It is currently Fri Apr 19, 2024 2:57 am

All times are UTC - 8 hours [ DST ]




Post new topic Reply to topic  [ 45 posts ]  Go to page Previous  1, 2, 3
Author Message
Offline
 Post subject: Re: EidoGo Security Vulnerability Alert
Post #41 Posted: Thu Apr 28, 2016 1:34 pm 
Lives in gote

Posts: 422
Liked others: 269
Was liked: 129
KGS: captslow
Online playing schedule: irregular and by appointment
Curiosity kills the cat.
I just logged in after my last post. My account was not yet deleted.

I now read it has been properly addressed in the meantime.
Thank you all. I can now again spend numerous hours browsing this forum again :wink:

(And it is just a coincidence that my virusscanner intercepted a malicious mail just two minutes ago.)

Top
 Profile  
 
Offline
 Post subject: Re: EidoGo Security Vulnerability Alert
Post #42 Posted: Sat Apr 30, 2016 5:48 am 
Lives with ko

Posts: 160
Liked others: 127
Was liked: 175
Rank: 4d
KGS: KOCMOHABT
Offtop: If admins of this site would like to embed my board here just pm me [url]kocmohabt.baduk@gmail.com[/url]. As example of embedding http://gokifu.com/s/pb.y. Thank you.

Top
 Profile  
 
Offline
 Post subject: Re: EidoGo Security Vulnerability Alert
Post #43 Posted: Tue May 03, 2016 5:19 pm 
Beginner

Posts: 5
Liked others: 0
Was liked: 0
Check out the site http://go.ba.net based on eidogo code but with the xss security vulnerability patched.

Boards can be embedded like this

<iframe src=http://go.ba.net/playgo/go-embed.html?sgf=example.sgf>
</iframe>

Top
 Profile  
 
Offline
 Post subject: Re: EidoGo Security Vulnerability Alert
Post #44 Posted: Tue May 03, 2016 7:17 pm 
Dies with sente

Posts: 82
Liked others: 19
Was liked: 46
banet wrote:
Check out the site http://go.ba.net based on eidogo code but with the xss security vulnerability patched.


In your other announcement thread, you said that the vulnerabilities were only "mostly" patched (whatever that means), and based on a quick look, it appears that your javascript is still using eval in a few places to apparently do JSON parsing. Are you sure that you've patched up the XSS vulnerabilities properly?

Also, there seems to be little purpose to linking to your site via an iframe just to use something that is essentially EidoGo, which is already integrated into L19x19. In fact, this could create further security problems, if your site does something malicious or contains unfixed security issues that allows others to do malicious things.

Since your site is based on EidoGo, which is licensed under AGPL requiring derivative works to be open-source under AGPL as well, have you made your modified source code available somewhere (which would be required to comply with the AGPL)?

Top
 Profile  
 
Offline
 Post subject: Re: EidoGo Security Vulnerability Alert
Post #45 Posted: Tue May 03, 2016 11:51 pm 
Beginner

Posts: 5
Liked others: 0
Was liked: 0
We used the eidogo ui javascript only. We run a different database, and added the SGF xss safety filter at the db level.

Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 45 posts ]  Go to page Previous  1, 2, 3

All times are UTC - 8 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group