Home | Webstore
Latest News: OOTP 26 Available - FHM 12 Available - OOTP Go! Available

Out of the Park Baseball 26 Buy Now!

  

Go Back   OOTP Developments Forums > Prior Versions of Our Games > Earlier versions of Out of the Park Baseball > Earlier versions of OOTP: Online Leagues > Earlier versions of OOTP: Commissioner's Corner

Earlier versions of OOTP: Commissioner's Corner Want to run an online league? Want to learn about the 'ins' and 'outs' of being a commish? This is the place!

Reply
 
Thread Tools
Old 12-03-2008, 11:52 AM   #61
f.montoya
Hall Of Famer
 
f.montoya's Avatar
 
Join Date: Nov 2004
Posts: 6,077
Forgot to mention that 3 sites of mine got hit. Spent 3+ hours cleaning up the mess.
__________________
Fidel Montoya

Asahi2 Baseball League ex-Commissioner(Historical League Since 2004)
Ex-Web Host
Current Mod Maker??
f.montoya is offline   Reply With Quote
Old 12-03-2008, 11:55 AM   #62
canadiancreed
Hall Of Famer
 
Join Date: Aug 2004
Posts: 11,660
Sorry if I've missed this, but how is OOTP9 files linked to being able to upload and comprimise sites? The only things that OOTP9 would have on a site is a zip or rar for the league file and basic html pages correct?
canadiancreed is offline   Reply With Quote
Old 12-03-2008, 12:01 PM   #63
f.montoya
Hall Of Famer
 
f.montoya's Avatar
 
Join Date: Nov 2004
Posts: 6,077
Quote:
Originally Posted by Tony M View Post
...

Until the emergency patch comes out there's nothing that can be done to prevent this potential way in, unless you are able to set up a separate FTP user that only has access to the OOTP directories and no access to forums...
Even that doesn't solve this issue. I've seen 2 of my sites with altered (OOTP generated) index.html pages with an ****** inserted. The hole you saw is EXACTLY how the bad guy is getting in. He either plays OOTP or spent enough time around here to get enough info on how to do this.

Even if you use a limited FTP account, the ****** can still get into the OOTP reports. If this happens, you run the risk of allowing a trojan type virus to get into several league members' computers.
__________________
Fidel Montoya

Asahi2 Baseball League ex-Commissioner(Historical League Since 2004)
Ex-Web Host
Current Mod Maker??
f.montoya is offline   Reply With Quote
Old 12-03-2008, 12:02 PM   #64
gollum65
All Star Reserve
 
Join Date: Feb 2007
Posts: 925
It's the actual OOTP league file that GMs download and install into OOTP.
gollum65 is offline   Reply With Quote
Old 12-03-2008, 12:04 PM   #65
Tony M
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 6,156
Quote:
Originally Posted by f.montoya View Post
Even that doesn't solve this issue. I've seen 2 of my sites with altered (OOTP generated) index.html pages with an ****** inserted. The hole you saw is EXACTLY how the bad guy is getting in. He either plays OOTP or spent enough time around here to get enough info on how to do this.

Even if you use a limited FTP account, the ****** can still get into the OOTP reports. If this happens, you run the risk of allowing a trojan type virus to get into several league members' computers.
OK. I didn't realise that. I got the impression that the forums were being compromised by the access. Certainly Gollum's attacker was going at the forums but had done it all by FTP.

I don't think I've ever used an ****** - is it something you can get browsers to not show as it seems quite a big security risk on any site?

I think point 2 is still valid though.
Tony M is offline   Reply With Quote
Old 12-03-2008, 12:50 PM   #66
f.montoya
Hall Of Famer
 
f.montoya's Avatar
 
Join Date: Nov 2004
Posts: 6,077
If you just want to make sure your index files are clean, download them to your hard drive and open them with a text editor. If you see anything in any of your index files like...

Code:
< ****** ...BLAH, Blah, BLAH.../******>
Remove it. Scour your files for anything like this and remove it.
__________________
Fidel Montoya

Asahi2 Baseball League ex-Commissioner(Historical League Since 2004)
Ex-Web Host
Current Mod Maker??

