Page 1 of 4 123 ... LastLast
Results 1 to 10 of 40
  1. #1
    New Pligger KerryG's Avatar
    Joined
    Jul 2008
    Posts
    8

    [SOLVED] Do NOT run version 9.9.0!!!

    Fair warning to everyone, 9.9 is RIDDLED with security holes. My pligg 9.9 site was running less than 24 hours and my hosting provider shut it down because it had been compromised and other scripts installed that were doing bad things. A few internet searches shows quite a few SQL injection bugs and total lack of sanitation of input parameters as well as a nice hack to get anyone's password.

    If you are running pligg 9.9, you will be compromised very, very soon. Posting a quaint warning that there are security holes that have fixes and workarounds and not posting those fixes or workarounds is a complete disservice to the 16,000 people who have downloaded this version.

    Does anyone know if these are only issues with 9.9 and can an older version be used? Due to the nature of these issues I am assuming it is probably all versions of pligg that are vulnerable.

    Users beware, again, your 9.9 sites are wide open for attack and all anyone has to do is a quick google search to find your site and its all over.

  2. #2
    Constant Pligger onlinebisnes's Avatar
    Joined
    May 2007
    Posts
    143
    its version 0.9.9.. not ver 9.9
    I guess this is an old story..we are all still waiting the new version to came out.

  3. #3
    Pligg Donor catchpen's Avatar
    Joined
    Jan 2008
    Posts
    185
    KerryG - Did your hosting provider give you any details? It would be nice to know what happened and how.

  4. #4
    Casual Pligger ddluk's Avatar
    Joined
    Feb 2008
    Posts
    33
    Yes, sorry off course it's 0.9.9. We will see in next few hours if that is old story. When they don't release new version using Pligg will be dangerous.

    @catchpen

    They don't need to give him any details, only look to that exploit I provided link. Run it and see that it can change your files in your template folder, so everyone can customize it to include to one off your template file any code they want.

  5. #5
    Casual Pligger sixlaneve's Avatar
    Joined
    Dec 2006
    Posts
    69
    let's wait for 1.0 then...

    anyway, nothing stop us to develop on 0.9.9 and upgrade later i think

  6. #6
    Pligg Founder Yankidank's Avatar
    Joined
    Dec 2005
    Location
    San Francisco, CA
    Posts
    5,063
    Site
    http://pligg.com/demo/
    All known security issues should be patched by weeks end. Please be patient as we work on providing you with a solution as quickly as possible.
    The Facebook Module for Pligg CMS!
    Register, Login, and Submit Stories with Facebook. An absolute MUST HAVE for all Pligg sites!

  7. #7
    New Pligger KerryG's Avatar
    Joined
    Jul 2008
    Posts
    8
    Quote Originally Posted by Yankidank View Post
    All known security issues should be patched by weeks end. Please be patient as we work on providing you with a solution as quickly as possible.
    I don't think you fully appreciate the issue here. It is highly recommended that anyone using 0.9.9 take their site OFFLINE immediately. The hacker used an exploit that allowed them to install a script called hello.php into the root directory of my installation. My provider only told me that the script was doing "bad things" and so they disabled my account which shut off 10 different websites. You should post what all of the known security issues are and the current code to fix them and you might actually get some help from your community in solving the problems.

    I run a much larger open source project than this and I have found that you need to be as open as possible to your users and they will respond by giving you assistance during problems like this. If you keep try to minimize a significant problem like this, it only hurts you and the project.

  8. #8
    New Pligger KerryG's Avatar
    Joined
    Jul 2008
    Posts
    8

    Exclamation

    For anyone that doesn't understand how bad this is, there is a very simple script available that you run and point to a pligg site, within about 2 seconds you have SHELL access to that site and can do anything you want. This isn't a simple page hack, this is a SERIOUS security problem that gives a hacker complete access to your entire hosting environment. Once you have shell access you can sit there and download files, edit files, install code, pretty much anything you want.

  9. #9
    New Pligger justelite's Avatar
    Joined
    Sep 2006
    Posts
    7
    my website was hacked today! Yestersday I just upgrade it at Pligg Beta 9.9.0.

  10. #10
    New Pligger justelite's Avatar
    Joined
    Sep 2006
    Posts
    7

    Exclamation

    I digg the issue and I found how the attacker found my site:

    "Powered By Pligg" - Google'da Ara

    He search for Powered By Pligg!!

    He modify my footer and put By BeyazKurt words.
    Also put some redirect to a page.

Page 1 of 4 123 ... LastLast

Similar Threads

  1. upgradation of old pligg version 6 to latest version 9.8.2
    By kishor in forum Questions & Comments
    Replies: 5
    Last Post: 01-22-2008, 08:48 PM
  2. Replies: 0
    Last Post: 12-17-2007, 08:10 PM
  3. [SOLVED] Version number doesn't update after upgrade
    By AshMCairo in forum Questions & Comments
    Replies: 8
    Last Post: 12-13-2007, 09:02 AM
  4. [SOLVED] Link To Pligg Templating Version 1.0 Video Broken
    By Adaman in forum Questions & Comments
    Replies: 6
    Last Post: 07-05-2007, 04:23 PM
  5. php and mysql version, pligg version
    By inallev in forum Questions & Comments
    Replies: 2
    Last Post: 02-14-2007, 01:29 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Pligg Modules and Pligg Templates from Pligg Pro Donate to Pligg CMS Dreamhost Web Hosting Host Gator Web Hosting