Back

Dev Tracker

A chronological record of developer forum posts and site updates.
1 2 3 4 5 6 7 ... 20 21
Update & Summary: Emergency Maintenance
Apr 01, 2023, 09:00:11
At approximately 14:00 Server Time on Friday, March 31 the engineering team was alerted to an individual probing for XSS (Cross-Site Scripting) weaknesses by pasting HTML script tags in various text fields on the site, some player-facing and some only visible to staff. Out of an abundance of caution we put the site into maintenance so we could evaluate the situation.

During the maintenance period, we reviewed the attacker's activity, focusing in particular on what fields the attacker typed script tags into. Then, we reviewed what pages (player-facing and staff-facing) display the contents of those text fields, whether those pages are properly escaping the text in question to prevent XSS vulnerabilities, and whether anyone viewed those pages while they potentially contained text content from this attacker.

Because it is part of our development practices to evaluate all new and revamped/refactored features for XSS vulnerabilities, we could not find issues in player-facing areas such as Forums, Private messages, Clan Info, or Dragon Biographies, or our primary staff-facing tools. We did identify and correct issues in some of our rarely used staff-facing tools that were not used while this attacker was active. Additionally, we identified some extremely old code that had potential issues and corrected them, but these areas are not areas where content entered by the attacker could have been viewed by another player or staff.

While XSS has a broad scope, one of the major concerns in any XSS attack is the potential that session cookies—tokens stored in your browser that "prove" that you are a particular logged-in user—could be stolen by an attacker, allowing them to essentially be "logged in" as you without knowing your password. Our session cookies are all set to use the "HttpOnly" flag which means that scripts categorically cannot access them. Barring vulnerabilities in browsers themselves, we do not believe session cookies were immediately at risk. Nonetheless, we revoked all outstanding staff and volunteer moderator sessions early on in our investigation as a safety measure.

Again, while we do not believe player sessions were at risk for the above reasons, if you wish to revoke all outstanding sessions for your account, including those for browsers/devices other than the one you are currently interacting with the site with, you can change your password either via Account Settings or the Forgot Password feature.

In addition to reviewing our existing code, we also looked into ways to detect and block this sort of behavior proactively. We have made some initial changes in that area and we are going to continue to improve our security posture by adding additional layers of protection, detection and alerting. Please bear with us as some of these changes may introduce minor bugs while we fine-tune things.

In summary, at present we believe this individual was at the stage of probing for vulnerabilities, and we used the maintenance period to review and strengthen our protections against this sort of attack. We do not have reason to believe the attacker accomplished anything of major concern at this point.

If you believe you have found a vulnerability of any kind anywhere on Flight Rising, please disclose it to us privately using Contact Us right away.

Thank you for your patience and understanding.
Status Update
Jan 30, 2023, 06:58:35
Site Status | By Mutron
Maintenance has concluded. Some pages may load slowly as players return to the site. We will be monitoring throughout the day.
Status Update
Dec 21, 2022, 22:36:27
Site Status | By Mutron
We believe we have addressed the issue affecting Auction House and other search features, as well as causing general site slowness. We are currently monitoring.
Status Update
Oct 17, 2022, 10:31:57
Site Status | By Mutron
Maintenance has concluded. Some pages may load slowly as players return to the site. We will be monitoring throughout the day.
Status Update
Sep 30, 2022, 12:02:50
Site Status | By Mutron
We will be performing scheduled maintenance from 06:00 - 07:00 Server Time on Monday, October 3 to launch the refactored Clan Profile. During this period Flight Rising will be unavailable.
Status Update
Sep 09, 2022, 11:32:15
Site Status | By Mutron
Maintenance has concluded. Some pages may load slowly as players return to the site. We will be monitoring throughout the day.
Status Update
Aug 10, 2022, 05:51:41
Site Status | By Mutron
Maintenance has concluded. Some pages may load slowly as players return to the site. We will be monitoring throughout the day.
Thundercrack Carnivale 2022
Jul 24, 2022, 10:19:26
Forum Post | Announcements & News | By Mutron
@Fennelroot Yes, the elemental festival currency items now drop in all elements! The chests still drop in the festival's specific element.
Gathering turns?
Jul 24, 2022, 10:18:04
Forum Post | Bug Report Forums | By Mutron
@Fruitgummysnake We granted an additional 30 (15+15) gathering turns, rather than setting them to 45, so depending on your well-fed bonus and your element's dominance position you could end up with between 40 and 48 turns. Hope that helps!
Turns not all used properly
Jul 24, 2022, 07:52:55
Forum Post | Bug Report Forums | By Mutron
Hello @DiamondDustSky -- We checked our results and it looks like all of the turns were correctly used, although I'm sorry you could not see what you received! I suspect that what happened is that the new Gathering refactor page allows you to double click the button, which causes 2 turns to be used but only 1 result to be displayed. So if you are rapidly clicking the button turns may appear to drop fast and you will not see the results properly.

