Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,843 Members
164,841 Posts
37 Users Online

Please welcome our newest member, mmmmmu!

Affiliates
Go Back AdminFusion » Getting Started » Software » Invision Power Board » [IPB News] IP.Board Security Enhancements
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 10-24-2007, 06:12 PM   #1

Title: Apprentice

Points: 4,964, Level: 20Points: 4,964, Level: 20Points: 4,964, Level: 20
Level up: 21%, 86 Points neededLevel up: 21%, 86 Points neededLevel up: 21%, 86 Points needed
Activity: 45%Activity: 45%Activity: 45%

Join Date: Sep 2005

Posts: 443

Industry News is on a distinguished road
 
 
Post [IPB News] IP.Board Security Enhancements

IP.Board Security Enhancements

We are releasing three minor security updates to address issues recently reported regarding areas of IP.Board 2.3.1. These security issues are rather low priority and require specific sets of circumstances to be utilized. Even then the impact is minimal due to other security features in the software.


Issue 1 (Reported by Forumlar (Tartışma ve Paylaşımların Merkezi - Türkçe Forum - Turkish Forum / Board / Blog) )

If you use a character set other than iso-8859-1 or utf-8, it is possible to submit javascript to your user profile fields. The potential damage is mitigated by the use of httpOnly cookies in IP.Board. Please note that IP.Board ships with iso-8859-1 set by default. Therefore, unless you have specifically changed the character set in the Admin CP your installation is not impacted by this issue.

Issue 2 (Reported by Critical Security.NET (Powered by Invision Power Board) )

A user is able to upload a non-image file if the file is given an image name in a specific format. The security implications are very low because IP.Board automatically resets the file to a .txt file and treats it as such, however this could result in broken photo or avatar images being displayed, and script files with a .txt extension saved in your uploads directory. Again the potential damage is mitigated by the use of httpOnly cookies in IP.Board thereby disallowing javascript access to cookies.

Issue 3 (Reported by CommunitySEO (Powered by Invision Power Board) )

If you have subscription packages enabled on your site using the subscriptions manager included with IP.Board which promote a paying user to a new user group, it is possible to recraft a payment form to set the member's ID to a different member. The issue would require that an actual valid payment is made and no unauthorized access could be gained, however a specially crafted form could result in all administrators/moderators of a site being demoted to a subscriber group, for example. The reverse, a user being promoted to admin, is not possible in this issue.


Patching Your IP.Board

The IP.Board 2.3.1 download in the client area has already been updated with the required changes. If you download IP.Board after the date of this announcement your installation will be up to date.

Changed Files
Download the zip file below which includes only the changed files for this update. Simply upload and overwrite the old files.

9.12.2007.zip ( 23.55K ) Number of downloads: 1636


Manual Instructions
The following file contains manual patch instructions for those who want to edit php files by hand.

More...
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
[IPB News] IP.Board 2.3.2, IP.Gallery 2.2.1, and IP.Converge 1.0.0 Released Industry News Invision Power Board 0 10-24-2007 06:12 PM
[IPB News] IP.Board Security Enhancements Industry News Invision Power Board 0 09-13-2007 01:33 AM
[IPB News] IPB 2.x.x Security Update (06-05-6) Industry News Invision Power Board 0 05-17-2006 07:07 PM
[IPB News] IPB 2.x.x Security Update (04-25-06) Industry News Invision Power Board 0 04-25-2006 04:08 PM
[IPB News] IPB 2.x.x Critical Security Update Industry News Invision Power Board 0 01-05-2006 10:08 PM

AdminFusion

All times are GMT +1. The time now is 01:35 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72