Go Back   Pligg Forum > Announcements > Pligg News
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-09-2007, 08:17 AM
beatniak's Avatar
beatniak beatniak is offline
Pligg Dev/MB creator
 
Join Date: Apr 2006
Location: NL - 52.100863;5.108356
Posts: 310
Downloads: 32
Uploads: 0
Thanks: 14
Thanked 77 Times in 48 Posts
Exclamation [Security Fix] For ALL Pligg versions when extra fields enabled

I've found a bug that makes all pligg versions vulnerable for deformation hacks and site hijacking when the extra fields are enabled.
In other words, all pligg sites that have extra fields enabled are wide open for hack attacks.

IMPORTANT: PLEASE UPGRADE IMMEDIATELY!!!

Here are the bugfix packages for Pligg 9.6 / 9.5 / 9.1 / 9.0 / 8.2
Upgrade info: Just overwrite your pligg install with the included files

I added the fix for all the official templates, but for fixing your own template:
1) Look in: /templates/<yget or MB>/submit_step_3.tpl
2) copy the code between "Steef 2k7-07 security fix start" and "Steef 2k7-07 security fix end"
3) paste in: /templates/<your template>/submit_step_3.tpl

Fix is already added to the SVN, so 9.7 will be save.
__________________
Like my work? Donations are welcome if you would like to support my work!
Finger pliggin' good sites of mine: receptencocktail.nl / numarketing.nl / goboz.com

Last edited by beatniak : 07-09-2007 at 10:04 AM. Reason: added security_fix for 8.2 and 9.5
Reply With Quote
Sponsored Links
  #3 (permalink)  
Old 07-09-2007, 09:37 AM
tbones tbones is offline
Constant Pligger
 
Join Date: Apr 2007
Posts: 1,073
Downloads: 26
Uploads: 0
Thanks: 53
Thanked 25 Times in 23 Posts
v9.5 users should take the v9.6 fix?
Reply With Quote
  #4 (permalink)  
Old 07-09-2007, 09:45 AM
beatniak's Avatar
beatniak beatniak is offline
Pligg Dev/MB creator
 
Join Date: Apr 2006
Location: NL - 52.100863;5.108356
Posts: 310
Downloads: 32
Uploads: 0
Thanks: 14
Thanked 77 Times in 48 Posts
Quote:
Originally Posted by tbones View Post
v9.5 users should take the v9.6 fix?
Whoops.... forgot that one. Added the fix for 9.5 and 8.2 in the first post.

Here's the fix for pligg 7(rc63). Couldn't attach it in the first, because i have a max 5 files limit when attaching

These are all the official pligg packages i have, so if you want a bugfix of another pligg version, please provide the (official) download link to that version.
Attached Files
File Type: rar pligg_7rc63_beatniak_security_fix.rar (5.0 KB, 6 views - Who Downloaded?)
__________________
Like my work? Donations are welcome if you would like to support my work!
Finger pliggin' good sites of mine: receptencocktail.nl / numarketing.nl / goboz.com

Last edited by beatniak : 07-09-2007 at 12:21 PM. Reason: added security_fix for pligg 7
Reply With Quote
  #5 (permalink)  
Old 07-09-2007, 11:49 AM
P1mpPanther's Avatar
P1mpPanther P1mpPanther is offline
Constant Pligger
 
Join Date: Feb 2007
Posts: 293
Downloads: 20
Uploads: 0
Thanks: 47
Thanked 10 Times in 9 Posts
Thank you!
__________________
RunStream :: RSS feed creator | RSS Marketing Platform | TagBlast!

