FreelanceWizard Posted September 27, 2014 Share #1 Posted September 27, 2014 Some of you may have heard of the recent "Shell Shock" exploit involving bash. That, along with other security issues in Wordpress, have led me to disable (for the time being) the Wordpress side of the Tonberry's Lantern. I'll need to determine if, based on its relatively low usage, we want to continue it or just retire it. So, if you click on the Lantern link, you'll get bounced to the forum. That's intentional. Link to comment
Coatleque Posted September 27, 2014 Share #2 Posted September 27, 2014 That's rough. We had to take pre-emptive measures yesterday due to the exploit as well for multiple clients, modifying firewall rules and locking down remote administration, etc. Strangely enough it's considered a "low priority" intrusion. Link to comment
FreelanceWizard Posted September 27, 2014 Author Share #3 Posted September 27, 2014 Yeah, the exploit is an enormous pain. If anyone was observing strange visual artifacts on the site today or nginx errors, that was due to the patches required to defend against it causing our php cache (Xcache) huge heartburn and crashing our FastCGI processes. I've changed it out to a different cache module and those issues should now be fixed. 1 Link to comment
GloryRhodes Posted September 29, 2014 Share #4 Posted September 29, 2014 I would vote to continue it, if only because my character, Spahro, was made specifically to be a reporter for it. I'd be willing to take over whatever needs to be done for it if you guys want to continue it. Link to comment
FreelanceWizard Posted September 29, 2014 Author Share #5 Posted September 29, 2014 You can still do reports -- just in the forum side, as opposed to the Wordpress side. Should the WP side come back up, it'll sync both ways like it did before. Link to comment
Faye Posted September 29, 2014 Share #6 Posted September 29, 2014 I did like the Wordpress side of it, though. Made it feel like a real newspaper. I got some good giggles at the IC slander and watching Gus and Verad squirm. ;_; Link to comment
FreelanceWizard Posted September 29, 2014 Author Share #7 Posted September 29, 2014 It's probably not going away forever, but we're many, many versions behind and my attempt to upgrade resulted in some of the key plugins exploding spectacularly, unfortunately. If I can't get the bridges working right, a lot of the value goes away. I actually have some other tricks up my sleeve for making the forum look newspaper-ish, though... Right now I'm focused on keeping us safe from shellshock (still waiting on the patch for the new vulnerabilities announced today, bash devs...), and then I'll look into fixing our Wordpress install. Link to comment
Recommended Posts
Please sign in to comment
You will be able to leave a comment after signing in
Sign In Now