Advertisement

EVE Online's new forum is back online

EVE title image

Back in April, EVE Online received a brand-new forum with a revamped search tool, the ability to "like" posts, and other useful features. Unfortunately, players quickly found several serious security problems in the new forum software, including the ability to inject arbitrary HTML (but not script) into any thread via a modified forum signature.

It also became known that the forum was a modified version of open source software Yet Another Forum, with the authentication system tied to CCP's own login service. A cookie exploit was discovered in this login system shortly after the forums went online, allowing users to post as anyone they wanted -- even as developers. The new forum was temporarily disabled pending a security review and the old one reactivated.

After a complete security revamp and a period of rigorous testing, the new forum returned to service today. This forum is tied into CCP's web platform EVE Gate, which provides quick access to your character's evemails while not in the game and has integrated social networking features. The old forum will be officially decommissioned on Friday, September 9th and left as a permanent archive.

[UPDATE: We've been informed that the previous injection exploit involved only HTML and not script. The post has been modified accordingly.]