We will look into correcting this so you can't accidentally skip seeing the results of a turn.
fest chests not in digging in game datab
Jul 24, 2022, 07:16:45
Forum Post | Bug Report Forums | By Mutron
Hello all, we have checked and confirmed that the festival chests are correctly configured and are dropping in Lightning Digging, there is just an issue with the Game Database that prevents them from displaying because they are not permanent Gathering drops.
Extra turns not distributed
Jul 24, 2022, 07:13:19
Forum Post | Bug Report Forums | By Mutron
@TheHunterZ Yes, we awarded +15 once when we discovered Charged Sprockets weren't dropping, then another +15 when we discovered an issue had caused the drop rate to be set incorrectly.
Extra turns not distributed
Jul 24, 2022, 07:10:05
Forum Post | Bug Report Forums | By Mutron
@Peculiarity Looking at our records, it looks like you used your first 15 turns of the day before Thundercrack began, several hours ago, and then 15 (the first awarded 15) after it began. Sorry for the confusion!

EDIT: For clarity's sake, since I started typing the original post, the second 15 was also used, so our records show a total of 45 turns used since rollover.
Status Update
Jul 24, 2022, 06:35:03
Site Status | By Mutron
All players have been granted an additional 15 gathering turns due to Charged Sprockets not dropping in Gathering for a brief period, and an additional 15 on top of that due to an error with the drop rate.
Status Update
Jul 24, 2022, 06:21:10
Site Status | By Mutron
Maintenance is complete! Thundercrack Carnivale will be extended by half an hour, until 06:30 Server Time on July 31, as a result of the extended maintenance.
Status Update
Jul 21, 2022, 10:59:52
Site Status | By Mutron
We will be performing scheduled maintenance from 05:30 - 06:00 Server Time on Sunday, July 24 immediately prior to Thundercrack Carnivale. During this period Flight Rising will be unavailable.
Flash Sale in Marketplace on wrong tab
Jul 16, 2022, 09:00:03
Forum Post | Bug Report Forums | By Mutron
This issue should be fixed now! Thank you for the report.
Status Update
Jul 05, 2022, 08:46:37
Site Status | By Mutron
XP bars in Gathering, Baldwin's Bubbling Brew and Arlo's Ancient Artifacts have had minor visual updates to more closely match each other.
Skin/accent chests in scavenging?
Jun 28, 2022, 09:28:30
Forum Post | Bug Report Forums | By Mutron
We have updated the skin chests to drop in Digging in order to match the description given in the announcement post for the festival. We apologize for the confusion!
Status Update
Jun 28, 2022, 09:21:12
Site Status | By Mutron
Brightshine Jubilee skin chests were incorrectly dropping in Scavenging. This has been corrected so that they now drop in Digging.
Bug/oversight: Gathering exp at max
Jun 22, 2022, 06:59:36
Forum Post | Bug Report Forums | By Mutron
@RedWillia While the old Gathering implementation displayed it this way as well, you are correct that it is inconsistent with other features, I will bring it up with the wider team!
Status Update
Jun 21, 2022, 09:24:09
Site Status | By Mutron
Maintenance to deploy the Gathering Refactor has concluded. Please see this thread for more information about what's changed!
Status Update
Jun 13, 2022, 10:06:27
Site Status | By Mutron
Maintenance has concluded. Some pages may load slowly as players return to the site. We will be monitoring throughout the day.
Status Update
May 19, 2022, 14:13:31
Site Status | By Mutron
Today's maintenance has concluded. Some pages may load slowly as players return to the site.
Status Update
Mar 11, 2022, 15:46:59
Site Status | By Mutron
We believe we have refunded the small number of credit card gem purchases that were affected by today's issue. As always, if you find you are are charged but do not receive your gems within 24 hours, please submit a ticket using Contact Us.
Status Update
Mar 11, 2022, 14:59:14
Site Status | By Mutron
After discussion, we will be refunding certain credit card gem purchases which resulted in players being charged but receiving an error message instead of gems. The affected purchases occurred between approximately 11:40 and 12:50 Server Time today, March 11. We will provide an update when the refunds are issued.
Status Update
Mar 11, 2022, 13:47:27
Site Status | By Mutron
We have deployed a fix for credit card gem purchases and have re-enabled them while we monitor. Some purchases from the past 1-2 hours may have received an error message despite being charged, we are working to identify these purchases and deliver gems to the affected players.
Status Update
Mar 11, 2022, 12:52:45
Site Status | By Mutron
We have temporarily disabled the ability to purchase gems via credit card in order to investigate a possible issue. We will ensure that everyone that purchased gems receives them, however, there may be delays in delivery in the mean time.
Very long loading times
Mar 01, 2022, 19:32:10
Forum Post | Bug Report Forums | By Mutron
We were able to capture some data that points to an intermittent packet loss issue and have forwarded it to our hosting provider. At this point we are waiting to see if our hosting provider is able to make a fix based on what we have provided them. Thank you for your patience, everyone!
Parent nesting bug
Mar 01, 2022, 12:47:46
Forum Post | Bug Report Forums | By Mutron
As an update, we have deployed a fix that may alleviate the issue somewhat. We have not reproduced the exact situation as the reports in this thread, but we have a theory as to why it might occur, so we are trying a simple, relatively low risk fix first.
Parent nesting bug
Mar 01, 2022, 09:52:23
Forum Post | Bug Report Forums | By Mutron
Hello all,

