Security Patch Announcement

in #steem6 years ago (edited)

isolated-3077193_960_720.jpg

Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain.

This threat did not create any risk to Steem accounts or token balances, however, our engineers quickly located the problem and fixed it. The patch was deployed to steemit's Steem nodes within 24 hours of discovering the bug. We have contacted witnesses to update their seed and witness nodes to preserve the stability of the P2P network and are in the process of informing exchanges to ensure their continuous operation. The patch doesn't require a replay; Node operators should simply update and restart steemd.

At this time, we do not believe the vulnerability is being actively exploited in any sort of attack, however, we recommend anyone running a steemd node upgrade to the newest version of stable. This can be done via docker pull steemit/steem using our provided Docker image.

steemit devs

logo-steemit@2x.png

Sort:  
There are 2 pages
Pages

How do I update my witness please?

If you are not running a witness server, then you don’t have to worry about it.

Good to hear you are on the case. Security is a constant battle and Steemit is sure to come under attack as it gets more popular. Some of us remember a previous assault. At least we had some other options to access the blockchain.

It's like a game of whack-a-mole, isn't it? The moment you patch one hole, another one shows up...

@Curie 's Witness/Seed has been updated, Cheers.

My witness, backup witness, seed and rpc nodes have all been updated now :)

Dear @ausbitbank;

I need any help to stop @grumpycat hurting innocent people.
We have to show that Steemit is bigger than any bully who is trying to impose his own rules by using his high SP on innocent people.
The post below is the summary of the situation :
https://steemit.com/life/@firedream/stop-the-grumpycat
Thank you for any help to stop the actions of @grumpycat.

Best Regards.

FD.

Check, I update 3 hours ago my witness servers.

Updated and running smoothly. Thank you for a quick turn around of fixing the issue.

All my witness servers are up to date.
Full STEEMING continue.

Cheers,
@yehey

Good job dev, good to catch this issue before it is too late.

Way to go, guys!

How can we explore the next steemit updates? I would like to know what you guys working at in the near future...

Thanks!!

Blocktrades' witness node was updated.

good that you guys take care of it.

Witness updated!

Already updated seed and witness nodes.
keep up the updates:P

All my witness servers are updated.
Node servers used by SteemSQL and Steemitboard have been updated too

All jacked up and good to go!

updated

Both my main and back up witness nodes are updated and running. Thanks for the update!

My nodes are updated.

Updated.

It's been done for a while now. Thanks for the official post.

witness server update, up and running.

@steemitdev Got a 32.75% Vote via @klye

Send any amount of STEEM or SBD Over 1.000 & Recieve a RANDOM @KLYE VOTE
Make sure to include the link to your post in the memo field of the transfer!
( Any amounts < 1.000 STEEM or SBD will be considered donations )
Vote power is Generated via RNG (Random Number Generator)

It's reassuring to hear that there was such a quick and robust response before this vulnerability was exploited, good job to everyone involved!

My server has been updated, thank you.

Thank you for looking after the community, the investments and the tech!

That's a relief. Thanks for the info

I LOVE knowing that you guys are on it. Thank you.

Thats a great news...at least we have wonderful engineers. Thanks for info

Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain

Who informed?
Where informed ?
Could you refer to an issue or PR, please.

Wow, i am glad the probem was identified on time and fixed. Thanks for the important update

could you explain how to do this o.O!!!!!!!!!!!!!

Kudos to the engineers for a timely intervention.
We are unstoppable.

Thanks so much for keeping us informed as quickly as possible of threats to Steemd security. Much appreciated!

Ok. We totally understand that there will always be security risks. Now we can rest assured that your security team is actively in control. We shall keep steeming

This isn't responsible for the network slowing down for about half the day each day, is it? Bandwidth seems to get crushed around the same hours all the time.

Bandwidth is unrelated.

A DoS is not so bad unless it lasts a lot. It is great to hear that it is fixed now, you are moving fast, guys, great job!

good job guys.

Cryptwo Witness node has been all updated

Thanks for sharing this information.

Good thing your on top of things guys. Good job

Suggestion, could it be added a check, verification, who of witnesses did update and give us voters this information on that witness web page, so we voters can ask 'our' witness to do their job or we can take votes away from the ones not doing update. Could this be done?

Kudos to all the engineers working around the clock to keep the Steem/Steemit platform safe.

In these days of volatile digital vulnerabilities, your tasks are no easy jobs! You guys and ladies rock.

Congratulations @steemitdev, this post is the most rewarded post (based on pending payouts) in the last 12 hours written by a User account holder (accounts that hold between 0.1 and 1.0 Mega Vests). The total number of posts by User account holders during this period was 2609 and the total pending payments to posts in this category was $11820.44. To see the full list of highest paid posts across all accounts categories, click here.

If you do not wish to receive these messages in future, please reply stop to this comment.

Congratulations, your post received one of the top 10 most powerful upvotes in the last 12 hours. You received an upvote from @thejohalfiles valued at 281.70 SBD, based on the pending payout at the time the data was extracted.

If you do not wish to receive these messages in future, reply with the word "stop".

Any information that the system is safe in me is very encouraging.

There are 2 pages
Pages