Search The ForumSearch   RegisterRegister  LoginLogin

AfterLogic Aurora

 AfterLogic Forum : AfterLogic Aurora
Subject Topic: 2FA security issue Post ReplyPost New Topic
Author
Message << Prev Topic | Next Topic >>
solkmaaker
Senior Member
Senior Member


Joined: 28 June 2020
Online Status: Offline
Posts: 158
Posted: 26 April 2024 at 1:13pm | IP Logged Quote solkmaaker

You are sending all 2FA data (including secret) to google when you are using google QR code generator (which does not work any more)?
Back to Top View solkmaaker's Profile Search for other posts by solkmaaker
 
Igor
AfterLogic Support
AfterLogic Support


Joined: 24 June 2008
Location: United States
Online Status: Offline
Posts: 6044
Posted: 27 April 2024 at 12:16am | IP Logged Quote Igor

We did indeed, in the new version this won't be happening. The new version is now being thoroughly tested, and will be released once the testing is done. Thank you.

--
Regards,
Igor, Afterlogic Support
Back to Top View Igor's Profile Search for other posts by Igor
 
solkmaaker
Senior Member
Senior Member


Joined: 28 June 2020
Online Status: Offline
Posts: 158
Posted: 27 April 2024 at 1:37am | IP Logged Quote solkmaaker

For those who want to get it working until improved version is available:

Replace line:
Code:
return 'https://chart.googleapis.com/chart?chs='.$width.'x'.$height.'&chld='.$level.'|0&cht=qr&chl='.$urlencoded.'';*

With:
Code:
return 'https://api.qrserver.com/v1/create-qr-code/?data='.$urlencoded.'&size='.$width.'x'.$height.'';


in file: /vendor/afterlogic/googleauthenticator/PHPGangsta/GoogleAuthenticator.php

This is not good solution, since it just sends data to another provider.
Use it at your own risk.

Igor, is the new version going to minor or major version of product?
Back to Top View solkmaaker's Profile Search for other posts by solkmaaker
 
Igor
AfterLogic Support
AfterLogic Support


Joined: 24 June 2008
Location: United States
Online Status: Offline
Posts: 6044
Posted: 27 April 2024 at 1:39am | IP Logged Quote Igor

I believe this is going to be 9.7.8 but it still may change.

And thank you for the fix!

--
Regards,
Igor, Afterlogic Support
Back to Top View Igor's Profile Search for other posts by Igor
 

If you wish to post a reply to this topic you must first login
If you are not already registered you must first register

  Post ReplyPost New Topic
Printable version Printable version

Forum Jump

Powered by Web Wiz Forums version 7.9
Copyright ©2001-2004 Web Wiz Guide