Security Patch Announcement

avatar
(Edited)

isolated-3077193_960_720.jpg

Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain.

This threat did not create any risk to Steem accounts or token balances, however, our engineers quickly located the problem and fixed it. The patch was deployed to steemit's Steem nodes within 24 hours of discovering the bug. We have contacted witnesses to update their seed and witness nodes to preserve the stability of the P2P network and are in the process of informing exchanges to ensure their continuous operation. The patch doesn't require a replay; Node operators should simply update and restart steemd.

At this time, we do not believe the vulnerability is being actively exploited in any sort of attack, however, we recommend anyone running a steemd node upgrade to the newest version of stable. This can be done via docker pull steemit/steem using our provided Docker image.

steemit devs

logo-steemit@2x.png



0
0
0.000
65 comments
avatar

Wow, i am glad the probem was identified on time and fixed. Thanks for the important update

0
0
0.000
avatar

Thank you for looking after the community, the investments and the tech!

0
0
0.000
avatar

My witness, backup witness, seed and rpc nodes have all been updated now :)

0
0
0.000
avatar

That's a relief. Thanks for the info

0
0
0.000
avatar

Good to hear you are on the case. Security is a constant battle and Steemit is sure to come under attack as it gets more popular. Some of us remember a previous assault. At least we had some other options to access the blockchain.

0
0
0.000
avatar

It's like a game of whack-a-mole, isn't it? The moment you patch one hole, another one shows up...

0
0
0.000
avatar

All my servers and services have been updated with the updated code.

Good work Steem Team!

0
0
0.000
avatar

All my servers already updated.

0
0
0.000
avatar
(Edited)

Updated and running smoothly. Thank you for a quick turn around of fixing the issue.

All my witness servers are up to date.
Full STEEMING continue.

Cheers,
@yehey

0
0
0.000
avatar

Check, I update 3 hours ago my witness servers.

0
0
0.000
avatar
(Edited)

My witness is updated. Thanks.

0
0
0.000
avatar

Still an anonymous pussy tho, eh TT?

0
0
0.000
avatar

could you explain how to do this o.O!!!!!!!!!!!!!

0
0
0.000
avatar

Kudos to the engineers for a timely intervention.
We are unstoppable.

0
0
0.000
avatar

Thanks so much for keeping us informed as quickly as possible of threats to Steemd security. Much appreciated!

0
0
0.000
avatar

Ok. We totally understand that there will always be security risks. Now we can rest assured that your security team is actively in control. We shall keep steeming

0
0
0.000
avatar

It's been done for a while now. Thanks for the official post.

0
0
0.000
avatar

This isn't responsible for the network slowing down for about half the day each day, is it? Bandwidth seems to get crushed around the same hours all the time.

0
0
0.000
avatar

Already updated seed and witness nodes.
keep up the updates:P

0
0
0.000
avatar

A DoS is not so bad unless it lasts a lot. It is great to hear that it is fixed now, you are moving fast, guys, great job!

0
0
0.000
avatar

All my witness servers are updated.
Node servers used by SteemSQL and Steemitboard have been updated too

0
0
0.000
avatar

My server has been updated, thank you.

0
0
0.000
avatar

Both my main and back up witness nodes are updated and running. Thanks for the update!

0
0
0.000
avatar

All jacked up and good to go!

0
0
0.000
avatar

It's reassuring to hear that there was such a quick and robust response before this vulnerability was exploited, good job to everyone involved!

0
0
0.000
avatar

My nodes are updated.

0
0
0.000
avatar
(Edited)

Suggestion, could it be added a check, verification, who of witnesses did update and give us voters this information on that witness web page, so we voters can ask 'our' witness to do their job or we can take votes away from the ones not doing update. Could this be done?

0
0
0.000
avatar

@steemitdev Got a 32.75% Vote via @klye

Send any amount of STEEM or SBD Over 1.000 & Recieve a RANDOM @KLYE VOTE
Make sure to include the link to your post in the memo field of the transfer!
( Any amounts < 1.000 STEEM or SBD will be considered donations )
Vote power is Generated via RNG (Random Number Generator)
0
0
0.000
avatar

witness server update, up and running.

0
0
0.000
avatar

I LOVE knowing that you guys are on it. Thank you.

0
0
0.000
avatar

Good job dev, good to catch this issue before it is too late.

0
0
0.000
avatar

Kudos to all the engineers working around the clock to keep the Steem/Steemit platform safe.

In these days of volatile digital vulnerabilities, your tasks are no easy jobs! You guys and ladies rock.

0
0
0.000
avatar

How do I update my witness please?

0
0
0.000
avatar

If you are not running a witness server, then you don’t have to worry about it.

0
0
0.000
avatar

Thats a great news...at least we have wonderful engineers. Thanks for info

0
0
0.000
avatar

Congratulations @steemitdev, this post is the most rewarded post (based on pending payouts) in the last 12 hours written by a User account holder (accounts that hold between 0.1 and 1.0 Mega Vests). The total number of posts by User account holders during this period was 2609 and the total pending payments to posts in this category was $11820.44. To see the full list of highest paid posts across all accounts categories, click here.

If you do not wish to receive these messages in future, please reply stop to this comment.

0
0
0.000
avatar

Congratulations, your post received one of the top 10 most powerful upvotes in the last 12 hours. You received an upvote from @thejohalfiles valued at 281.70 SBD, based on the pending payout at the time the data was extracted.

If you do not wish to receive these messages in future, reply with the word "stop".

0
0
0.000
avatar

Any information that the system is safe in me is very encouraging.

0
0
0.000
avatar

I am glad to hear you in this case. Security is a constant battle and Steemit may be attacked as it gets more popular. Some of us remember the previous attacks. At least we have some other options to access the blockchain..

0
0
0.000
avatar

Earlier this week, steemit was informed of a potential vulnerability in steemd that could lead to a denial of service attack in both the API and P2P layers of steemd, but has absolutely no impact on the cryptography securing the Steem blockchain

Who informed?
Where informed ?
Could you refer to an issue or PR, please.

0
0
0.000
avatar

good that you guys take care of it.

0
0
0.000
avatar

Where are the release notes?
What has been changed?

0
0
0.000
avatar

is this the reason poloniex deposit is broken again?

0
0
0.000
avatar

Can you please provide URL to commit which fixes the issue? It that related to latest fc library changes?

0
0
0.000
avatar

thanks for the info!
hehehe
great help...
God bless!!!

0
0
0.000