![]() |
|
MyBB DataBreach?? - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: The Lounge (https://sinister.li/Forum-The-Lounge) +--- Thread: MyBB DataBreach?? (/Thread-MyBB-DataBreach) |
MyBB DataBreach?? - Vulva - 06-22-2019 [redacted] just came out saying they just got breached because of a mybb vulnerability. is siniter.ly in the clear? RE: MyBB DataBreach?? - Drako - 06-22-2019 If there is a problem, I'm glad I didn't use my password for anything else here. Hopefully we're all good and everyone else. RE: MyBB DataBreach?? - Oni - 06-22-2019 We have extra precautions in place for things like this. That said, I'm looking into it, and making extra sure we were not impacted. RE: MyBB DataBreach?? - Oni - 06-23-2019 I do have qualms with how the MyBB devs chose to deal with the recent situation and I'll make an effort to speak with them. That said, our security measures were sufficient, and nothing of harm was done. The board is up to date and we only suffered a couple hours of downtime. My statement to the developers: Quote:I spoke with Nervo about the transparency of vulnerabilities several years ago. I've ran a forum for almost a decade and I've never seen a situation so dire. Board owners need to be updated with security flaws and there's no reason it should have taken until the 10th to do so. I expect more from the MyBB team and I'm sure the other board owners do as well. It is not realistic to expect users to keep up to date with the Github. These vulnerabilities were in the wild long before other owners heard. RE: MyBB DataBreach?? - Drako - 06-23-2019 (06-23-2019, 12:00 AM)Oni Wrote: I do have qualms with how the MyBB devs chose to deal with the recent situation and I'll make an effort to speak with them. That said, our security measures were sufficient, and nothing of harm was done. The board is up to date and we only suffered a couple hours of downtime. That's the risk you have to take running a site. You always have to be active with security patches and such. Hopefully MyBB can deal with stuff like this better later on. RE: MyBB DataBreach?? - Pikami - 06-23-2019 (06-23-2019, 12:00 AM)Oni Wrote: My statement to the developers: They only pushed the commit fixing the issue on Jun 10th, the same day they released a new version. So even if you were to track the changes on git it wouldn't have made much of a difference from waiting for a new release and patching it then. Personaly I can't think of a solution for reporting about these things to the board owners, maybe send an email to everyone after every single release, but that wouldn't be any different from just following mybb's twitter feed and keeping an eye out for updates. RE: MyBB DataBreach?? - Oni - 06-23-2019 (06-23-2019, 02:18 AM)Drako Wrote:(06-23-2019, 12:00 AM)Oni Wrote: I do have qualms with how the MyBB devs chose to deal with the recent situation and I'll make an effort to speak with them. That said, our security measures were sufficient, and nothing of harm was done. The board is up to date and we only suffered a couple hours of downtime. That's assumed, but in this case the developers knew for a week, and didn't disclose. RE: MyBB DataBreach?? - mothered - 06-23-2019 (06-23-2019, 11:47 AM)Oni Wrote: but in this case the developers knew for a week, and didn't disclose. Sadly, It's the case with most data breaches. Companies/devs do not enjoy a negative Impact on their reputation, by revealing breaches there and then. RE: MyBB DataBreach?? - Mr.Kurd - 06-26-2019 Are you talking about the RCE and XSS exploit? RE: MyBB DataBreach?? - Oni - 06-26-2019 (06-26-2019, 01:40 PM)Mr.Kurd Wrote: Are you talking about the RCE and XSS exploit? Yes. We weren't affected. |