OOTP reports. If this happens, you run the risk of allowing a trojan type virus to get into several league members' computers.
OK. I didn't realise that. I got the impression that the forums were being compromised by the access. Certainly Gollum's attacker was going at the forums but had done it all by FTP.

I don't think I've ever used an ****** - is it something you can get browsers to not show as it seems quite a big security risk on any site?

I think point 2 is still valid though.
Tony M is offline   Reply With Quote
Old 12-03-2008, 12:50 PM   #66 (permalink)
Hall Of Famer
 
f.montoya's Avatar
 
Join Date: Nov 2004
Posts: 5,028
Thanked 13x in 6 posts
If you just want to make sure your index files are clean, download them to your hard drive and open them with a text editor. If you see anything in any of your index files like...

Code:
< ****** ...BLAH, Blah, BLAH.../******>
Remove it. Scour your files for anything like this and remove it.
__________________
Fidel Montoya

Asahi2 Baseball Commissioner(Historical League Since 2004)
www.allsimbaseball.com (OOTP web hosting - Customized sites for online leagues - No website knowledge necessary!)
Share Your Mods - Free, unlimited and easy to upload to share your Mods instantly(free site registration required)

Last edited by Tony M; 12-03-2008 at 01:03 PM. Reason: put some codes round it
f.montoya is offline   Reply With Quote
Old 12-03-2008, 01:03 PM   #67 (permalink)
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 5,161
Blog Entries: 2
Thanked 63x in 40 posts
Quote:
Originally Posted by f.montoya View Post
If you just want to make sure your index files are clean, download them to your hard drive and open them with a text editor. If you see anything in any of your index files like...

Code:
< ****** ...BLAH, Blah, BLAH.../******>
Remove it. Scour your files for anything like this and remove it.
Obviously ignore the space between the < and ****** - for some reason the forum wants to do iframes!!! (security risk)
Tony M is offline   Reply With Quote
Old 12-03-2008, 01:09 PM   #68 (permalink)
Hall Of Famer
 
f.montoya's Avatar
 
Join Date: Nov 2004
Posts: 5,028
Thanked 13x in 6 posts
Thanks Tony.

I thought I was going to get banned for knocking off the OOTP forums with an ****** sample.
__________________
Fidel Montoya

Asahi2 Baseball Commissioner(Historical League Since 2004)
www.allsimbaseball.com (OOTP web hosting - Customized sites for online leagues - No website knowledge necessary!)
Share Your Mods - Free, unlimited and easy to upload to share your Mods instantly(free site registration required)
f.montoya is offline   Reply With Quote
Old 12-03-2008, 01:27 PM   #69 (permalink)
Minors (Single A)
 
Join Date: Jun 2004
Posts: 65
Does anyone know if 2007/2008 have the same security issues as 2009. I run a league that is getting hacked also but we run 2007/2008 not 2009.
ericm26 is offline   Reply With Quote
Old 12-03-2008, 01:34 PM   #70 (permalink)
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 5,161
Blog Entries: 2
Thanked 63x in 40 posts
Quote:
Originally Posted by ericm26 View Post
Does anyone know if 2007/2008 have the same security issues as 2009. I run a league that is getting hacked also but we run 2007/2008 not 2009.
Without access to a 2007/2008 game I couldn't say. I'll just go and have a look in the 2008 forum and find a random online league to see if it's still on the previous version.
Tony M is offline   Reply With Quote
Old 12-03-2008, 01:38 PM   #71 (permalink)
Minors (Rookie Ball)
 
Join Date: Apr 2006
Posts: 49
Is there a patch out? Someone emailed a league I'm in with a patch...please confirm this
Mike44126 is offline   Reply With Quote
Old 12-03-2008, 01:43 PM   #72 (permalink)
Hall Of Famer
 
molarmite's Avatar
 
Join Date: Jul 2005
Location: Minnesota
Posts: 4,232
Thanked 41x in 22 posts
Well considering I was the one who emailed you, you probably won't believe that I confirm it but I'm sure someone else will soon.
__________________


http://vmlb.allsimbaseball3.com/

From the wise mind of Davey Eckstein


"Now all you need is a signature. A quote or initial, perhaps."


molarmite is offline   Reply With Quote
Old 12-03-2008, 02:34 PM   #73 (permalink)
Minors (Triple A)
 
cnield's Avatar
 
Join Date: Nov 2006
Posts: 297
Quote:
Originally Posted by molarmite View Post
Well considering I was the one who emailed you, you probably won't believe that I confirm it but I'm sure someone else will soon.
The link that was sent to us was for the 9.2.7 patch (?). However, that patch was put up on November 17, which was before you guys figured out what the hole was. So I'm a bit dubious that the patch would solve anything.
__________________
Find Barclays Premier League Uniforms and others in my Photobucket
--
Long Running OOTP X League MLB Dreams Looking for Owners
cnield is offline   Reply With Quote
Old 12-03-2008, 02:39 PM   #74 (permalink)
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 5,161
Blog Entries: 2
Thanked 63x in 40 posts
Quote:
Originally Posted by cnield View Post
The link that was sent to us was for the 9.2.7 patch (?). However, that patch was put up on November 17, which was before you guys figured out what the hole was. So I'm a bit dubious that the patch would solve anything.
I told Andreas about this hole a couple of days after this thread started so this patch does cover this hole.
Tony M is offline   Reply With Quote
Old 12-03-2008, 02:43 PM   #75 (permalink)
All Star Reserve
 
