Raised This Month: $51 Target: $400
 12% 

Release SourceBans++ (v1.6.4) [Updated: 2021-10-06]


Post New Thread Closed Thread   
 
Thread Tools Display Modes
sneaK
SourceMod Moderator
Join Date: Feb 2015
Location: USA
Old 04-11-2017 , 13:44   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#981

Care to share how this happened so other owners here can protect themselves?
__________________
sneaK is offline
nguyenbaodanh
AlliedModders Donor
Join Date: Jun 2007
Location: HCMC, Vietnam
Old 04-11-2017 , 13:51   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#982

Quote:
Originally Posted by blackhawk74 View Post
Care to share how this happened so other owners here can protect themselves?
Sure, currently if we add some one as admin, without password. Hacker can easily login to the sourcebans website even we didn't set that admin as the webadmin role.
You can test on your sourceban now,
just enter the admin username - don't need to enter any password.
Bang
you've have logged in as a website admin...

That's how my site got hacked :\ ...
He'd looked into my sb banlist and test each user until he found one server root admin that I've set without password to log on the website
(my server roles > mod > smod >root and webADMIN is for the sourcebans login )

RIP me.

But I've fixed anyway. Thanks him for that.
If someone here using this and used to set admins in the server without web login password. YOU SHOULD FIX
__________________

Last edited by nguyenbaodanh; 04-11-2017 at 13:58.
nguyenbaodanh is offline
shanapu
Veteran Member
Join Date: Apr 2015
Location: .de
Old 04-11-2017 , 14:20   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#983

Quote:
Originally Posted by nguyenbaodanh View Post
Sure, currently if we add some one as admin, without password. ~
just enter the admin username - don't need to enter any password.
Bang
you've have logged in as a website admin...
~
If someone here using this and used to set admins in the server without web login password. YOU SHOULD FIX
I can reproduce this :/
__________________
coding & free software
shanapu is offline
Cooky
Veteran Member
Join Date: Jun 2010
Location: 127.0.0.1
Old 04-11-2017 , 14:37   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#984

Quote:
Originally Posted by shanapu View Post
I can reproduce this :/
Same, but only if we add the user through Sourcebans itself. We have our own built store/admin system, which places users directly into the correct tables. By doing that I can't reproduce...

Some serious leak indeed...
Cooky is offline
sneaK
SourceMod Moderator
Join Date: Feb 2015
Location: USA
Old 04-11-2017 , 16:13   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#985

This should've been temp "fixed" in a more recent commit, the patch fix was only allowing login through steam, so the manual user login/password boxes are removed.

Edit: Here's the commit from almost 1 year ago: https://github.com/sbpp/sourcebans-p...f66c9b3618589a

Adds this option:

You guys should definitely update asap, there have been some security fixes since, such as this important one.
__________________

Last edited by sneaK; 04-11-2017 at 16:21.
sneaK is offline
nguyenbaodanh
AlliedModders Donor
Join Date: Jun 2007
Location: HCMC, Vietnam
Old 04-12-2017 , 00:19   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#986

Quote:
Originally Posted by blackhawk74 View Post
This should've been temp "fixed" in a more recent commit, the patch fix was only allowing login through steam, so the manual user login/password boxes are removed.

Edit: Here's the commit from almost 1 year ago: https://github.com/sbpp/sourcebans-p...f66c9b3618589a

Adds this option:

You guys should definitely update asap, there have been some security fixes since, such as this important one.
Any instructions to use the steam login one?
__________________
nguyenbaodanh is offline
sneaK
SourceMod Moderator
Join Date: Feb 2015
Location: USA
Old 04-12-2017 , 02:00   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#987

Quote:
Originally Posted by nguyenbaodanh View Post
Any instructions to use the steam login one?
I would just download + replace all files from the latest commit.
__________________
sneaK is offline
lay295
Senior Member
Join Date: Sep 2013
Old 04-12-2017 , 02:35   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#988

I just used this MySQL query to temp fix the logins for now until it's fixed.

Code:
UPDATE sb_admins SET 'password' = replace('password', '1fcc1a43dfb4a474abb925f54e65f426e932b59e', '');
It'll give you this error box when you try and login



However you'll need to manually wipe new users of their passwords until it's fixed.
__________________


Last edited by lay295; 04-12-2017 at 02:36.
lay295 is offline
JackHammer20
Member
Join Date: Dec 2015
Old 04-12-2017 , 07:09   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#989

Quote:
Originally Posted by blackhawk74 View Post
I would just download + replace all files from the latest commit.
Do you mean from the Dev version? (1.5.5-dev)
JackHammer20 is offline
Cooky
Veteran Member
Join Date: Jun 2010
Location: 127.0.0.1
Old 04-12-2017 , 07:16   Re: [RELEASE] SourceBans++ (v1.5.4.7) [Updated: 2016-04-28]
#990

Quote:
Originally Posted by JackHammer20 View Post
Do you mean from the Dev version? (1.5.5-dev)
Or stable version, yes.
Cooky is offline
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 00:13.


Powered by vBulletin®
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Theme made by Freecode