L* R*
HOME FORUM DOWNLOADS
Content
  Links
     Browse SVN
     SVN Commit log
     Documentation (Wiki)
  Developers
     Taskmanager
User
Welcome, Guest. Please login or register.
Did you miss your activation email?
December 04, 2008, 04:33:10 PM

Login with username, password and session length
Search



Advanced search
Support GoPHP5.org
BeBot - An Anarchy Online/Age Of Conan chat automaton > Forum > Information > News > Topic: BeBot v0.2.4 released (Security) (Update May21st)
Pages: [1]   Go Down
« previous next »
Print
Author Topic: BeBot v0.2.4 released (Security) (Update May21st)  (Read 779 times)
0 Members and 1 Guest are viewing this topic.
Khalem
BeBot Founder
Administrator
Grandmaster
********
Offline Offline

Gender: Male
Posts: 670



WWW
BeBot v0.2.4 released (Security) (Update May21st)
« on: May 18, 2006, 02:51:39 PM »

This is a security release that addresses a directory traversal issue in the help module.
The issue was discovered by Somebotty @ irc.funcom.com and brought to my intention on May 18th.
In the course of the evning the vulnerability was properly identified, tested, and a fix applied and then tested.
While this may sound serious (and all directory traversal bugs are) it is mitigated by two factors.
- It is only possible to access .txt files trough the HELP function
- On Unix systems it is further mitigated by the user input being lowercased. As Unix systems are case sensitive this makes it even harder to exploit.
There are no known ways to exploit this issue due to the mitigating factors, but non the less we are releasing a version with this bug fixed.

Changelog:
- Fixed directory traversal security issue in the HELP module.
  Thanx to Somebotty @ irc.funcom.com for discovery and notification.
- PHP split into a separate branch to conserve bandwith and make download sizes more manageable.
- The log function have been changed so that if the second parameter is "Security" the event is logged
  to security.txt in the log directory and an alert is sendt to guildchat or private group.

New modules:
- Replaced old Items.php with new module by Vhab.

Downloads
http://files.shadow-realm.org/bebot/BeBot_v0.2.4.tar.gz
http://files.shadow-realm.org/bebot/BeBot_v0.2.4.zip

The php bundle have been split into its own branch as its only needed by windows users, and it will generally be updated less often than the bot core.
http://files.shadow-realm.org/bebot/BeBot-php_v5.1.4.zip
« Last Edit: May 20, 2006, 10:08:41 PM by Khalem » Logged

BeBot Founder and Fixer Kingpin
Madman coder and destroyer of good code
Khalem
BeBot Founder
Administrator
Grandmaster
********
Offline Offline

Gender: Male
Posts: 670



WWW
Re: BeBot v0.2.4 released (Security) (Update May21st)
« Reply #1 on: May 20, 2006, 10:10:59 PM »

Please note that if you downloaded 0.2.4 before 3am UTC on May 21st you will need to redownload the archive or replace core/BotHelp.php due to a typo that made it into this file which would cause the bot to give a fatal error on startup.

http://svn.shadow-realm.org/index.py/BeBot/branches/0.2/core/BotHelp.php?revision=102
Logged

BeBot Founder and Fixer Kingpin
Madman coder and destroyer of good code
Pages: [1]   Go Up
Print
BeBot - An Anarchy Online/Age Of Conan chat automaton > Forum > Information > News > Topic: BeBot v0.2.4 released (Security) (Update May21st)
« previous next »
 
Jump to:  

Recent
online not working after ...
by Alreadythere
[Today at 03:53:28 PM]

Bot not working after tod...
by Alreadythere
[Today at 01:04:41 PM]

Tokens Calulator
by Temar
[December 03, 2008, 01:09:03 PM]

Bebot does not work with ...
by IKShadow
[December 03, 2008, 08:54:04 AM]

!items database
by Temar
[December 03, 2008, 07:27:59 AM]

massive_pvp_time_table 1
by Sudoka
[December 03, 2008, 06:49:07 AM]

Log playtime from buddys ...
by IKShadow
[December 02, 2008, 06:48:12 AM]

[request] Raid timers
by Elesar1
[December 01, 2008, 04:41:09 PM]

Shared DB online list
by Temar
[December 01, 2008, 01:55:47 AM]

relay colors
by Temar
[December 01, 2008, 01:54:56 AM]
Stats
Members
Total Members: 1246
Latest: Vingus
Stats
Total Posts: 11192
Total Topics: 1508
Online Today: 21
Online Ever: 168
(July 01, 2007, 09:30:02 PM)
Users Online
Users: 7
Guests: 18
Total: 25
vikor
upstart
Sudoka
Glarawyn
Snarfblatt
Vingus

Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
TinyPortal v0.9.8 © Bloc | NewDef design by Bloc
Page created in 0.222 seconds with 29 queries. (Pretty URLs adds 0.029s, 4q)
Loading...