Bay 12 Games Forum

Please login or register.

Login with username, password and session length
Advanced search  

Author Topic: Wiki Downtime (unexpected) to patch a critical security flaw  (Read 1578 times)

Locriani

  • Bay Watcher
  • Locriani == Briess
    • View Profile
    • dwarf fortress wiki
Wiki Downtime (unexpected) to patch a critical security flaw
« on: April 09, 2010, 02:02:45 pm »

The wiki will be down for a bit to patch a critical security flaw (yay, another one!) in the MediaWiki software.  I have no estimate as to length of downtime.
Logged
I am one of many administrators of the wiki.  Please use my user page (http://dwarffortresswiki.org/index.php/User_talk:Briess) on the wiki to contact me, as I check that more often than these forums.

Warlord255

  • Bay Watcher
  • Master Building Designer
    • View Profile
Re: Wiki Downtime (unexpected) to patch a critical security flaw
« Reply #1 on: April 09, 2010, 02:20:51 pm »

Here's to hoping it'll be up soon. Keep up the good work.
Logged
DF Vanilla-Spice Revised: Better balance, more !!fun!!
http://www.bay12forums.com/smf/index.php?topic=173907.msg7968772#msg7968772

LeadfootSlim on Steam, LeadfootSlim#1851 on Discord. Hit me up!

PencilinHand

  • Bay Watcher
    • View Profile
Re: Wiki Downtime (unexpected) to patch a critical security flaw
« Reply #2 on: April 09, 2010, 02:46:40 pm »

The wiki will be down for a bit to patch a critical security flaw (yay, another one!) in the MediaWiki software.  I have no estimate as to length of downtime.

You have my thanks for your efforts, both past and present.
Logged

Box

  • Bay Watcher
  • [VERMINHUNTER]
    • View Profile
Re: Wiki Downtime (unexpected) to patch a critical security flaw
« Reply #3 on: April 09, 2010, 02:51:41 pm »

If you don't mind my prying, was this a security flaw that would only affect the wiki or could it have been used to target users?

I'm wondering because it isn't often that security flaws are spotted before they are already abused or shown off.   :-\


EDIT: I guess a more direct question would be: what are the extent of the damages, if there were any at all?
« Last Edit: April 09, 2010, 02:55:56 pm by Box »
Logged
You should come inside the box.

Then you'll know what I mean.

Locriani

  • Bay Watcher
  • Locriani == Briess
    • View Profile
    • dwarf fortress wiki
Re: Wiki Downtime (unexpected) to patch a critical security flaw
« Reply #4 on: April 09, 2010, 02:58:00 pm »

I've disabled login, as it affected that. (It's still enabled, if you know where to look, but please don't log in as the login process is vulnerable)!

Basically, mediawiki had a CSRF flaw that could allow another person to hijack your login.
« Last Edit: April 09, 2010, 03:00:00 pm by Locriani »
Logged
I am one of many administrators of the wiki.  Please use my user page (http://dwarffortresswiki.org/index.php/User_talk:Briess) on the wiki to contact me, as I check that more often than these forums.

tigrex

  • Bay Watcher
    • View Profile
Re: Wiki Downtime (unexpected) to patch a critical security flaw
« Reply #5 on: April 09, 2010, 03:55:34 pm »

Given that it's a wiki about DF, the next time someone enters an incorrect password, the drawbridge will be raised and the magma pumps activated.
Logged

Shades

  • Bay Watcher
    • View Profile
Re: Wiki Downtime (unexpected) to patch a critical security flaw
« Reply #6 on: April 09, 2010, 05:09:29 pm »

Given that it's a wiki about DF, the next time someone enters an incorrect password, the drawbridge will be raised and the magma pumps activated.

Worth the risk then :)
Logged
Its like playing god with sentient legos. - They Got Leader
[Dwarf Fortress] plays like a dizzyingly complex hybrid of Dungeon Keeper and The Sims, if all your little people were manic-depressive alcoholics. - tv tropes
You don't use science to show that you're right, you use science to become right. - xkcd

Max White

  • Bay Watcher
  • Still not hollowed!
    • View Profile
Re: Wiki Downtime (unexpected) to patch a critical security flaw
« Reply #7 on: April 09, 2010, 07:39:45 pm »

Oh no, were will I get answers about how to do things so they wont destroy my fortress and result in fun!

Box

  • Bay Watcher
  • [VERMINHUNTER]
    • View Profile
Re: Wiki Downtime (unexpected) to patch a critical security flaw
« Reply #8 on: April 09, 2010, 09:43:28 pm »

Oh no, were will I get answers about how to do things so they wont destroy my fortress and result in fun!

The site was up about two hours after the initial post.

So, you've been able to research how to build lavish and expensive noble housing over bottomless pits without any survivors for quite a while now.

Still no login, though.
Logged
You should come inside the box.

Then you'll know what I mean.