Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, February 10, 2009

WARNING! Transfer security exploit

Last night we were tipped about a major security issue for all content creators in Secondlife.
I managed to create a copy of a non transfer item and give it to James. Once given the original permissions are reverted.
Anonymous: I was given information that results in any NO TRANSFER object now being turned into a TRANSFERABLE object. My friend was give 2 items which when in inventory are full permissions and can be given out
Our source then walked us through the simple process.
We will not tell you how it is done, or who showed us, but this is a major issue for all creators in SL.
JamesT Juno: we took a horse we had ourselves and made a copy we could sell or give away
JamesT Juno: we tried it too
JamesT Juno: we COULD reproduced it very easily

This has been reported to security@lindenlab.com and we hope they will act quickly to protect the already harassed content creators.

Hello, and thank you for your report to the Second Life security team.
This list is for reporting security issues that might compromise residents or the Second Life Grid.

We hope they do move fast before more find this method out and content creators lose more.

We will keep you updated on any replies from Linden Lab.

JamesT Juno
Dana Vanmoer
Click images to see full size

UPDATE:
Thank you for reporting this issue. I have created a security
ticket on your behalf (SEC-***) with the details that you provided.
We have been able to confirm what you reported and will be
escalating this to our development team who will ultimately deal
with the issue.

Tuesday, October 7, 2008

Eye on the Blog (even though it isn't)

I can't understand why this isn't posted on the blog - other than the already conjectured only keeping good news on there! But this is an issue everyone should be aware of and as such SHOULD be on the blog:

Today, we released an important update that improves the security of the Second Life viewer for all Residents. This update eliminates a recently discovered issue, and we’re requiring that all Residents download and install it to ensure that everyone remains secure while using Second Life. You will be prompted to download and install the update when you log-in, or you can get it from this Downloads page:http://secondlife.com/support/downloads.php

Linden Lab has released a Security Update to the Second Life viewer software today to address a potential security issue. This Security Update includes an additional security patch related to the Security Update issued on 26-Sept-2008.
Available for:Second Life Viewer 1.20.15 / 1.20.16
Second Life Release Candidate Viewer 1.21.4
Description:We recently updated the Second Life server and viewers to enhance the communications code. All transfer operations are now restricted to files that the user has expressly chosen, and specific directories that the viewer uses for transferring data.
For the safety of all Second Life users, we are releasing this updated viewer to all Residents.
Potential vulnerabilities had been identified in those message communications directed at a Second Life viewer over the previous protocol. By taking advantage of this vulnerability, while extremely difficult technically, a malicious user could potentially use the viewer to access files on the victim’s computer.
We currently have no evidence of this vulnerability ever being exploited.
This Security Update 2008-10-06 is required to continue to log-in to Second Life.
By downloading the update, you will upgrade the software on your computer to version 1.20.17:
* Second Life Release Viewer 1.20.17
For Residents who use the Release Candidate viewer, you are required to update to RC5, which also includes other latest bug fixes:
* Second Life Release Candidate Viewer 1.21 RC5
Earlier versions of Second Life (1.19.1, 1.19, and before) include the serious vulnerabilities and are no longer supported.
You will be prompted to upgrade to the latest version on your next login.
For any Residents who prefer / have been using earlier versions that do not include WindLight rendering, we have created a page on the Second Life Wiki that explains how to turn all related graphics settings to “Low,” effectively turning off WindLight in the current official viewer:
https://wiki.secondlife.com/wiki/Turn_off_WindLight_rendering
The source code for these new 1.20 and 1.21 RC5 viewers will be made available via the usual open source channels.

Again a forum thread has been created for discussion and questions this can be found HERE
On the question of non SL veiwers Prospero Linden had this to say:
Potentially other clients are vulnerable. It will depend on the details of those clients. We will have a new open source code drop soon with the fixes in it; anybody who has distributed a client based off of that open source code drop would be strongly advised to apply the patch. You will need to contact the people who build and maintain the clients other than the official SL viewers to get patched versions.If you *must* use a vulnerable client-- and we strongly recommend against this-- connect only to SL or to trusted OpenSim sites; do not connect to random OpenSim servers unless they are run by people whom you specifically trust. You must also disable your streams entirely in preferences (both audio and media), to protect your IP address.Please do see the wiki page on adjusting the settings for the 1.20 client. I know I found myself that I actually did better with Windlight on a very low-spec machine. I know that doesn't mean necessarily everybody else will, but give it a try.

