Arlecho's ScreenConnect 6 releases
https://www.connectwise.com/company/trus...CmMugLn4qk

FYI - update your instances ASAP.  Apparent 10 scoring CVE discovered.
Reply
(Feb 19, 2024, 21:38 pm)yanki77h Wrote: Quick question i patched and installed lates version when i try to login it says invalid credentials what am i doing wrong

Make sure you put username as 'Administrator' and password as 'Administrator'. Capital 'A'.

(Feb 19, 2024, 21:38 pm)yanki77h Wrote: Quick question i patched and installed lates version when i try to login it says invalid credentials what am i doing wrong

Cheers, I upgraded.
Reply
a server of mine was hacked, hacker removed everything from my server.
hacker also added some unknow extensions
Reply
(Feb 20, 2024, 01:36 am)Dolphin34 Wrote: https://www.connectwise.com/company/trus...CmMugLn4qk

FYI - update your instances ASAP.  Apparent 10 scoring CVE discovered.

I attempted the 3.2 patcher with latest SC 23.9.8 but didn't work. i was able to pull up remote page but only the 'admin' section worked. 'access' just sits and spins

I can confirm 3.2 patcher (Thanks again Arlecho!!) works with 22.10.16976.8812 updated 2/16/24 in the archive section https://screenconnect.connectwise.com/download/archive

If you read the bottom of the CVE notice, it says they are updating some installs starting with 22.4, so can someone attempt some of the other installs that they updated 2/15 or 2/16?
Reply
(Feb 20, 2024, 11:18 am)redditisqueer Wrote:
(Feb 20, 2024, 01:36 am)Dolphin34 Wrote: https://www.connectwise.com/company/trus...CmMugLn4qk

FYI - update your instances ASAP.  Apparent 10 scoring CVE discovered.

I attempted the 3.2 patcher with latest SC 23.9.8 but didn't work. i was able to pull up remote page but only the 'admin' section worked. 'access' just sits and spins

I can confirm 3.2 patcher (Thanks again Arlecho!!) works with 22.10.16976.8812 updated 2/16/24 in the archive section https://screenconnect.connectwise.com/download/archive

If you read the bottom of the CVE notice, it says they are updating some installs starting with 22.4, so can someone attempt some of the other installs that they updated 2/15 or 2/16?

I updated from 23.8.6.8735 to 23.9.8.8811 successfully. 

I will say that I was on an older version a few months ago that had been updated multiple times. I got this issue:  able to pull up remote page but only the 'admin' section worked. 'access' just sits and spins
I migrated to a new server and reinstalled all clients. It ended up being an issue with the database file but the work had already been done, but I didn't have to worry about it.
Reply
(Feb 20, 2024, 12:10 pm)vbcoderx Wrote:
(Feb 20, 2024, 11:18 am)redditisqueer Wrote:
(Feb 20, 2024, 01:36 am)Dolphin34 Wrote: https://www.connectwise.com/company/trus...CmMugLn4qk

FYI - update your instances ASAP.  Apparent 10 scoring CVE discovered.

I attempted the 3.2 patcher with latest SC 23.9.8 but didn't work. i was able to pull up remote page but only the 'admin' section worked. 'access' just sits and spins

I can confirm 3.2 patcher (Thanks again Arlecho!!) works with 22.10.16976.8812 updated 2/16/24 in the archive section https://screenconnect.connectwise.com/download/archive

If you read the bottom of the CVE notice, it says they are updating some installs starting with 22.4, so can someone attempt some of the other installs that they updated 2/15 or 2/16?

I updated from 23.8.6.8735 to 23.9.8.8811 successfully. 

I will say that I was on an older version a few months ago that had been updated multiple times. I got this issue:  able to pull up remote page but only the 'admin' section worked. 'access' just sits and spins
I migrated to a new server and reinstalled all clients. It ended up being an issue with the database file but the work had already been done, but I didn't have to worry about it.

Can you eloborate on the database issue? I have the same issue now and I'm not ready to reinstall everything on a new server.
Reply
(Feb 20, 2024, 12:10 pm)vbcoderx Wrote:
(Feb 20, 2024, 11:18 am)redditisqueer Wrote:
(Feb 20, 2024, 01:36 am)Dolphin34 Wrote: https://www.connectwise.com/company/trus...CmMugLn4qk

FYI - update your instances ASAP.  Apparent 10 scoring CVE discovered.