We are investigating the possibility that this issue is related to the other site lag detailed here. It may be that this bug has existed for a very long time but only occurs under very specific circumstances where randomly long load times cause a race condition between one side loading and the other side loading. If that is the case it may be something we can fix, so that even if the lag persists at least it will not interfere so severely with breeding dragons. Thanks and sorry for the frustration this has been causing!
AH listing not listing (Lagging)
Mar 01, 2022, 09:25:14
Forum Post | Bug Report Forums | By Mutron
I can confirm that based on our logs, there have been intermittent issues regarding Auction House listings taking a while to show up in search results. We are in the process of investigating the cause.
Very long loading times
Mar 01, 2022, 09:12:30
Forum Post | Bug Report Forums | By Mutron
Hello all,

Just wanted to update that we are looking into this issue.

At the moment, one current lead we are following is that we are seeing indications that we have increased packet loss in the evenings (around 17:00-19:00 Server Time, give or take) based on charts we record. Based on similarity to past issues, this indicates it may be in networking equipment outside our servers, and it also seems like it may be dependent on time of day.

We have some staff members that are also experiencing this issue when it occurs and hopefully that will help us gather information we can send to our hosting provider.

We are also seeing some issues that relate primarily to our search backend, they could be connected or they could be unrelated, but the overlapping timing is suspicious. One example is that there have been instances where new Auction House listings were taking a while to show up.

I apologize for the frustration and inconvenience this is causing!
Status Update
Feb 28, 2022, 08:57:14
Site Status | By Mutron
We will be performing scheduled maintenance from 09:00 - 10:30 Server Time on Wednesday, March 2. During this period Flight Rising will be unavailable.
Work is not done error
Feb 07, 2022, 07:53:09
Forum Post | Bug Report Forums | By Mutron
Hello all,
You cannot uncover any tiles while there is work order (Rugged Work or Precise Work) in progress on that specific dig site. Speaking with the team, it looks like this was discussed but would have complicated the implementation of the feature as there are already a lot of moving parts.
Typo in Arlo
Feb 07, 2022, 07:39:19
Forum Post | Bug Report Forums | By Mutron
This has been fixed, thank you!
Status Update
Feb 03, 2022, 12:35:27
Site Status | By Mutron
We will be performing scheduled maintenance from 06:00 - 07:00 Server Time on Monday, February 7. During this period Flight Rising will be unavailable.
Bio won't save?
Jan 20, 2022, 11:07:05
Forum Post | Bug Report Forums | By Mutron
@mithrel We have a tentative fix for this issue now, can you let me know if it works?

