Salmoneus Posted July 23, 2017 Posted July 23, 2017 Hi everyone, Early yesterday morning I was alerted of a suspicious change to one of our forum software files. I immediately investigated and took the forum offline when I realized that something was amiss. Without delving into too many technical details, an unpatched vulnerability in IPB allowed an attacker to inject a malicious piece of JavaScript code into a specific skin's markup. This code would only be output and executed in a users browser under a specific set of circumstances: the user had to be visiting the forum for the first time from a search engine using a major browser. Users who didn't meet all of these criteria did not get the malicious script. From my investigation it looks like this attack was automated, and its sole purpose was to redirect users to spam/malware domains while flying under the radar from staff and forum members. I've seen no evidence of any further compromise, but of course this is not a 100% certainty. This may be a good time to change your Sal's password, and make sure it is unique from passwords for other sites. I spent most of Saturday upgrading the forum and blogs to the latest Invision Community version, which also involved upgrading the webserver and other backend software. This was an unplanned upgrade, and while I've lightly tested things, you may encounter features that are broken. If you do, please let me know by posting in this thread! Right now there are background tasks running to rebuild post content, stats, search indexes, blog entries and more. Until those complete, old posts (and other content) may be formatted incorrectly, and search results may be incomplete. I deeply apologize for this situation -- software patches are critical and need to be applied right away. I will make it a point to make sure future patches are applied ASAP. Quote
Army of One Posted July 24, 2017 Posted July 24, 2017 Thanks for getting the forums back up Sal, patchy forums are better than no forums. Hopefully everything evens out smoothly before long. Quote
Angel Hayley Posted July 24, 2017 Posted July 24, 2017 Thanks for the update Sal, I was worried sick. Hope everything comes back up eventually :) BB code is still fairly brokenĀ Quote
Magic of Woodcut Posted July 24, 2017 Posted July 24, 2017 (edited) Not sure if this would count as a bug but I have noticed that my entire signature is in code when a post of mine appears. I do see that one of the above posters has a signature with an option to reveal hidden contents, but it's unclear to me if that is automated or intentionally instilled with the signature editing service. Either way if I could figure out a way to go around this issue (not to mention stick to the signature rules), that'd be great. Do note that the spoiler code will not work, so if there is a bug mentioned in this comment, it very well may be that. Otherwise nice perpetual update. Edited July 24, 2017 by Magic of Woodcut fidgeted around with it and looks as if the spoiler code does indeed work. i think i implemented the code in the wrong place or something Quote
Fatalysm Posted July 24, 2017 Posted July 24, 2017 (edited) 2 hours ago, Magic of Woodcut said: Not sure if this would count as a bug but I have noticed that my entire signature is in code when a post of mine appears. I do see that one of the above posters has a signature with an option to reveal hidden contents, but it's unclear to me if that is automated or intentionally instilled with the signature editing service. Either way if I could figure out a way to go around this issue (not to mention stick to the signature rules), that'd be great. Do note that the spoiler code will not work, so if there is a bug mentioned in this comment, it very well may be that. Otherwise nice perpetual update. Most of the BBCODE doesn't seem to function correctly. It'll take a bit of time before it's all back to normal. Feel free to report bugs here:Ā Ā Edited July 24, 2017 by Fatalysm Although it looks like you've figured out signatures :). Quote
O hai im KAMIL Posted July 28, 2017 Posted July 28, 2017 Sal is like Batman; he disappeared for a while but he was always watching, and when the forums needed him most, he came back. Ā also this harsh white background is blinding me, is there any way to get a dark mode? Quote
Chaoss Posted July 28, 2017 Posted July 28, 2017 (edited) 20 minutes ago, O hai im KAMIL said: Sal is like Batman; he disappeared for a while but he was always watching, and when the forums needed him most, he came back. Ā also this harsh white background is blinding me, is there any way to get a dark mode? Yeah! We're discussing new themes here: Ā Ā Ā Edited July 28, 2017 by Chaoss Quote
Dimosthimise Posted August 1, 2017 Posted August 1, 2017 Has the super-secret forums been changed at all? I'm not seeing it on my side. Quote
Fatalysm Posted August 1, 2017 Posted August 1, 2017 (edited) 8 hours ago, Lily Haaron said: Has the super-secret forums been changed at all? I'm not seeing it on my side. I don't think so, I would hazard a guess that you don't have the correct permissions to be able to see them. If you're supposed t.o be able to see them, message Salmoneus or Lilshu to get your permissions changed so you can see it again. (Everyone's permissions changed slightly in the upgrade, things were switched off and it was a little chaotic). Edited August 1, 2017 by Fatalysm Quote
