03/17/2008 - Smarty has recently found and fixed a security vulnerability.
It has come to our attention that a securtiy vulnerability has recently been found and fixed within Smarty where user-supplied input is not properly sanitized. This is due to Smarty not properly handling modifier security within the Smarty Templating Engine. This is not an issue with the NATS code, but with Smarty itself. You can find out more about this issue here: http://www.securityfocus.com/bid/28105
Although admin access would be needed in order to take advantage of this exploit, it is highly recommended that you upgrade to the latest version of Smarty (2.6.19) in order to be as secure as possible. If you need help with this, please place a ticket in our support system and a TMM technical support specialist will be happy to assist you.
02/11/2008 - Netbilling and NBnative may have missing credits
It has come to our attention recently that when Netbilling posts credit transactions for NATS, the post sometimes did not include the original transaction id that the credit correlates to. Without this id, NATS cannot process the credit transaction correctly.
We have been working actively with Netbilling, and we have resolved the issue. Netbilling now passes along information that allows NATS to identify a credit transaction with a previous transaction, and we have modified NATS to account for the recent changes.
As a result, anyone who uses Netbilling or NBnative may have missing credit transactions.
If you currently use Netbilling or NBnative, we ask that you contact us via our client support system (http://clients.toomuchmedia.com) so that we may provide you with proper updates and ensure that your transaction records are accurate and up-to-date.
02/11/2008 - Too Much Media has changed our office IP to 96.56.200.10
We recommend to all of our clients to IP restrict their NATS admin and the access to their servers. We have recently changed our office IP from 67.84.12.95 to the new IP: 96.56.200.10
If you have either of these IP restrictions in place, please remove our old IP and put our new office IP in its place.
12/23/2007 - Details on recent NATS security issue.
We have become aware of a security issue involving admin passwords we maintain for support of our clients. As a precaution, we have added a few features to aid in the security of NATS. Please submit a support ticket at your earliest convenience so you may be updated to take advantage of these new features. This is not an exploit of NATS and this update does not patch any holes. It adds new security features.
There are also a few steps you can take in the mean time to make your NATS install more secure. Remove admin access from all accounts that you do not wish to access your admin area. This should include the TMM admin account used for support as we will no longer be maintaining this account. We have already initiated a password change for this account for you and we have not kept the new password. You may fully delete this account if you wish. Change the passwords of all other admin accounts. Setup the ADMIN IP restrictions in your NATS configuration. There are instructions for this setup found here: http://kb.toomuchmedia.com/idx/0/676/ If you have any questions about any of these actions please submit a ticket so we may assist you.
Once you have been updated to the latest version of NATS, you may implement the new admin action logging feature. This will allow you to track all requests made to the admin pages of your NATS install. The setup instructions for this can be found here: http://kb.toomuchmedia.com/idx/0/677/
If you have any questions or concerns, please feel free to submit a support ticket.