We did not change the character limit, but we did run into an issue that happens to be triggered by character counts over a certain number.
500 server error when uploading new skin
Jan 20, 2022, 11:02:21
Forum Post | Bug Report Forums | By Mutron
@Illusia We have made a potential fix, can you check if it is working for you now?
500 Internal Server Error
Jan 20, 2022, 11:01:36
Forum Post | Bug Report Forums | By Mutron
Hello @Natron @Foa Can you check if it is fixed now? Thanks!
Status Update
Jan 20, 2022, 10:50:45
Site Status | By Mutron
We believe we have fixed an issue causing HTTP 500 errors in certain situations such as creating or editing large posts in the Forums, uploading skin artwork, or updating dragon bios.
500 server error when uploading new skin
Jan 20, 2022, 10:49:00
Forum Post | Bug Report Forums | By Mutron
Hello @Illusia, we are working on a fix for this issue right now! It should be fixed fairly soon.
500 Internal Server Error
Jan 20, 2022, 10:30:50
Forum Post | Bug Report Forums | By Mutron
@Natron
Can you confirm this occurs when you actually go to submit your changes after editing a post, to make them live?

UPDATE: I think I have found the issue, I am working to resolve it.
Status Update
Jan 19, 2022, 08:32:26
Site Status | By Mutron
Maintenance has concluded. Some pages may load slowly as players return to the site. We will be monitoring throughout the day.
Status Update
Jan 03, 2022, 09:25:47
Site Status | By Mutron
Maintenance has concluded. Some pages may load slowly as players return to the site. We will be monitoring throughout the day.
Exalt Bonus not updated
Jan 01, 2022, 07:30:42
Forum Post | Bug Report Forums | By Mutron
@Yewwily @Disillusionist Thank you for the reports, this has been fixed now!

A brief explanation of what happened is in this post: https://www1.flightrising.com/forums/bug/3090079/7#post_49926233
Tomo not updating?
Jan 01, 2022, 07:28:06
Forum Post | Bug Report Forums | By Mutron
Sorry about that everyone! We fed all of the dragons on the site several days ago and that resulted in everyone receiving a Well-Fed Bonus last night. Certain intensive processes that are supposed to run only during rollover ended up taking longer because of this, and they ran into the time period when players have returned to the site. As a result we had a few hiccups, including this issue.

Everyone has been reset to 10 Tomo turns again as of a few minutes ago.
New scene doesn't drop in the Coliseum
Dec 10, 2021, 10:58:08
Forum Post | Bug Report Forums | By Mutron
Thanks for reporting this! We have made several changes to the Coliseum item drops for Frigidfin Expedition and extended the event, as detailed in the announcement thread.
randomized fishpot dropping
Dec 10, 2021, 10:57:47
Forum Post | Bug Report Forums | By Mutron
Thanks for reporting this! We have made several changes to the Coliseum item drops for Frigidfin Expedition and extended the event, as detailed in the announcement thread.
Status Update
Dec 10, 2021, 10:56:38
Site Status | By Mutron
We've made some changes to Coliseum item drops for the Frigidfin Expedition. Due to these errors, we are extending the micro-holiday by one (1) day. The Frigidfin Expedition will now end at 06:00 Server Time on Tuesday, December 14th.
Weird Security Alert Thing?
Dec 10, 2021, 10:11:45
Forum Post | Bug Report Forums | By Mutron
Hello all,

After looking into this and speaking to our advertising partner, we believe the alerts about this URL are false positives. That is, the URL is not truly malicious but AVG and Avast are now reporting it as such. It is however an advertising-related script.

The reasoning behind that statement is that we know the script is part of our advertising partner's standard advertising stack and has been since at least early March 2020. We have records of this because it turned out to be unintentionally interfering with the functioning of certain buttons on the site around that time period, and we had to work through it with them. We are double checking with them what we can share about the specific function of this script.