Chaoss Posted August 2, 2017 Posted August 2, 2017 On 8/1/2017 at 9:41 AM, Fatalysm said: I don't think so, I would hazard a guess that you don't have the correct permissions to be able to see them. If you're supposed t.o be able to see them, message Salmoneus or Lilshu to get your permissions changed so you can see it again. (Everyone's permissions changed slightly in the upgrade, things were switched off and it was a little chaotic). So theyĀ doĀ exist... I was told of them as a child but I always thought they were a myth. 1 Quote
Fatalysm Posted August 2, 2017 Posted August 2, 2017 3 hours ago, Chaoss said: So theyĀ doĀ exist... I was told of them as a child but I always thought they were a myth. Watch National Treasure with Nicholas Cage, that should explain everything you need to know. Quote
mikeyy Posted August 8, 2017 Posted August 8, 2017 (edited) Was only able to log in after entering my current display name. The original name I used for the account (that it was created as) no longer worked. Bit of a hassle but no biggie. The only issue with that I see is if it will allow new users to create accounts with the original names, which could get confusing. EDIT: I just now saw the announcement. My bad. Edited August 8, 2017 by mikeyy I'm dumb. 1 Quote
Micael Fatia Posted August 16, 2017 Posted August 16, 2017 My gosh, I absolutely hate the new interface. It's so much harder to navigate and the super bright white forum skin is incredibly annoying. Quote
Fatalysm Posted August 16, 2017 Posted August 16, 2017 28 minutes ago, Micael Fatia said: My gosh, I absolutely hate the new interface. It's so much harder to navigate and the super bright white forum skin is incredibly annoying. It's not that hard to navigate, it's largely the same! We've got a discussion going for new themes here: Ā Quote
Micael Fatia Posted August 17, 2017 Posted August 17, 2017 16 hours ago, Fatalysm said: It's not that hard to navigate, it's largely the same! We've got a discussion going for new themes here: Ā Trust me, it's incredibly difficult to navigate. It must be the skin, because I'm having a hard time finding things and just adapting to it's overall look. The Damage Inc forums have the same software, and they're nowhere near as hard to navigate. I'm guessing the Sal's forums haven't been tinkered around with yet, or have been too much because there's definitely something... wrong. Quote
Chaoss Posted August 17, 2017 Posted August 17, 2017 6 hours ago, Micael Fatia said: Trust me, it's incredibly difficult to navigate. It must be the skin, because I'm having a hard time finding things and just adapting to it's overall look. The Damage Inc forums have the same software, and they're nowhere near as hard to navigate. I'm guessing the Sal's forums haven't been tinkered around with yet, or have been too much because there's definitely something... wrong. I don't agree, the Damage Inc forum is the exact same version and when I just visited it I had no trouble understand it.Ā Sure this isĀ different from the last Sal's version, but it only takes 2 seconds to learn the new layout. In any case it's not going to change so complaining won't solve anything. The bigger problem, which I agree with you,Ā isĀ the skin, which we are actively trying to make better in the thread Fatalysm linked! :) Quote
Micael Fatia Posted August 17, 2017 Posted August 17, 2017 2 hours ago, Chaoss said: I don't agree, the Damage Inc forum is the exact same version and when I just visited it I had no trouble understand it.Ā Sure this isĀ different from the last Sal's version, but it only takes 2 seconds to learn the new layout. In any case it's not going to change so complaining won't solve anything. The bigger problem, which I agree with you,Ā isĀ the skin, which we are actively trying to make better in the thread Fatalysm linked! :) Uh, what lol. So you don't agree... by agreeing with exactly what I said? :P As I pointed out the Damage Inc forums are the exact same, and much easier to navigate/bear most likely because of the bright skin here. DI's is so much better it makes it appear both forums are using different software. Quote
Chaoss Posted August 17, 2017 Posted August 17, 2017 (edited) 1 hour ago, Micael Fatia said: Uh, what lol. So you don't agree... by agreeing with exactly what I said? :P As I pointed out the Damage Inc forums are the exact same, and much easier to navigate/bear most likely because of the bright skin here. DI's is so much better it makes it appear both forums are using different software. You misunderstand. You're complaining about two different things, and I countered just one of them -Ā that it's "hard to navigate" here. But these are the same exact forums as Damage, so thatĀ complaint makes no sense.Ā The other complaint you made is about the theme, which is currently being worked on! But once you saw the topic Fatalysm linked you to you continued to say how hard it was to navigate the site which led me to believe it was the physical layout instead of the theme which got you all worked up - hence my initial comment .Ā Edited August 17, 2017 by Chaoss emoticons are still broken lol Quote