Last edited by Tony M; 12-03-2008 at 01:03 PM. Reason: put some codes round it
f.montoya is offline   Reply With Quote
Old 12-03-2008, 01:03 PM   #67
Tony M
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 6,156
Quote:
Originally Posted by f.montoya View Post
If you just want to make sure your index files are clean, download them to your hard drive and open them with a text editor. If you see anything in any of your index files like...

Code:
< ****** ...BLAH, Blah, BLAH.../******>
Remove it. Scour your files for anything like this and remove it.
Obviously ignore the space between the < and ****** - for some reason the forum wants to do iframes!!! (security risk)
Tony M is offline   Reply With Quote
Old 12-03-2008, 01:09 PM   #68
f.montoya
Hall Of Famer
 
f.montoya's Avatar
 
Join Date: Nov 2004
Posts: 6,077
Thanks Tony.

I thought I was going to get banned for knocking off the OOTP forums with an ****** sample.
__________________
Fidel Montoya

Asahi2 Baseball League ex-Commissioner(Historical League Since 2004)
Ex-Web Host
Current Mod Maker??
f.montoya is offline   Reply With Quote
Old 12-03-2008, 01:27 PM   #69
ericm26
Minors (Single A)
 
Join Date: Jun 2004
Posts: 68
Does anyone know if 2007/2008 have the same security issues as 2009. I run a league that is getting hacked also but we run 2007/2008 not 2009.
ericm26 is offline   Reply With Quote
Old 12-03-2008, 01:34 PM   #70
Tony M
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 6,156
Quote:
Originally Posted by ericm26 View Post
Does anyone know if 2007/2008 have the same security issues as 2009. I run a league that is getting hacked also but we run 2007/2008 not 2009.
Without access to a 2007/2008 game I couldn't say. I'll just go and have a look in the 2008 forum and find a random online league to see if it's still on the previous version.
Tony M is offline   Reply With Quote
Old 12-03-2008, 01:38 PM   #71
Mike44126
Minors (Single A)
 
Join Date: Apr 2006
Posts: 87
Is there a patch out? Someone emailed a league I'm in with a patch...please confirm this
Mike44126 is offline   Reply With Quote
Old 12-03-2008, 01:43 PM   #72
molarmite
Hall Of Famer
 
molarmite's Avatar
 
Join Date: Jul 2005
Location: Minnesota
Posts: 4,924
Well considering I was the one who emailed you, you probably won't believe that I confirm it but I'm sure someone else will soon.
__________________
From the wise mind of Davey Eckstein

"Now all you need is a signature. A quote or initial, perhaps."


[
molarmite is offline   Reply With Quote
Old 12-03-2008, 02:34 PM   #73
cnield
Major Leagues
 
Join Date: Nov 2006
Posts: 310
Quote:
Originally Posted by molarmite View Post
Well considering I was the one who emailed you, you probably won't believe that I confirm it but I'm sure someone else will soon.
The link that was sent to us was for the 9.2.7 patch (?). However, that patch was put up on November 17, which was before you guys figured out what the hole was. So I'm a bit dubious that the patch would solve anything.
cnield is offline   Reply With Quote
Old 12-03-2008, 02:39 PM   #74
Tony M
Global Moderator
 
Tony M's Avatar
 
Join Date: Feb 2006
Location: Here
Posts: 6,156
Quote:
Originally Posted by cnield View Post
The link that was sent to us was for the 9.2.7 patch (?). However, that patch was put up on November 17, which was before you guys figured out what the hole was. So I'm a bit dubious that the patch would solve anything.
I told Andreas about this hole a couple of days after this thread started so this patch does cover this hole.
Tony M is offline   Reply With Quote
Old 12-03-2008, 02:43 PM   #75
Corsairs
Hall Of Famer
 
Corsairs's Avatar
 
Join Date: Aug 2007
Posts: 2,360
Is there a Mac version of the patch available? The mailing I received only pointed to a PC version. Several of my owners use Macs.
__________________
Founder of the Planetary Extreme Baseball Alliance (PEBA)
Premiere OOTP fictional league where creativity counts and imagination is your only limitation
Check for openings - contact us today!
Corsairs is offline   Reply With Quote
Old 12-03-2008, 06:14 PM   #76
kq76
Global Moderator
 
kq76's Avatar
 
Join Date: Nov 2002
Posts: 11,868
Is this patch going to be publicly announced? It sounds like it is only being spread privately and I don't understand why that would be. If it fixes an exploit surely it should be announced like any other patch so as many people can know about it as possible rather than just talked about here and in private.

