SMF Login vulnerability: Change your passwords

Author Topic: SMF Login vulnerability: Change your passwords  (Read 21554 times)

Badspot

  • Administrator
There was a vulnerability of some kind on the forum that allowed an attacker to login to seemingly arbitrary accounts.  I received reports that this was due to brute forcing the password recovery email link, but some some compromised accounts did not have their password changed.  There may be more than one vulnerability and it may not be fixed.  My confidence in smf is low.

I have taken the following actions:

* Updated to SMF 2.0.15
* Changed email recovery code to be 40 characters instead of 10
* Deleted lastest 1000 posts and latest 42 topics (approximately covering the period in which accounts were compromised)
* Restored user data from 2018-05-03 backup (so your passwords and profile info will be whatever it was two months ago)

Updating the forum involved resetting all user permissions and porting over various hacks and fixes.  If I've missed something critical, please tell me directly via PM or email.

Update: If you have not done so since the update, I'd recommend changing your password. 
« Last Edit: July 14, 2018, 03:02:07 AM by Badspot »

Badspot

  • Administrator
Where's my loving avatar


This looks funky as hell.

i hope we can eventually get the blockland forums classic theme back


uh, i think the search function is a bit broken, after searching for something it just shows a white screen.


i hope we can eventually get the blockland forums classic theme back
this, it feels so weird without the old theme

Thanks for not leaving the forums dead despite what it's turned into over the years 😆👌



if your guy's search function is not correct try turning on WYSIWYG (yes thats a real thing) in your layout settings in your account

Thank you for not giving up on the forums, Badspot!

Thank you for not giving up on the forums, Badspot!
honestly this. the easy thing to do would be just to delete everything and call it a night and im glad he chose to try and fix it instead