Security Patch Announcement

in steem •  last year

isolated-3077193_960_720.jpg

Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain.

This threat did not create any risk to Steem accounts or token balances, however, our engineers quickly located the problem and fixed it. The patch was deployed to steemit's Steem nodes within 24 hours of discovering the bug. We have contacted witnesses to update their seed and witness nodes to preserve the stability of the P2P network and are in the process of informing exchanges to ensure their continuous operation. The patch doesn't require a replay; Node operators should simply update and restart steemd.

At this time, we do not believe the vulnerability is being actively exploited in any sort of attack, however, we recommend anyone running a steemd node upgrade to the newest version of stable. This can be done via docker pull steemit/steem using our provided Docker image.

steemit devs

logo-steemit@2x.png

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

How do I update my witness please?

·

If you are not running a witness server, then you don’t have to worry about it.

Good to hear you are on the case. Security is a constant battle and Steemit is sure to come under attack as it gets more popular. Some of us remember a previous assault. At least we had some other options to access the blockchain.

·

It's like a game of whack-a-mole, isn't it? The moment you patch one hole, another one shows up...

@Curie 's Witness/Seed has been updated, Cheers.

·

Dear @ausbitbank;

I need any help to stop @grumpycat hurting innocent people.
We have to show that Steemit is bigger than any bully who is trying to impose his own rules by using his high SP on innocent people.
The post below is the summary of the situation :
https://steemit.com/life/@firedream/stop-the-grumpycat
Thank you for any help to stop the actions of @grumpycat.

Best Regards.

FD.

All my servers and services have been updated with the updated code.

Good work Steem Team!

Check, I update 3 hours ago my witness servers.

All my servers already updated.

Updated and running smoothly. Thank you for a quick turn around of fixing the issue.

All my witness servers are up to date.
Full STEEMING continue.

Cheers,
@yehey

Good job dev, good to catch this issue before it is too late.

Way to go, guys!

How can we explore the next steemit updates? I would like to know what you guys working at in the near future...

·
·
·

Thanks!!

Blocktrades' witness node was updated.

good that you guys take care of it.

Witness updated!

Already updated seed and witness nodes.
keep up the updates:P

All my witness servers are updated.
Node servers used by SteemSQL and Steemitboard have been updated too

All jacked up and good to go!

updated

Both my main and back up witness nodes are updated and running. Thanks for the update!

My nodes are updated.

Updated.

It's been done for a while now. Thanks for the official post.

witness server update, up and running.

@steemitdev Got a 32.75% Vote via @klye

Send any amount of STEEM or SBD Over 1.000 & Recieve a RANDOM @KLYE VOTE
Make sure to include the link to your post in the memo field of the transfer!
( Any amounts < 1.000 STEEM or SBD will be considered donations )
Vote power is Generated via RNG (Random Number Generator)

wow great news.

It's reassuring to hear that there was such a quick and robust response before this vulnerability was exploited, good job to everyone involved!

My server has been updated, thank you.

why did they decline ur payment?

I LOVE knowing that you guys are on it. Thank you.

That's a relief. Thanks for the info

Thats a great news...at least we have wonderful engineers. Thanks for info

Thank you for looking after the community, the investments and the tech!

Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain

Who informed?
Where informed ?
Could you refer to an issue or PR, please.

A DoS is not so bad unless it lasts a lot. It is great to hear that it is fixed now, you are moving fast, guys, great job!

Suggestion, could it be added a check, verification, who of witnesses did update and give us voters this information on that witness web page, so we voters can ask 'our' witness to do their job or we can take votes away from the ones not doing update. Could this be done?

good job guys.

Thanks so much for keeping us informed as quickly as possible of threats to Steemd security. Much appreciated!

Cryptwo Witness node has been all updated

Ok. We totally understand that there will always be security risks. Now we can rest assured that your security team is actively in control. We shall keep steeming

Thanks for sharing this information.

Good thing your on top of things guys. Good job

Kudos to all the engineers working around the clock to keep the Steem/Steemit platform safe.

In these days of volatile digital vulnerabilities, your tasks are no easy jobs! You guys and ladies rock.

Wow, i am glad the probem was identified on time and fixed. Thanks for the important update

This isn't responsible for the network slowing down for about half the day each day, is it? Bandwidth seems to get crushed around the same hours all the time.

·

Bandwidth is unrelated.

Congratulations @steemitdev, this post is the most rewarded post (based on pending payouts) in the last 12 hours written by a User account holder (accounts that hold between 0.1 and 1.0 Mega Vests). The total number of posts by User account holders during this period was 2609 and the total pending payments to posts in this category was $11820.44. To see the full list of highest paid posts across all accounts categories, click here.

If you do not wish to receive these messages in future, please reply stop to this comment.

Congratulations, your post received one of the top 10 most powerful upvotes in the last 12 hours. You received an upvote from @thejohalfiles valued at 281.70 SBD, based on the pending payout at the time the data was extracted.

If you do not wish to receive these messages in future, reply with the word "stop".

Any information that the system is safe in me is very encouraging.

I am glad to hear you in this case. Security is a constant battle and Steemit may be attacked as it gets more popular. Some of us remember the previous attacks. At least we have some other options to access the blockchain..

could you explain how to do this o.O!!!!!!!!!!!!!

Kudos to the engineers for a timely intervention.
We are unstoppable.

My witness node is now compliant with the update as per @someguy123 revision he posted for steem-in-abox

thanks for the info!
hehehe
great help...
God bless!!!

Where are the release notes?
What has been changed?

is this the reason poloniex deposit is broken again?

Can you please provide URL to commit which fixes the issue? It that related to latest fc library changes?

Please visit this link
i am sure changing your mind
https://steemit.com/respect/@shanto24/great-steemit-user-2-18

Thank you..👌