Hydaelyn Role-Players
Security Update - Printable Version

+- Hydaelyn Role-Players (https://ffxiv-roleplayers.com/mybb18)
+-- Forum: Off-Topic (https://ffxiv-roleplayers.com/mybb18/forumdisplay.php?fid=42)
+--- Forum: Off-Topic Discussion (https://ffxiv-roleplayers.com/mybb18/forumdisplay.php?fid=14)
+--- Thread: Security Update (/showthread.php?tid=5242)



Security Update - Kylin - 10-24-2013

The site has just undergone a security update. As a result, several core files were overwritten and some minor things may not be working properly. I think I fixed most of them. If another issue arises, please report it here. Thanks.

Security update solved the following:

Vulnerabilities dealt with:
  • High Risk: Authorization bypass vulnerability within the PM system
  • Medium Risk: Accounts without login keys could be hijacked
  • Low Risk: Weakness within the generate_post_check() function
  • Low Risk: Anonymous statistics may not always be anonymous
  • Low Risk: Database backups are exposed in logs

Bugs dealt with:
Show Content