Posts: 1,170
Joined: Mar 2020
Reputation:
44
Location: Austria
Posts: 1,170
Joined: Mar 2020
Reputation:
44
Location: Austria
February 18th, 2021 at 10:17 AM
Hy Darth Hy folks, the forum was hacked once by an insecure plugin, which one was that? mydropzone plugin or?
Why I ask, strangely enough, are the previously paid plugins offered for free
MyDropzone
Symposium
ENdless
Drafts Autosafe
Default Message
lg Tc4me
[x] <= Drive in nail here for new display!
Posts: 122
Joined: Apr 2020
Reputation:
22
Posts: 122
Joined: Apr 2020
Reputation:
22
February 18th, 2021 at 11:11 AM
(This post was last modified: February 18th, 2021 at 11:13 AM by s3_gunzel.)
If I recall it was the Hovercard plugin
Posts: 5,287
Joined: May 2013
Reputation:
181
Location: Where's North?
Items (6) ▼
Posts: 5,287
Joined: May 2013
Reputation:
181
Location: Where's North?
Items (6) ▼
February 18th, 2021 at 5:32 PM
Yes, hovercards was the plugin that got us. There was another one that was vulnerable as well. I don’t remember exactly which one it was (I’ll look back through the messages and get back to you). They were notified multiple times when it was discovered.
Update: It was the drafts auto save plugin. Checked back today, still does not appear to have been patched. Sent another message to the MyBB team about it today.
Posts: 5,287
Joined: May 2013
Reputation:
181
Location: Where's North?
Items (6) ▼
Posts: 5,287
Joined: May 2013
Reputation:
181
Location: Where's North?
Items (6) ▼
February 18th, 2021 at 7:56 PM
I just made them aware again, they will probably address it shortly. Don’t install the drafts auto save yet. Hovercards has already been patched.
MyDropZone and Symposium are safe too I believe. I audited those a while back. Not sure about any of the other ones, haven’t audited all of them yet.
Posts: 1,170
Joined: Mar 2020
Reputation:
44
Location: Austria
Posts: 1,170
Joined: Mar 2020
Reputation:
44
Location: Austria
February 18th, 2021 at 8:14 PM
ok Thank you, I'll keep waiting before I try, thank you
yes Ben throws out one plugin after the other, is he in a good mood or bored?
[x] <= Drive in nail here for new display!
Posts: 5,287
Joined: May 2013
Reputation:
181
Location: Where's North?
Items (6) ▼
Posts: 5,287
Joined: May 2013
Reputation:
181
Location: Where's North?
Items (6) ▼
February 18th, 2021 at 10:51 PM
Did some digging and research on this one. The plugin is no longer vulnerable. It turns out it was evidently patched at some point as a fly-by-night thing, with absolutely no change to the version, date, or timestamp. No idea when exactly it was patched, it was done at some point after this August with no mention of it publicly.
Posts: 1,170
Joined: Mar 2020
Reputation:
44
Location: Austria
Posts: 1,170
Joined: Mar 2020
Reputation:
44
Location: Austria
February 19th, 2021 at 5:08 AM
That’s already very good, thank you Darth-Apple for your commitment,
[x] <= Drive in nail here for new display!