Go Back   Pligg CMS Forum > Announcements > Pligg News

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-28-2007, 06:22 PM
AshDigg's Avatar
Coder
 
Join Date: Dec 2005
Posts: 1,574
Thanks: 235
Thanked 345 Times in 206 Posts
Security Vulnerability Part 2

I'm very sorry to inform you that the patch I posted the other day created another very serious problem. We have a patch available here and advise you to apply this immediately. If you have not installed the first patch, you don't need to, just install this one. If you did install the first patch, then just replace the login file.

I'm very sorry for the inconvenience and thank you for your support.




If you upgrade to Beta 9.6 it already has the fix included.


Instructions for Beta 9.0, 9.1 and 9.5

1) upload the upgrade_login.php into your root Pligg folder. Not the install folder. Then open the file in your browser. If you have *any* errors, let us know as many details as you can so we can help you fix it. This only needs to be done once, so if you did it within the last 2 days you don't need to again.

2) upload the appropriate login.php file. Rename your existing /login.php file to /login.php.bak, rename the new one you just uploaded to /login.php. Please note, this is NOT the /libs/login.php file.

3) If you can login / logout without any problems, then delete the .bak file.
Attached Files
File Type: php upgrade_login.php (352 Bytes, 263 views)
File Type: php 9.5_login.php (5.7 KB, 236 views)
File Type: php 9.1_login.php (5.3 KB, 171 views)
File Type: php 9.0_login.php (5.4 KB, 91 views)
__________________
- Ash

Last edited by AshDigg; 05-28-2007 at 07:50 PM..
Reply With Quote
  #2 (permalink)  
Old 05-28-2007, 06:22 PM
AshDigg's Avatar
Coder
 
Join Date: Dec 2005
Posts: 1,574
Thanks: 235
Thanked 345 Times in 206 Posts
Instructions for Beta 8.2

1) upload the upgrade_0.8.2.php into your root Pligg folder. Not the install folder. Then open the file in your browser. If you have *any* errors, let us know as many details as you can so we can help you fix it. This only needs to be done once, so if you did it within the last 2 days you don't need to again.

2) upload the 8.2_login.php file. Rename your existing /login.php file to /login.php.bak, rename the new one you just uploaded to /login.php. Please note, this is NOT the /libs/login.php file.

3) If you can login / logout without any problems, then delete the .bak file.

If the upgrade file just shows a blank page, try to run this in phpMyAdmin.

Code:
ALTER TABLE `users` ADD `last_reset_code` varchar(255) default NULL
Attached Files
File Type: php upgrade_0.8.2.php (250 Bytes, 83 views)
File Type: php 8.2_login.php (4.9 KB, 77 views)
__________________
- Ash

Last edited by AshDigg; 05-28-2007 at 07:03 PM..
Reply With Quote
  #3 (permalink)  
Old 05-28-2007, 06:22 PM
AshDigg's Avatar
Coder
 
Join Date: Dec 2005
Posts: 1,574
Thanks: 235
Thanked 345 Times in 206 Posts
Instructions for Beta 7.2

1) upload the upgrade_0.7.2.php into your root Pligg folder. Not the install folder. Then open the file in your browser. If you have *any* errors, let us know as many details as you can so we can help you fix it. This only needs to be done once, so if you did it within the last 2 days you don't need to again.

2) upload the 7.2_login.php file. Rename your existing /login.php file to /login.php.bak, rename the new one you just uploaded to /login.php. Please note, this is NOT the /libs/login.php file.

3) If you can login / logout without any problems, then delete the .bak file.

If the upgrade file just shows a blank page, try to run this in phpMyAdmin.

Code:
ALTER TABLE `users` ADD `last_reset_code` varchar(255) default NULL
Attached Files
File Type: php upgrade_0.7.2.php (250 Bytes, 80 views)
File Type: php 7.2_login.php (4.3 KB, 69 views)
__________________
- Ash

Last edited by AshDigg; 05-28-2007 at 07:03 PM..
Reply With Quote
  #4 (permalink)  
Old 05-28-2007, 08:19 PM
Fernandojs's Avatar
New Pligger
 
Join Date: Feb 2007
Location: Curitiba - BR
Posts: 23
Thanks: 0
Thanked 0 Times in 0 Posts
Thanks!

upgrade is complete!
Reply With Quote
  #5 (permalink)  
Old 05-28-2007, 08:48 PM
dollars5's Avatar
Pligg is my love :)
 
Join Date: Dec 2006
Location: India
Posts: 2,154
Thanks: 290
Thanked 266 Times in 177 Posts
NP m8, atleast you found it earlier and fixed it sooner before it hasbeen exploited - kudoos to you and thanks for the fix.
Reply With Quote
  #6 (permalink)  
Old 05-28-2007, 09:11 PM
New Pligger
 
Join Date: Mar 2007
Posts: 7
Thanks: 2
Thanked 0 Times in 0 Posts
Thanks for the heads up!
Reply With Quote
  #7 (permalink)  
Old 05-28-2007, 09:17 PM
Designer
Pligg Version: 9.9.
 
Join Date: Mar 2007
Posts: 159
Thanks: 1
Thanked 15 Times in 11 Posts
Send a message via MSN to skins4webs
Thanks again.

Upgrade was successful.
__________________
http://www.illestlyrics.com, hip-hop site
http://www.qkin.com, Web development site
Reply With Quote
  #8 (permalink)  
Old 05-28-2007, 09:24 PM
New Pligger
 
Join Date: Dec 2006
Posts: 3
Thanks: 1
Thanked 0 Times in 0 Posts
thank you

this worked really well - and this time there was no white page here :-)
Reply With Quote
  #9 (permalink)  
Old 05-28-2007, 10:35 PM
bichopro's Avatar
New Pligger
 
Join Date: Feb 2007
Posts: 9
Thanks: 1
Thanked 4 Times in 2 Posts
Thanks so much
__________________
Reply With Quote
  #10 (permalink)  
Old 05-29-2007, 12:29 AM
Casual Pligger
 
Join Date: Mar 2007
Location: Salem, Oregon
Posts: 51
Thanks: 18
Thanked 0 Times in 0 Posts
Send a message via Skype™ to harlem
thanks for catching it early and for an even quicker response.
Reply With Quote
Reply

Thread Tools
Display Modes
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Similar Threads
Thread Thread Starter Forum Replies Last Post
Pligg Security Vulnerability - Password Change Request sunstardude Bug Report 19 06-01-2007 01:53 PM
Security Vulnerability AshDigg Pligg News 36 05-28-2007 07:10 PM


Search Engine Friendly URLs by vBSEO 3.2.0