Hopefully the spate of fixes will now slow down and LL can concentrate on making this client stable, but the questions must be asked - how long has this security issue been an issue? Is this a way to scare everyone into using the official client? This last is pure speculation and probably unjustified as we have all seen the rush to update in the last couple of weeks showing that something has been going on behind the scenes, so it is to be hoped that this hole has now been plugged and we can all log in securely.
Dana

Thursday, February 28, 2008

Violence erupts in Ghul Federal Prison

To read about this latest violent episode with the walls of Ghul Federal Prison click here.

Friday, August 3, 2007

Handy Hints for You and Your Property

SINCE GRIEFING seems to be the number one past time of pesky little pubescent twerps, here are some handy hints to ensure the rest of get to use our time more creatively and pleasantly this weekend.

PERSONAL:

1. Get yourself a personal protection device. Rather than me recommend one, ask people you know what they use. Mysti Tool is one I’ve heard a lot of people talk about. (We will be running a story on personal security gadgets by R..J. Dumart in a future edition).

2. A personal bug device is also useful if you want to know if someone is bugging you or your property to listen in on your private conversations. I believe Oblijan Proost makes one of these.

3. There are also radar devices so you can see who is in your area. One I’ve been told about is Crystal Babeli radar.

4. Do not accept anything - objects particularly - from anyone you don’t know. (Anything which can contain a script is particularly dangerous).

5. Under Edit - Preferences, make sure you select 'Log Conversations and IMs' - this way you will have a record of who said what in case of a dispute.

6. If you are being personally attacked, SIT DOWN on an object (you can’t be pushed if you are sitting down) and write down the name of your attacker and the location.

7. There are personal protection services about but of the several I contacted for information, Mustafaaab Connoisseur of Defender Servants of THE FORCE was the most helpful. (He offered the above advice of sitting down).

8. If you are being pestered by noise, mute the origin of that noise ot turn your sound off.

9. Change your password often and use a combination of letters and numbers to give it a high security rating.

10. Make sure that the ATMs you use in SL are real and that you trust the company that is behind them.

PROPERTY:

1. You can protect things in your inventory by storing them in something like Toneless Tomba’s ‘Inventory Box Organiser’, but there are sure to be others out there. This also means you can store items outside your inventory. (Be careful with 'no copy' items though).

(Reducing the number of items in your inventory is good because keeping it under 4,000 items reduces inventory loss.

2. Don’t invite just anybody in your land group. Make sure you know who they are - them having an account with SL goes part of this way.

3. When you place an object on your land, make sure it is not set at ‘For Sale’. (Electric Sheep has a new system which ‘scrapes’ everything in Second Life and ‘advertises’ objects that are for sale (even that new lounge chair you rezzed in your own home).

4. Make sure that you don’t allow any public building or objects to be rezzed on your land, by anyone other than yourself or people you trust.

5. If you REALLY want to make sure your home is safe from intrusion, make it inaccessible to anyone who does not have any payment information available on their profile

6. Land owners can join www.slbanlink.com if they want to join up with other landowners who have banned people from their land. This organisation ensures that if you ban someone, other landowners will also be advised that this person has been a nuisance elsewhere.

7. Rat Thing agent profiler, which is produced by Ng Security profiles avatar’s by age and payment info, so this goes some way to tracking troublesome avatars.

This list of handy hints is by no means exhaustive or in order of priority, but it will go part of the way to making sure you and your property are protected as much as they can be in this 'Wild West' land of SL.

In the course of doing some research for this article, I searched ‘security’ on Second Life and was surprised to see security groups offering to undertake “... black jobs that can’t be listed here” and “assassinations”! lol

I couldn’t help but think this was the 21st Century version of ‘cowboys and indians’ or ‘cops and robbers’.

Enjoy your weekend!