Corsairs's Avatar
 
Join Date: Aug 2007
Posts: 818
Thanked 67x in 21 posts
Is there a Mac version of the patch available? The mailing I received only pointed to a PC version. Several of my owners use Macs.
__________________
Commissioner of the Planetary Extreme Baseball Alliance (PEBA) and the League of the Rising Sun (LRS)
Premiere OOTP fictional leagues where creativity counts and imagination is your only limitation
Check for openings - contact us today!
Corsairs is offline   Reply With Quote
Old 12-03-2008, 06:14 PM   #76 (permalink)
Global Moderator
 
kq76's Avatar
 
Join Date: Nov 2002
Posts: 6,535
Thanked 39x in 28 posts
Is this patch going to be publicly announced? It sounds like it is only being spread privately and I don't understand why that would be. If it fixes an exploit surely it should be announced like any other patch so as many people can know about it as possible rather than just talked about here and in private.

EDIT: I was just passed the link to the aforementioned patch. I don't know why it wasn't publicly posted, but unless someone can tell me why it shouldn't be I'll be linking to it here and in the online league board's stickied thread.
__________________
Useful Links: X Manual - Downloads - Newsletters - Licenses FAQ - Other FAQ - Tech Support

Interactive Online League Directory - find or advertise a league today!
Canadian Baseball League - uses OOTP9, running steadily since April 2002
kq76 is offline   Reply With Quote
Old 12-03-2008, 07:15 PM   #77 (permalink)
Global Moderator
 
kq76's Avatar
 
Join Date: Nov 2002
Posts: 6,535
Thanked 39x in 28 posts
Quote:
Originally Posted by Tony M View Post
I don't think I've ever used an ****** - is it something you can get browsers to not show as it seems quite a big security risk on any site?
See:

Quote:
Originally Posted by Alan T View Post
As far as end users go, users that use firefox with noscript for instance is not fully protected, as by default noscript allowed iframes. Those users should go in to the noscript settings and make sure to explicitly say not to allow iframes either (unless they override it). I am less familiar with internet explorer, but I understand there are ways to protect yourself there as well.
People should know, however, that there are legitimate uses for iframes. For example, a number of online leagues use them quite effectively to display league standings on their websites. However, iframes are usually not needed and if a web designer has them as necessary parts of their website then they should probably re-think that. I'd like to keep iframes enabled myself as they can add to a site, but I think for now I'm going to disable them as Alan T explained above. I imagine every web browser probably has a way to disable, except maybe ie.
__________________
Useful Links: X Manual - Downloads - Newsletters - Licenses FAQ - Other FAQ - Tech Support

Interactive Online League Directory - find or advertise a league today!
Canadian Baseball League - uses OOTP9, running steadily since April 2002
kq76 is offline   Reply With Quote
Old 12-03-2008, 07:27 PM   #78 (permalink)
Hall Of Famer
 
mikev's Avatar
 
Join Date: Dec 2004
Location: Bay Area, CA
Posts: 3,676
Thanked 6x in 5 posts
Quote:
Originally Posted by kq76 View Post
Is this patch going to be publicly announced? It sounds like it is only being spread privately and I don't understand why that would be. If it fixes an exploit surely it should be announced like any other patch so as many people can know about it as possible rather than just talked about here and in private.

EDIT: I was just passed the link to the aforementioned patch. I don't know why it wasn't publicly posted, but unless someone can tell me why it shouldn't be I'll be linking to it here and in the online league board's stickied thread.
Why the hell would that not be publicly announced?
__________________
70% of the earth's surface is covered by water. The other 30% is taken care of by Patrick Willis.


Global Unified Baseball Association - Vice Commish and California Crusaders GM
mikev is offline   Reply With Quote
Old 12-03-2008, 07:53 PM   #79 (permalink)
All Star Reserve
 
Join Date: Feb 2007
Posts: 776
I've kept my toungue privately on this all morning. I cannot for the life of me understand why a patch was made to address a security hole in OOTP without being released to the public. I'm not stupid. I'm not going to say that I know 100% for sure that my site was hacked due to an exploit of this security hole, but I'd say it's a good bet that it was. And even if it wasn't, for the OOTP developers to sit there and watch as numerous sites were hacked over the past month and not do anything to circulate this patch file is inexcusable to me, and it's causing me serious doubts as to whether I want to buy OOTP 10 when it comes out.

It's one thing to fix an issue that isn't a major security hole and wait to release it in a cummulative patch. It's quite another to fix a major security hole and not release an "emergency patch" when you know your customers are being victimized, regardless if you think the security hole is the problem or not.
gollum65 is offline   Reply With Quote
Old 12-03-2008, 08:16 PM   #80 (permalink)
Hall Of Famer
 
Cooleyvol's Avatar
 
Join Date: Dec 2001
Location: Woodland Mills, TN
Posts: 4,356
Thanked 9x in 6 posts
So, can all commishes get this patch or is there a select few that are worthy of being protected against this?
__________________



SEC Champions, 2006,2008-14
2008, 2011 National Runners-up
2009, 2010, 2012, 2013 National Champions
Cooleyvol is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 11:00 AM.


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
Copyright © 2009 Out of the Park Developments