Go Back   Pligg CMS Forum > Pligg Development > Bug Report

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 10-10-2006, 08:48 PM
Pligg Donor
Pligg Version: 9.9
Pligg Template: push it
 
Join Date: Feb 2006
Posts: 67
Thanks: 8
Thanked 4 Times in 3 Posts
Question security issues

Are the xss and other security issues that were posted in this forum taken care of in the latest svn version of pligg?

Some kind of announcement should be posted to let folks know what's going on with it.
Reply With Quote
  #2 (permalink)  
Old 10-10-2006, 08:53 PM
jitgos's Avatar
Constant Pligger
 
Join Date: Apr 2006
Location: Indiana (soon New Hampshire)
Posts: 339
Thanks: 94
Thanked 49 Times in 38 Posts
8.1.0 included many fixes and 8.1.5 will most likely be released in a few days to address the other issues. I believe every specific security issue that has been posted on the forums was fixed within minutes and included in the svn.

Jitgos
Reply With Quote
  #3 (permalink)  
Old 10-10-2006, 08:54 PM
Pligg Donor
Pligg Version: 9.9
Pligg Template: push it
 
Join Date: Feb 2006
Posts: 67
Thanks: 8
Thanked 4 Times in 3 Posts
Quote:
I believe every specific security issue that has been posted on the forums was fixed within minutes and included in the svn.
There was one post made yesterday that outlined some new issues, but that post was removed (which I guess prompted you to post the correct guidelines for reporting security issues). Those were the issues I was most curious about.

They probably shouldn't have been posted to the open forum, but now that they are "out there", I just wanted to make sure there was already a security patch. People should be notified and encouraged to upgrade as well to protect their pligg sites when stuff like that is found and patched.

Last edited by Rodney; 10-10-2006 at 08:56 PM.. Reason: added more info :)
Reply With Quote
  #4 (permalink)  
Old 10-10-2006, 09:13 PM
kbeeveer46's Avatar
Pligg Developer/Admin
Pligg Version: 0
Pligg Template: none
 
Join Date: Jun 2006
Location: Muncie, Indiana
Posts: 3,547
Thanks: 254
Thanked 649 Times in 513 Posts
Rodney, that's why 8.1.0 was released. Because there were a lot of holes patched and we felt that they were big enough holes that they warranted a quick release. We've never had this many people tesing Pligg at one time and they're finding things that have never been reported before.
__________________
I accept donations for my time helping users like you on the forum and IRC.
Reply With Quote
  #5 (permalink)  
Old 10-11-2006, 02:03 PM
Pligg Donor
Pligg Version: 9.9
Pligg Template: push it
 
Join Date: Feb 2006
Posts: 67
Thanks: 8
Thanked 4 Times in 3 Posts
Quote:
Rodney, that's why 8.1.0 was released. Because there were a lot of holes patched and we felt that they were big enough holes that they warranted a quick release
8.1.0 was released on 10/8 but the forum post with the security issues was posted on 10/9 AFTER the 8.1.0 release. It said that the most current version of pligg had vulnerabilities.

The whole post was removed, but I think it clearly stated the problems were in the 8.1.0 version of pligg.
Reply With Quote
  #6 (permalink)  
Old 10-11-2006, 02:17 PM
kbeeveer46's Avatar
Pligg Developer/Admin
Pligg Version: 0
Pligg Template: none
 
Join Date: Jun 2006
Location: Muncie, Indiana
Posts: 3,547
Thanks: 254
Thanked 649 Times in 513 Posts
Yeah, that's why Jit mentioned maybe even another release with the fixes you mentioned.
__________________
I accept donations for my time helping users like you on the forum and IRC.
Reply With Quote
  #7 (permalink)  
Old 10-11-2006, 03:11 PM
jitgos's Avatar
Constant Pligger
 
Join Date: Apr 2006
Location: Indiana (soon New Hampshire)
Posts: 339
Thanks: 94
Thanked 49 Times in 38 Posts
Just to confirm. As soon as those were issues were brought up within minutes they were fixed in the svn. We havent released antoher update yet b/c we want to make sure we have fixed all similar issues we can find and then release an official update within a day or two.

Pligg was tested by a lot of people before being released but as KB said the digg article has brought in soooo many people using pligg that other things have come up.

Jitgos


Jitgos
Reply With Quote
  #8 (permalink)  
Old 10-11-2006, 04:28 PM
savant's Avatar
Constant Pligger
 
Join Date: Apr 2006
Location: UK
Posts: 1,218
Thanks: 64
Thanked 207 Times in 148 Posts
do you mean these:

xss:
http://www.pligg.com/forum/showthrea...light=security

xss and sql injection
http://www.pligg.com/forum/showthrea...light=security

both have been fixed.
__________________
Anatomy of the Pligg template Help needed
Reply With Quote
  #9 (permalink)  
Old 10-11-2006, 08:21 PM
New Pligger
 
Join Date: Sep 2006
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Quote:
Originally Posted by savant View Post
No, I've posted other vulnerabilities. IMHO, I think there are more, that's why I said you should do a general code review.

BTW, some problems were fixed incorrectly (ej. applying strip_tags instead of intval)
Reply With Quote
  #10 (permalink)  
Old 10-12-2006, 01:50 AM
savant's Avatar
Constant Pligger
 
Join Date: Apr 2006
Location: UK
Posts: 1,218
Thanks: 64
Thanked 207 Times in 148 Posts
i will try and look for them in the forum.

xknown thanks again for the security updates.
__________________
Anatomy of the Pligg template Help needed
Reply With Quote
Reply

Thread Tools
Display Modes
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Similar Threads
Thread Thread Starter Forum Replies Last Post
9.9.5 Specific Release Notes for Security Issues margotb Installation and Upgrade Help 10 08-02-2008 10:11 AM
Use Pligg Security System for Non-pligg sites byron Modification Tutorials 1 06-19-2007 12:49 PM
Reporting Security Vulnerabilities jitgos Bug Report 0 10-09-2006 09:56 PM


Search Engine Friendly URLs by vBSEO 3.2.0