Go Back   Pligg CMS Forum > Announcements > Pligg News

Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-26-2007, 10:08 PM
AshDigg's Avatar
Coder
 
Join Date: Dec 2005
Posts: 1,574
Thanks: 235
Thanked 345 Times in 206 Posts
Security Vulnerability

A very serious bug has been found in _all_ versions of Pligg. We have a patch available here. We advise you to apply this immediately.

For 9.0, 9.1, 9.5 versions
1) upload the upgrade_login.php into your root Pligg folder. Not the install folder. Then open the file in your browser. If you have *any* errors, let us know as many details as you can so we can help you fix it.

2) upload the appropriate login.php file. Rename your existing /login.php file to /login.php.bak, rename the new one you just uploaded to /login.php. Please note, this is NOT the /libs/login.php file.

3) If you can login / logout without any problems, then delete the .bak file.

We expect to release a beta 9.5.1 (security update) before the end of the month to fix this and a few other bugs we found.

Thanks.

ps: if you want to manually edit your login file, look here.
Attached Files
File Type: php upgrade_login.php (352 Bytes, 585 views)
File Type: php 9.1_login.php (5.3 KB, 261 views)
File Type: php 9.5_login.php (5.6 KB, 458 views)
File Type: php 9.0_login.php (5.3 KB, 172 views)
__________________
- Ash

Last edited by AshDigg; 05-26-2007 at 11:23 PM..
  #2 (permalink)  
Old 05-26-2007, 10:59 PM
New Pligger
 
Join Date: Dec 2006
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
What exactly was the problem, and how bad of a risk is it to not apply this update?

(These questions should be addressed in all Security updates if possible)
  #3 (permalink)  
Old 05-26-2007, 11:05 PM
dollars5's Avatar
Pligg is my love :)
 
Join Date: Dec 2006
Location: India
Posts: 2,154
Thanks: 290
Thanked 266 Times in 177 Posts
Pls check here Pligg Security Vulnerability - Password Change Request, there was a security hole which had the risk of site takeover - but thankfully Ash got it fixed sooner.

Pls take some additional precautions also as outlined in that thread to protect your site better.

Last edited by dollars5; 05-26-2007 at 11:44 PM..
  #4 (permalink)  
Old 05-26-2007, 11:09 PM
New Pligger
 
Join Date: Sep 2006
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
One point I'd like to share is the note to change /login.php to /login.php.bak

I wouldn't leave any .bak extension files of any kind on a server. I've seen those exploited by hackers before.
  #5 (permalink)  
Old 05-26-2007, 11:15 PM
AshDigg's Avatar
Coder
 
Join Date: Dec 2005
Posts: 1,574
Thanks: 235
Thanked 345 Times in 206 Posts
Quote:
Originally Posted by robaubie View Post
One point I'd like to share is the note to change /login.php to /login.php.bak

I wouldn't leave any .bak extension files of any kind on a server. I've seen those exploited by hackers before.
Good point, update my instructions, thanks
__________________
- Ash
  #6 (permalink)  
Old 05-26-2007, 11:15 PM
Constant Pligger
 
Join Date: Apr 2006
Posts: 122
Thanks: 1
Thanked 1 Time in 1 Post
What about earlier versions of Pligg? I am running a modified 8.2.
__________________
DuckFat
slackmosphere.com
  #7 (permalink)  
Old 05-26-2007, 11:25 PM
AshDigg's Avatar
Coder
 
Join Date: Dec 2005
Posts: 1,574
Thanks: 235
Thanked 345 Times in 206 Posts
Quote:
Originally Posted by DuckFat View Post
What about earlier versions of Pligg? I am running a modified 8.2.
For 8.2 follow the same instructions but use these files.
Attached Files
File Type: php 8.2_login.php (4.8 KB, 116 views)
File Type: php upgrade_0.8.2.php (334 Bytes, 139 views)
__________________
- Ash

Last edited by AshDigg; 05-27-2007 at 12:01 AM..
  #8 (permalink)  
Old 05-26-2007, 11:52 PM
Constant Pligger
 
Join Date: Apr 2006
Posts: 122
Thanks: 1
Thanked 1 Time in 1 Post
Okay, I did as instructed but when I brought up the upgrade_0.8.2.php file in my browser nothing is displayed but a blank white page. I am using FireFox. Is that what is supposed to happen? I was expecting at least a "patch applied" message.
__________________
DuckFat
slackmosphere.com
  #9 (permalink)  
Old 05-27-2007, 12:02 AM
AshDigg's Avatar
Coder
 
Join Date: Dec 2005
Posts: 1,574
Thanks: 235
Thanked 345 Times in 206 Posts
Quote:
Originally Posted by DuckFat View Post
Okay, I did as instructed but when I brought up the upgrade_0.8.2.php file in my browser nothing is displayed but a blank white page.
I just replaced the file. Please try it again. thanks
__________________
- Ash
  #10 (permalink)  
Old 05-27-2007, 12:08 AM
New Pligger
 
Join Date: Feb 2007
Posts: 27
Thanks: 6
Thanked 0 Times in 0 Posts
Just thought I would throw this out there. As a Pligg community lets not throw this up on DIGG or any other information source that will attract hackers attention . If I am totally wrong I apologize
Closed Thread

Thread Tools
Display Modes
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Vulnerability Part 2 AshDigg Pligg News 17 06-17-2007 02:28 PM
Pligg Security Vulnerability - Password Change Request sunstardude Bug Report 19 06-01-2007 01:53 PM


Search Engine Friendly URLs by vBSEO 3.2.0