Go Back   RSG Clan - News, Forums, Games and More. > Main Category > Games Main

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 04-12-2011, 03:31 PM
Administrator
 
Join Date: Aug 2008
Posts: 68,181
Tournaments Joined: 0
Tournaments Won: 0
Post EVE Blog Entry Outlines New Forum Security Issues [EVE Online]

EVE Online's shiny new forums launched last week, but they didn't stay up for long. According to a new dev blog entry, helpful players helped point out a wide variety of possible vulnerabilities in the forums. Players could:
  • Post as anyone.
  • Read any forum anyone had access to.
  • Inject HTML (NOT SCRIPT) into your signature.
  • Inject HTML (and possibly script) in the post reporting feature. (Something someone without roles would not have been able to see i.e. not you unless you were exploiting)
  • Edit anyone else's posts
CCP Sreegs said that CCP doesn't see any way for players to access your personal information or credit cards. "In essence, the vulnerabilities were limited to people's ability to escalate their privileges on the forum itself and nowhere else," he said.

Sreegs also commented that he trying to formalize a program that will reward players who provide information that helps CCP better secure their systems. Regardless, it's always a good idea to submit vulnerabilities if you find them.



More...
Reply With Quote
Sponsored Links
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Blog Entry Showcases EVE Character Creator Video [EVE Online] RSS FEED Games Main 0 12-31-2010 12:40 PM
EVE Online Blog Outlines Contract Improvements [EVE Online] RSS FEED Games Main 0 12-27-2010 04:24 PM
Champions Online GM Duties Outlined in Blog Entry [Champions Online] RSS FEED Games Main 0 12-10-2009 03:07 PM
Dev Blog Outlines COSMOS Features [EVE Online] RSS FEED Games Main 0 09-28-2009 03:53 PM
Dev Blog Entry Explains Desync Issue [EVE Online] RSS FEED Games Main 0 09-11-2009 03:24 PM


All times are GMT -4. The time now is 11:38 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.0