...and a Pligg site on deck!
Reply With Quote
  #6 (permalink)  
Old 07-09-2007, 04:18 PM
argh2xxx argh2xxx is offline
Constant Pligger
 
Join Date: Jan 2007
Posts: 294
Downloads: 26
Uploads: 0
Thanks: 0
Thanked 7 Times in 5 Posts
You can post this fix anywhere on submit_step_3.tpl? Or you must post on specific location like the patch instructed? I mean I use a custom template, and so it looks a bit different in submit_step_3.tpl
__________________
http://www.blogmyway.org
Reply With Quote
  #7 (permalink)  
Old 07-09-2007, 06:13 PM
beatniak's Avatar
beatniak beatniak is offline
Pligg Dev/MB creator
 
Join Date: Apr 2006
Location: NL - 52.100863;5.108356
Posts: 310
Downloads: 32
Uploads: 0
Thanks: 14
Thanked 77 Times in 48 Posts
RTFA.................................
Quote:
I added the fix for all the official templates, but for fixing your own template:
1) Look in: /templates/<yget or MB>/submit_step_3.tpl
2) copy the code between "Steef 2k7-07 security fix start" and "Steef 2k7-07 security fix end"
3) paste in: /templates/<your template>/submit_step_3.tpl
__________________
Like my work? Donations are welcome if you would like to support my work!
Finger pliggin' good sites of mine: receptencocktail.nl / numarketing.nl / goboz.com
Reply With Quote
  #8 (permalink)  
Old 07-09-2007, 06:23 PM
P1mpPanther's Avatar
P1mpPanther P1mpPanther is offline
Constant Pligger
 
Join Date: Feb 2007
Posts: 293
Downloads: 20
Uploads: 0
Thanks: 47
Thanked 10 Times in 9 Posts
k, ill get a few laughs for asking but, what does RTFA mean? (read the ---??)

And I thought i new EVERY acronym on the planet!!! (jk)
__________________
RunStream :: RSS feed creator | RSS Marketing Platform | TagBlast!

...and a Pligg site on deck!
Reply With Quote
  #9 (permalink)  
Old 07-10-2007, 04:31 AM
beatniak's Avatar
beatniak beatniak is offline
Pligg Dev/MB creator
 
Join Date: Apr 2006
Location: NL - 52.100863;5.108356
Posts: 310
Downloads: 32
Uploads: 0
Thanks: 14
Thanked 77 Times in 48 Posts
RTFA = Read The Fuçking Article

It's a derivative acronym of RTFM (Read The F***ing Manual). This instruction is given in response to a question when the person being asked believes that the question could be easily answered by reading the relevant "manual" or instructions.

Hence, RTFA... It's often replied in Digg (etc) to questions when the person being asked believes that the question could be easily answered by reading the relevant article.

There are many derivative acronyms of the form "RTF*", where '*' is the appropriate source of information. These include "RTFC" (Read The F***ing Code), "RTFFAQ or "RTFF" (Read The F***ing FAQ) and "RTFW" (Read The F***ing Wiki or Walkthrough). Other geek acronyms of interest are GIYD (Google It You Dumbass) and JFGI (Just F***ing Google It).

PS: Don't get too groggy on the "F", because it isn't supposed to be that rude. If it says RTA, no one understands the acronym
__________________
Like my work? Donations are welcome if you would like to support my work!
Finger pliggin' good sites of mine: receptencocktail.nl / numarketing.nl / goboz.com

Last edited by AshDigg : 07-10-2007 at 06:25 PM.
Reply With Quote
  #10 (permalink)  
Old 07-10-2007, 06:19 AM
dollars5's Avatar
dollars5 dollars5 is offline
Pligg is my love :)
 
Join Date: Dec 2006
Location: India
Posts: 2,160
Downloads: 29
Uploads: 1
Thanks: 292
Thanked 266 Times in 178 Posts
@Steef: lol, m8, new Web 2.0 acronyms to learn
Reply With Quote
Reply



Thread Tools
Display Modes
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Similar Threads
Thread Thread Starter Forum Replies Last Post
How can I add more extra fields (i've used all 15) revolver General Help 3 03-22-2007 05:16 PM
Adsense, Extra Fields and Pligg 9.0 (digitalnature template) rdanays General Help 1 01-01-2007 02:57 PM
Page titles & breadcrumbs AshDigg Core Development 11 06-30-2006 06:35 PM
Extra fields not working in Pligg 7.2+Mollio-beat 1.3 gragland Bug Report 0 06-18-2006 03:26 AM


LinkBacks Enabled by vBSEO 3.0.0