[IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

Results 1 to 15 of 15
  1. #1
    I'm-a ruin you, cunt! Delici0us is offline
    MemberRank
    Apr 2008 Join Date
    IsraelLocation
    731Posts

    [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Hello People!

    Earlier today Jonty posted a new release (strange, thought he had left). In his fix he claimed it improved on speed and so forth, however it was nothing more than a secret bug fix. In his previous versions he had left a critical security flaw that needed patching.

    The flaw allowed users to pass information thought GET data that would execute in a MySQL query. Trying to avoid tarnishing his ego he released a new version so he could try and ‘help’ people without them knowing.

    If you are running any version of Jontehs Uber edit you need to download this file. Failure to do so will leave your hotel open to being raped.

    For your convenience here is the new AllSeeingEye (taken from the 2.0.2 update). Just replace this on your webserver and you’ll be safe.

    allseeingeye.rar

    P.S

    Don’t even bother asking me to tell you where the exploit is, I am many things but a heartless asshole is not one of them. A handful of people know of the exploit so PLEASE UPDATE your CMS or get hacked. If you don't trust my link, feel free to download the 2.0.2 update and replace the allseeingeye from there.


  2. #2
    Valued Member Zyntix is offline
    MemberRank
    Jul 2012 Join Date
    146Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Wasn't this already releases by Jonteh?

  3. #3
    Zephyr Studios PRIZM is offline
    MemberRank
    Feb 2012 Join Date
    DenmarkLocation
    2,291Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Me no trust Jonty anymore :-/!
    But thanks! When i'm home i will set it up.

  4. #4
    I'm-a ruin you, cunt! Delici0us is offline
    MemberRank
    Apr 2008 Join Date
    IsraelLocation
    731Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Quote Originally Posted by Zyntix View Post
    Wasn't this already releases by Jonteh?
    He released it as an entire new sub-revision when in-fact the only thing that was changed was the AllSeeingEye. He only discovered the exploit today because somebody warned him. Instead of owning up to the fact it was shit, he tried to make you all think the new changes were in-there when in-fact it was just a patch.

    I know from experience, it’s easier on a hotel owner to change a non-important part of the site than to re-upload the entire site again.

    Quote Originally Posted by Lasse View Post
    Me no trust Jonty anymore :-/!
    But thanks! When i'm home i will set it up.
    I don’t think he ever knew it was there, himself. By the way, link me to your hotel :D

  5. #5
    Zephyr Studios PRIZM is offline
    MemberRank
    Feb 2012 Join Date
    DenmarkLocation
    2,291Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Quote Originally Posted by Delici0us View Post
    I don’t think he ever knew it was there, himself. By the way, link me to your hotel :D
    I am not home, i'm in Copenhagen on my iPad. I am buying Dedi or VPS and domain tomorrow maybe :)

  6. #6
    Valued Member Zyntix is offline
    MemberRank
    Jul 2012 Join Date
    146Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Thanks for this.
    Maybe I am gonna use UberCMS.
    Last edited by Zyntix; 14-07-12 at 10:00 PM.

  7. #7
    "(still lacks brains)" NoBrain is offline
    MemberRank
    Sep 2011 Join Date
    United KingdomLocation
    2,658Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    I have a feeling I know who told him, a good friend of mine who asked for his msn because he had found a critical exploit U2.

    Thanks for the patch, should of helped a lot of people!

  8. #8
    Alpha Member Caustik is offline
    MemberRank
    May 2011 Join Date
    LondonLocation
    1,837Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Thanks for the patch, good of you to release this.
    Although I think Jonty left it in their purposely (he wants to be like his idol MIRanda).

  9. #9
    I'm-a ruin you, cunt! Delici0us is offline
    MemberRank
    Apr 2008 Join Date
    IsraelLocation
    731Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Quote Originally Posted by ησвяαιη View Post
    I have a feeling I know who told him, a good friend of mine who asked for his msn because he had found a critical exploit U2.

    Thanks for the patch, should of helped a lot of people!
    A couple of people know of the exploit.

    Quote Originally Posted by Caustik View Post
    Thanks for the patch, good of you to release this.
    Although I think Jonty left it in their purposely (he wants to be like his idol MIRanda).
    I have to say, it’s quite funny that a couple of the ‘bigger’ hotels haven’t even patched there shit yet. It’s going to end so badly for them, when others find out how to do it.

  10. #10
    retired Andrew is offline
    MemberRank
    Jun 2008 Join Date
    985Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    I've known him for 5 years, he puts backdoors in everything. Now he has turned on me and treats me like shit even though i funded Zap's servers for a few months when he couldnt.

    Well done on releasing this - I host THC Hotel and found this in the apache access logs today when the customer came running to me complaining his site was deleted :(

    Respect.

  11. #11
    Old Habbo Developer AresCJ is offline
    MemberRank
    Jan 2009 Join Date
    USALocation
    1,183Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Quote Originally Posted by Andrew View Post
    I've known him for 5 years, he puts backdoors in everything. Now he has turned on me and treats me like shit even though i funded Zap's servers for a few months when he couldnt.

    Well done on releasing this - I host THC Hotel and found this in the apache access logs today when the customer came running to me complaining his site was deleted :(

    Respect.
    Hey Andrew,

    I need to speak with you, and I agree he has turned on people who really cared about him and his hotel, but it's okay.

  12. #12
    retired Andrew is offline
    MemberRank
    Jun 2008 Join Date
    985Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Quote Originally Posted by AresCJ View Post
    Hey Andrew,

    I need to speak with you, and I agree he has turned on people who really cared about him and his hotel, but it's okay.
    Feel free to PM me here, on dotXen forums or hit me up on email andrew@dotxia.com

  13. #13
    Account Upgraded | Title Enabled! salah-salah is offline
    MemberRank
    Jan 2009 Join Date
    UndergroundLocation
    716Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Very nice from you man, but can you upload the link again? Or make it public

  14. #14
    Account Upgraded | Title Enabled! SubZ is offline
    MemberRank
    Feb 2012 Join Date
    in a boatLocation
    455Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    This is why im on novacms now :)

  15. #15
    I'm-a ruin you, cunt! Delici0us is offline
    MemberRank
    Apr 2008 Join Date
    IsraelLocation
    731Posts

    Re: [IMPORTANT][CRITICAL] Uber 2.x.x - SQL Injection Fix

    Quote Originally Posted by salah-salah View Post
    Very nice from you man, but can you upload the link again? Or make it public
    I deleted the download link because you need to use this patch, http://forum.ragezone.com/f353/updat...er-2-x-862043/



Advertisement