Security Patch Announcement

in steem •  9 months ago

isolated-3077193_960_720.jpg

Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain.

This threat did not create any risk to Steem accounts or token balances, however, our engineers quickly located the problem and fixed it. The patch was deployed to steemit's Steem nodes within 24 hours of discovering the bug. We have contacted witnesses to update their seed and witness nodes to preserve the stability of the P2P network and are in the process of informing exchanges to ensure their continuous operation. The patch doesn't require a replay; Node operators should simply update and restart steemd.

At this time, we do not believe the vulnerability is being actively exploited in any sort of attack, however, we recommend anyone running a steemd node upgrade to the newest version of stable. This can be done via docker pull steemit/steem using our provided Docker image.

steemit devs

logo-steemit@2x.png

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

How do I update my witness please?

·

If you are not running a witness server, then you don’t have to worry about it.

Good to hear you are on the case. Security is a constant battle and Steemit is sure to come under attack as it gets more popular. Some of us remember a previous assault. At least we had some other options to access the blockchain.

·

It's like a game of whack-a-mole, isn't it? The moment you patch one hole, another one shows up...

@Curie 's Witness/Seed has been updated, Cheers.

·

Dear @ausbitbank;

I need any help to stop @grumpycat hurting innocent people.
We have to show that Steemit is bigger than any bully who is trying to impose his own rules by using his high SP on innocent people.
The post below is the summary of the situation :
https://steemit.com/life/@firedream/stop-the-grumpycat
Thank you for any help to stop the actions of @grumpycat.

Best Regards.

FD.

All my servers and services have been updated with the updated code.

Good work Steem Team!

Check, I update 3 hours ago my witness servers.

All my servers already updated.

Updated and running smoothly. Thank you for a quick turn around of fixing the issue.

All my witness servers are up to date.
Full STEEMING continue.

Cheers,
@yehey

Good job dev, good to catch this issue before it is too late.

Way to go, guys!

How can we explore the next steemit updates? I would like to know what you guys working at in the near future...

·
·
·

Thanks!!

Blocktrades' witness node was updated.

good that you guys take care of it.

All my witness servers are updated.
Node servers used by SteemSQL and Steemitboard have been updated too

Witness updated!

Already updated seed and witness nodes.
keep up the updates:P

All jacked up and good to go!

Updated.

Both my main and back up witness nodes are updated and running. Thanks for the update!

witness server update, up and running.

My nodes are updated.

updated

It's been done for a while now. Thanks for the official post.

My server has been updated, thank you.

Cryptwo Witness node has been all updated

Wow, i am glad the probem was identified on time and fixed. Thanks for the important update

Thanks for sharing this information.

Good thing your on top of things guys. Good job

Thank you for looking after the community, the investments and the tech!

Thanks so much for keeping us informed as quickly as possible of threats to Steemd security. Much appreciated!

Ok. We totally understand that there will always be security risks. Now we can rest assured that your security team is actively in control. We shall keep steeming

It's reassuring to hear that there was such a quick and robust response before this vulnerability was exploited, good job to everyone involved!

That's a relief. Thanks for the info

This isn't responsible for the network slowing down for about half the day each day, is it? Bandwidth seems to get crushed around the same hours all the time.

·

Bandwidth is unrelated.

Suggestion, could it be added a check, verification, who of witnesses did update and give us voters this information on that witness web page, so we voters can ask 'our' witness to do their job or we can take votes away from the ones not doing update. Could this be done?

@steemitdev Got a 32.75% Vote via @klye

Send any amount of STEEM or SBD Over 1.000 & Recieve a RANDOM @KLYE VOTE
Make sure to include the link to your post in the memo field of the transfer!
( Any amounts < 1.000 STEEM or SBD will be considered donations )
Vote power is Generated via RNG (Random Number Generator)

thanks for the info!
hehehe
great help...
God bless!!!

wow great news.

could you explain how to do this o.O!!!!!!!!!!!!!

I LOVE knowing that you guys are on it. Thank you.

A DoS is not so bad unless it lasts a lot. It is great to hear that it is fixed now, you are moving fast, guys, great job!

Kudos to all the engineers working around the clock to keep the Steem/Steemit platform safe.

In these days of volatile digital vulnerabilities, your tasks are no easy jobs! You guys and ladies rock.

good job guys.

Thats a great news...at least we have wonderful engineers. Thanks for info

Congratulations @steemitdev, this post is the most rewarded post (based on pending payouts) in the last 12 hours written by a User account holder (accounts that hold between 0.1 and 1.0 Mega Vests). The total number of posts by User account holders during this period was 2609 and the total pending payments to posts in this category was $11820.44. To see the full list of highest paid posts across all accounts categories, click here.

If you do not wish to receive these messages in future, please reply stop to this comment.

Congratulations, your post received one of the top 10 most powerful upvotes in the last 12 hours. You received an upvote from @thejohalfiles valued at 281.70 SBD, based on the pending payout at the time the data was extracted.

If you do not wish to receive these messages in future, reply with the word "stop".

Any information that the system is safe in me is very encouraging.

I am glad to hear you in this case. Security is a constant battle and Steemit may be attacked as it gets more popular. Some of us remember the previous attacks. At least we have some other options to access the blockchain..

Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain

Who informed?
Where informed ?
Could you refer to an issue or PR, please.

why did they decline ur payment?

My witness node is now compliant with the update as per @someguy123 revision he posted for steem-in-abox

Kudos to the engineers for a timely intervention.
We are unstoppable.

Where are the release notes?
What has been changed?

is this the reason poloniex deposit is broken again?

Can you please provide URL to commit which fixes the issue? It that related to latest fc library changes?

Please visit this link
i am sure changing your mind
https://steemit.com/respect/@shanto24/great-steemit-user-2-18

Thank you..👌