EDIT: I was just passed the link to the aforementioned patch. I don't know why it wasn't publicly posted, but unless someone can tell me why it shouldn't be I'll be linking to it here and in the online league board's stickied thread.
kq76 is offline   Reply With Quote
Old 12-03-2008, 07:15 PM   #77
kq76
Global Moderator
 
kq76's Avatar
 
Join Date: Nov 2002
Posts: 11,868
Quote:
Originally Posted by Tony M View Post
I don't think I've ever used an ****** - is it something you can get browsers to not show as it seems quite a big security risk on any site?
See:

Quote:
Originally Posted by Alan T View Post
As far as end users go, users that use firefox with noscript for instance is not fully protected, as by default noscript allowed iframes. Those users should go in to the noscript settings and make sure to explicitly say not to allow iframes either (unless they override it). I am less familiar with internet explorer, but I understand there are ways to protect yourself there as well.
People should know, however, that there are legitimate uses for iframes. For example, a number of online leagues use them quite effectively to display league standings on their websites. However, iframes are usually not needed and if a web designer has them as necessary parts of their website then they should probably re-think that. I'd like to keep iframes enabled myself as they can add to a site, but I think for now I'm going to disable them as Alan T explained above. I imagine every web browser probably has a way to disable, except maybe ie.
kq76 is offline   Reply With Quote
Old 12-03-2008, 07:27 PM   #78
mikev
Hall Of Famer
 
mikev's Avatar
 
Join Date: Dec 2004
Location: Bay Area, CA
Posts: 4,014
Quote:
Originally Posted by kq76 View Post
Is this patch going to be publicly announced? It sounds like it is only being spread privately and I don't understand why that would be. If it fixes an exploit surely it should be announced like any other patch so as many people can know about it as possible rather than just talked about here and in private.

EDIT: I was just passed the link to the aforementioned patch. I don't know why it wasn't publicly posted, but unless someone can tell me why it shouldn't be I'll be linking to it here and in the online league board's stickied thread.
Why the hell would that not be publicly announced?
__________________
Global Unified Baseball Association - Vice Commish and Oakland Oaks GM
mikev is offline   Reply With Quote
Old 12-03-2008, 07:53 PM   #79
gollum65
All Star Reserve
 
Join Date: Feb 2007
Posts: 925
I've kept my toungue privately on this all morning. I cannot for the life of me understand why a patch was made to address a security hole in OOTP without being released to the public. I'm not stupid. I'm not going to say that I know 100% for sure that my site was hacked due to an exploit of this security hole, but I'd say it's a good bet that it was. And even if it wasn't, for the OOTP developers to sit there and watch as numerous sites were hacked over the past month and not do anything to circulate this patch file is inexcusable to me, and it's causing me serious doubts as to whether I want to buy OOTP 10 when it comes out.

It's one thing to fix an issue that isn't a major security hole and wait to release it in a cummulative patch. It's quite another to fix a major security hole and not release an "emergency patch" when you know your customers are being victimized, regardless if you think the security hole is the problem or not.
gollum65 is offline   Reply With Quote
Old 12-03-2008, 08:16 PM   #80
Cooleyvol
Hall Of Famer
 
Cooleyvol's Avatar
 
Join Date: Dec 2001
Location: Union City, TN
Posts: 6,383
So, can all commishes get this patch or is there a select few that are worthy of being protected against this?
Cooleyvol is offline   Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 12:02 AM.

 

Major League and Minor League Baseball trademarks and copyrights are used with permission of Major League Baseball. Visit MLB.com and MiLB.com.

Officially Licensed Product – MLB Players, Inc.

Out of the Park Baseball is a registered trademark of Out of the Park Developments GmbH & Co. KG

Google Play is a trademark of Google Inc.

Apple, iPhone, iPod touch and iPad are trademarks of Apple Inc., registered in the U.S. and other countries.

COPYRIGHT © 2023 OUT OF THE PARK DEVELOPMENTS. ALL RIGHTS RESERVED.

 

Powered by vBulletin® Version 3.8.10
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Copyright © 2024 Out of the Park Developments