In the mean time, however, we recognize that these pop-ups are both worrisome and confusing. We are communicating with our ads partner about the issue.
Status Update
Dec 07, 2021, 09:36:12
Site Status | By Mutron
Dragon Search and Forum Search are now both fully online!
Status Update
Dec 07, 2021, 06:50:42
Site Status | By Mutron
Maintenance has concluded. Dragon Search and Forum Search may be unavailable for up to 24 hours. Some pages may load slowly as players return to the site. We will be monitoring throughout the day.
Can't load pages
Nov 30, 2021, 10:13:08
Forum Post | Bug Report Forums | By Mutron
Clearing your cache may help in some specific cases as well and is always worth trying if nothing else is working. I have updated my recent post to mention this.
Status Update
Nov 30, 2021, 08:57:41
Site Status | By Mutron
We have implemented a tentative fix for the HTTP 400 Bad Request errors some players have started experiencing in the past week. More information here.
Can't load pages
Nov 30, 2021, 08:54:44
Forum Post | Bug Report Forums | By Mutron
Hello all,

We have made a configuration change to our servers that may help the 400/Bad Request error problem for now.

Based on our monitoring information, it looks like the Cookie header in some players' HTTP requests is going over an internal limit. In other words, some cookie is getting too large. This started around the morning of the 24th, and we did not make any software deployments at that time. It is likely that this is coming from an advertisement or our ad partners' ad serving scripts, but it is difficult to track down as we would need retroactive logs of the typical sizes of all incoming cookies from before the event started.

We have doubled the limit for incoming cookie headers on our Web servers. Unfortunately, this is not an ideal solution, as the limit we had is pretty standard and you may now instead run into limits on browsers, intermediate proxies or firewalls, etc. Additionally, some of our Fairgrounds games and Coliseum may still be affected by this issue. Another problem is that if the cookie that is growing continues growing unbounded, this may just occur again soon, at which point we cannot reasonably raise the limit further.

If you continue getting this issue, for now the recommended course of action is to clear your cookies for flightrising.com and/or www1.flightrising.com in order to start with a "clean slate." If this does not help, clearing your cache is also recommended.

Thank you for your patience while we continue to investigate the root cause of this issue!
Status Update
Oct 05, 2021, 09:57:59
Site Status | By Mutron
Maintenance has concluded. Some pages may load slowly as players return to the site. We will be monitoring throughout the day.
Wednesday's Extended Maintenance
Aug 19, 2021, 07:30:34
Hello everyone! Thank you so much for your patience and understanding yesterday. This maintenance did not go as planned, and we apologize for the inconvenience and any frustration it may have caused you. Due to how long this maintenance lasted and as many of you noticed last night, your dragons were fed before we opened the site back up to players.

So what happened?

In our efforts to improve the performance of Flight Rising during heavy load, such as during breed releases or anniversaries, we contacted our hosting provider about upgrading our internet link speed. In order to do this, our front-end server was going to be moved to a rack that supported the higher speeds. This was scheduled to take approximately 1 hour.

Unfortunately, a number of things went wrong during the move:
  • Our hosting provider did not inform us that the move would cause our primary IP address to change, or that there would be no way to change it back besides returning the server to where it started. As a result, we had to update our DNS settings.
  • At some point in the move or the subsequent debugging, some of the boot settings on the server became corrupted, and we had to restore them to their correct values so the server would boot.
  • And the most serious issue: during the move, the server's secondary network port, which is integrated into the motherboard and is used to communicate with other back-end servers, was physically damaged. As a result, we could not open up the site because we could not communicate from this server to any of our other servers.

The last point took the longest for our hosting company to diagnose. At present we are now instead using a third network port which is part of an add-on card. We will be closely monitoring performance to see if there are any degradations relative to the previous setup.

What does this mean?

Some players may experience difficulty accessing the site, or parts of it, while the DNS changes propagate. These issues should resolve relatively soon as the changes were made almost a full day ago.

Thank you again, for your patience and your understanding during yesterday's surprise extended maintenance. It was an interesting day for everyone across the board.

Sincerely,
The Flight Rising team
Status Update
Aug 18, 2021, 17:59:58
Site Status | By Mutron
Maintenance has concluded. We will be monitoring for performance issues. Due to the late resolution, we're postponing the ads change. A full update on today's outage will be posted tomorrow.
1 2 3 4 5 6 7 ... 20 21