I attempted the 3.2 patcher with latest SC 23.9.8 but didn't work. i was able to pull up remote page but only the 'admin' section worked. 'access' just sits and spins

I can confirm 3.2 patcher (Thanks again Arlecho!!) works with 22.10.16976.8812 updated 2/16/24 in the archive section https://screenconnect.connectwise.com/download/archive

If you read the bottom of the CVE notice, it says they are updating some installs starting with 22.4, so can someone attempt some of the other installs that they updated 2/15 or 2/16?

I updated from 23.8.6.8735 to 23.9.8.8811 successfully. 

I will say that I was on an older version a few months ago that had been updated multiple times. I got this issue:  able to pull up remote page but only the 'admin' section worked. 'access' just sits and spins
I migrated to a new server and reinstalled all clients. It ended up being an issue with the database file but the work had already been done, but I didn't have to worry about it.

I've updated probably 5 times since 2018. For others looking, there are some database cleanup tasks you can do under Admin> Database > 'purge' , 'compact', 'purge all events', 'purge session captures'. Mine are set to 200 days for Access
Reply
Everyone running an internet accessible installation is highly recommended to stay up to date, they have had some other bad CVE's in the past.

Just take a good backup (with the services stopped) and try to upgrade whenever an upgrade is available.
Also keep the plugins up to date if you are running any.
Reply
(Feb 21, 2024, 04:28 am)Arlecho Wrote: Everyone running an internet accessible installation is highly recommended to stay up to date, they have had some other bad CVE's in the past.

Just take a good backup (with the services stopped) and try to upgrade whenever an upgrade is available.
Also keep the plugins up to date if you are running any.

I'm having a problem this morning where I'm getting "Invalid credentials. Please try again." we have 2fa on all accounts.

Is anyone else having this issue? Can't log in whatsoever.
Reply
(Jul 10, 2023, 01:45 am)logiclass Wrote: Hi there!
I found myself in the same loop, constant wheel, and an errror when you click some areas saying "DateTime is not valid".
Following your instructions, and after some testing, I found several differences, more than 20, from web.config at broken install, and web.config at new clean install. So I make a procedure that, without installing in other machine, let me fix installation. I think the failure is not at sessions.db, but at database string connection and missing configuration variables, but I thought better reinstall that continue searching for a fix:
1. Stop all services at your server, copy Screenconnect folder program to other location at same server.
2. Fully uninstall Screenconnect server from control panel.
3. Install from scratch Screenconnect server from latest build and activate.
4. It's time to get your things back:
- Copy, from web.config the following data:
AsymmetricKey
InstanceIdentifierBlob
machineKey decryptionKey
* Any other customization made like TTL for sessions, URLs...
* Check that new web.config has this line, if not, add it (it prevent SC from launching setup wizard at first login)
    <add key="IsSetup" value="true" />
5. Copy content to new install, overrwiting following folders:
App_ClientConfig
App_Extensions
App_Themes
App_WebResources
6. Copy Security.db to new install from:
App_data
Launch Screenconnect and wait hosts to connect. That's all!
You'll have new installation with no bugs from now on.
Let's check and share results!
My original web.config does not have the line  InstanceIdentifierBlob,
any suggestions?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  UserHEVC Releases (Movies) UserHEVC 30 11,987 Jan 01, 2025, 14:29 pm
Last Post: ExtremelyAnoid
  RodneyYouPlonker film releases RodneyYouPlonker 315 363,150 Nov 28, 2024, 07:33 am
Last Post: RodneyYouPlonker
  KC's Releases KCTPB 27 8,056 Jul 28, 2024, 08:24 am
Last Post: KCTPB
  PHaGE Releases PHaGE 0 4,985 Aug 05, 2023, 16:30 pm
Last Post: PHaGE
  Faithwyn Releases Faithwyn 291 361,154 Jun 07, 2023, 02:08 am
Last Post: Faithwyn



Users browsing this thread: 7 Guest(s)