BuffaloHelp 24 Report post Posted July 21, 2006 Admins were alerted today regarding strong security threat via shoutbox exploit for all IPB forums. Thanks to Klass and elevenmil, Xisto forum decided to place D21 Shoutbox offline for the time being. Although the threat did not reach Xisto, I felt it was necessary to take precautious measures as soon as possible, with Klass' guide before OpaQue can update patch files.The upgrade and security patch for D21 v1.1 to v1.2 will begin shortly. Please be patient and I am sorry for your inconveniences.Thank you. Share this post Link to post Share on other sites
Klass 0 Report post Posted July 21, 2006 Also would be a good Idea for any Xisto Hosted member running IPB and Deans shoutbox to check the support threads at invisionize and get the update.This is a extreme exploit. I will not go into detail about it.All your gaming needs check out Xisto's Game Server:http://forums.xisto.com/no_longer_exists/Army System 2.1 Share this post Link to post Share on other sites
Plenoptic 0 Report post Posted July 21, 2006 (edited) Luckily you caught this or we might have been in trouble. lol I signed on and I thought UhOh the shoutbox is gone. Nice catch guys. Sadly thought I have to restart the chase for the Shoutbox King but oh well lol Edited July 22, 2006 by Plenoptic (see edit history) Share this post Link to post Share on other sites
amc 0 Report post Posted July 22, 2006 Very nice catch, I use D21 as well, now i gotta go change it, thanks for posting this! Otherwise i might've been exploited Share this post Link to post Share on other sites
JField 0 Report post Posted July 22, 2006 thanks for this catch Share this post Link to post Share on other sites
MaineFishing45 0 Report post Posted July 22, 2006 So if I check Invisionize I should be able to get the update correct? Because I currently have two shoutboxes on sperate sites of mine, anyways thanks for catching this and hope Xisto can fix this.What does the threat do? Inject something or scew up the site, like the HELP link did a while back? Share this post Link to post Share on other sites
gameratheart 0 Report post Posted July 22, 2006 (edited) It is to do with mySQL, but it's not an injection, more of an exploit. Search the Invisionize Forums for "D21 Shoutbox v1.2" and the history will reveal all. Edited July 24, 2006 by NDPA (see edit history) Share this post Link to post Share on other sites
elevenmil 0 Report post Posted July 23, 2006 http://forums.invisionize.com/index.php?sh9&%23entry1707389 Â For a quick info on this. Â As said update to 1.2 to be safe. Share this post Link to post Share on other sites
BuffaloHelp 24 Report post Posted July 30, 2006 The update is still pending until OpaQue's return with better time schedule. Thanks for your patience everybody! Share this post Link to post Share on other sites
TypoMage 0 Report post Posted July 31, 2006 (edited) I am not trying to rush you Buffalo but do you know when it could be online again?(Or a intelegent guess?)I am a new member(Obviously) And I would like to check this Shoutbox out.(Is it only a chat or something else?) ThankyouOops I missed something else what is this D21 stuff? Do I have to change soemthing on my pc?I have read some of these posts and people are goning to change something?(Please give me a message) Notice from BuffaloHELP: Sent a PM. Other members: please stay within the topic and let not your discussion revolve around this post. Edited July 31, 2006 by BuffaloHELP (see edit history) Share this post Link to post Share on other sites
Florisjuh 0 Report post Posted August 3, 2006 I guess this is taking longer than expected? It's no problem to me though, I am not such of a shouter so I never used the shoutbox really. But I guess some people are a bit bored not being able to lift their hearts in the shoutbox. Xisto security uber alles of course ^^ Share this post Link to post Share on other sites
elevenmil 0 Report post Posted August 4, 2006 It can take awhile if admins are busy...Myself and Klass over at IPB Gaming alerted admins at trap about the exploit, and although Klass had the fix implemented within hours, his job allows him to have access to the internet continuously. Admins here might not have a load of time to work on it. Share this post Link to post Share on other sites
BuffaloHelp 24 Report post Posted August 6, 2006 Well, it's taking longer because OpaQue and I are thinking it's probably better to upgrade the forum from 2.1.6 to 2.1.7 and then update the shoutbox... otherwise OpaQue will be installing the shoutbox twice...So it's almost done... servers are in top shape and OpaQue is ready to do it in one single step :)UPDATE...Shoutbox is now up and running. Thanks everyone for your patience. Share this post Link to post Share on other sites