Micael Fatia Posted August 17, 2017 Posted August 17, 2017 17 minutes ago, Chaoss said: You misunderstand. You're complaining about two different things, and I countered just one of them -Ā that it's "hard to navigate" here. But these are the same exact forums as Damage, so thatĀ complaint makes no sense.Ā The other complaint you made is about the theme, which is currently being worked on! But once you saw the topic Fatalysm linked you to you continued to say how hard it was to navigate the site which led me to believe it was the physical layout instead of the theme which got you all worked up - hence my initial comment .Ā And I'm struggling to understand why it doesn't make sense. The skin itself makes it harder to navigate, purely because of the sore it is to the eyes. When you use DI's everything appears immediately neatly organized and super simple to interact with, and here it does the opposite effect. It truly drained me the first time I logged in trying to find the forums I was looking for and I'm used to look for in a heart beat after years and years using them. How can you 'counter' with something I acknowledged in my own posts and present it as a counter-argument? That's the only thing not making sense. I pointed out it was difficult to navigate, that it used the same software as the DI forums and the skin was most likely what was making it so difficult - in my own personal opinion - for me to come to terms with the new interface. And you replied with "Ā don't agree, the Damage Inc forum is the exact same version and when I just visited it I had no trouble understand it.Ā Sure this isĀ different from the last Sal's version, but it only takes 2 seconds to learn the new layout. In any case it's not going to change so complaining won't solve anything." To which I'd like to point out the following - 1) I stated it used the same software asĀ the DI forums 2) I pointed out after Fatalysm commented that I too thought the skin was likely the main problem that was making it so difficult to me 3) I shared my opinion, didn't make any demands for changes to be made to forums I don't intend to get back to using regularly; so suggesting I should take "2 seconds to learn the new layout" and that I should stop complaining because I voiced my opinion is quite uncalled for. Quote
Chaoss Posted August 17, 2017 Posted August 17, 2017 (edited) We'll have to agree to disagree. Saying it's hard to click buttons because of the color of the siteĀ baffles me. Like I said, we're looking for a cool blue skin for the site which willĀ hopefully put your mind at ease so the site doesn't drain you just to look at.Ā In any case, I don't want to argue with friends.Ā I'll admit toĀ being petty, and I amĀ sorry if I caused offense.Ā Ā Edited August 17, 2017 by Chaoss Quote
Micael Fatia Posted August 17, 2017 Posted August 17, 2017 We'll agree to disagree then. I didn't come visit here to get into a pointless argument over something that won't impact me in the long run, so I don't get why my opinion and the manner I worded my dislike for the current skin matters. It's a matter of opinion in the end, and the bright skin does make it more difficult for me to deal with the site. Especially taking into account I have 12K posts, that should give you a fair idea of the time I spent here and how used I got to the old simple interface in which I > always < used dark skins. If I felt it was a minor thing, I wouldn't have brought it up to begin with. Ā Anyway, how've you been? Long time no see. Quote
Salmoneus Posted August 18, 2017 Author Posted August 18, 2017 *With sad eyes* You shouldn't fight in here. This is a magical place. Yes, we need a new skin or two. Folks should look atĀ this topic and help us choose! Otherwise I'm going to upload random skins based on my cat's reactions (and while she's a classy cat, she has no innate sense of web design so it will most likely end badly). Ā 2 Quote
Chaoss Posted August 18, 2017 Posted August 18, 2017 8 hours ago, Salmoneus said: *With sad eyes* You shouldn't fight in here. This is a magical place. Yes, we need a new skin or two. Folks should look atĀ this topic and help us choose! Otherwise I'm going to upload random skins based on my cat's reactions (and while she's a classy cat, she has no innate sense of web design so it will most likely end badly). Ā Ya know what...Ā http://www.catforum.com/ It ain't half bad! Quote
Micael Fatia Posted August 18, 2017 Posted August 18, 2017 (edited) Honestly I'm happy with anything that's not white/bright. Edited August 18, 2017 by Micael Fatia Quote
reepicheep Posted August 20, 2017 Posted August 20, 2017 On 8/19/2017 at 0:00 AM, Micael Fatia said: Honestly I'm happy with anything that's not white/bright. I do enjoy not being blinded when I go on here every so often. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.