[SOLVED] Do NOT run version 9.9.0!!!

Register an Account
Pligg Chat Room
Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-31-2008, 04:40 AM
New Pligger
 
Join Date: Jul 2008
Posts: 8
Fair warning to everyone, 9.9 is RIDDLED with security holes. My pligg 9.9 site was running less than 24 hours and my hosting provider shut it down because it had been compromised and other scripts installed that were doing bad things. A few internet searches shows quite a few SQL injection bugs and total lack of sanitation of input parameters as well as a nice hack to get anyone's password.

If you are running pligg 9.9, you will be compromised very, very soon. Posting a quaint warning that there are security holes that have fixes and workarounds and not posting those fixes or workarounds is a complete disservice to the 16,000 people who have downloaded this version.

Does anyone know if these are only issues with 9.9 and can an older version be used? Due to the nature of these issues I am assuming it is probably all versions of pligg that are vulnerable.

Users beware, again, your 9.9 sites are wide open for attack and all anyone has to do is a quick google search to find your site and its all over.
  #2 (permalink)  
Old 07-31-2008, 06:18 AM
Constant Pligger
 
Join Date: May 2007
Posts: 148
its version 0.9.9.. not ver 9.9
I guess this is an old story..we are all still waiting the new version to came out.

Watch Tv Episode Online - Watch your favorites Tv Shows.
  #3 (permalink)  
Old 07-31-2008, 06:25 AM
catchpen's Avatar
Pligg Donor/Coder
 
Join Date: Jan 2008
Posts: 184
KerryG - Did your hosting provider give you any details? It would be nice to know what happened and how.
  #4 (permalink)  
Old 07-31-2008, 06:25 AM
Casual Pligger
 
Join Date: Feb 2008
Posts: 33
Yes, sorry off course it's 0.9.9. We will see in next few hours if that is old story. When they don't release new version using Pligg will be dangerous.

@catchpen

They don't need to give him any details, only look to that exploit I provided link. Run it and see that it can change your files in your template folder, so everyone can customize it to include to one off your template file any code they want.

Last edited by ddluk; 07-31-2008 at 06:27 AM. Reason: add replay
  #5 (permalink)  
Old 07-31-2008, 10:51 AM
sixlaneve's Avatar
Casual Pligger
 
Join Date: Dec 2006
Location: Rome
Posts: 69
Send a message via ICQ to sixlaneve Send a message via AIM to sixlaneve
let's wait for 1.0 then...

anyway, nothing stop us to develop on 0.9.9 and upgrade later i think
  #6 (permalink)  
Old 07-31-2008, 10:55 AM
Yankidank's Avatar
Pligg Founder/Coder/Designer
Pligg Version: SVN
Pligg Template: Wistie
 
Join Date: Dec 2005
Location: Ocala, FL
Posts: 3,800
Send a message via AIM to Yankidank Send a message via Skype™ to Yankidank
All known security issues should be patched by weeks end. Please be patient as we work on providing you with a solution as quickly as possible.

Now Available: Facebook Connect Module !
  #7 (permalink)  
Old 07-31-2008, 11:47 AM
New Pligger
 
Join Date: Jul 2008
Posts: 8
Quote:
Originally Posted by Yankidank View Post
All known security issues should be patched by weeks end. Please be patient as we work on providing you with a solution as quickly as possible.
I don't think you fully appreciate the issue here. It is highly recommended that anyone using 0.9.9 take their site OFFLINE immediately. The hacker used an exploit that allowed them to install a script called hello.php into the root directory of my installation. My provider only told me that the script was doing "bad things" and so they disabled my account which shut off 10 different websites. You should post what all of the known security issues are and the current code to fix them and you might actually get some help from your community in solving the problems.

I run a much larger open source project than this and I have found that you need to be as open as possible to your users and they will respond by giving you assistance during problems like this. If you keep try to minimize a significant problem like this, it only hurts you and the project.
  #8 (permalink)  
Old 07-31-2008, 01:56 PM
New Pligger
 
Join Date: Jul 2008
Posts: 8
For anyone that doesn't understand how bad this is, there is a very simple script available that you run and point to a pligg site, within about 2 seconds you have SHELL access to that site and can do anything you want. This isn't a simple page hack, this is a SERIOUS security problem that gives a hacker complete access to your entire hosting environment. Once you have shell access you can sit there and download files, edit files, install code, pretty much anything you want.
  #9 (permalink)  
Old 07-31-2008, 01:58 PM
New Pligger
 
Join Date: Sep 2006
Posts: 7
my website was hacked today! Yestersday I just upgrade it at Pligg Beta 9.9.0.
  #10 (permalink)  
Old 07-31-2008, 03:24 PM
New Pligger
 
Join Date: Sep 2006
Posts: 7
I digg the issue and I found how the attacker found my site:

"Powered By Pligg" - Google'da Ara

He search for Powered By Pligg!!

He modify my footer and put By BeyazKurt words.
Also put some redirect to a page.
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Where to download version 9.9.0? unv1 Questions and Comments 6 05-03-2009 08:03 PM
Moving servers and version 9.8 -> 9.9.0 johnsteel Questions and Comments 5 05-16-2008 04:21 PM
Does your Category load via version 9.9.0? Loz07 Questions and Comments 1 05-04-2008 10:30 PM
[SOLVED]  character issue - 9.9.0 animas Questions and Comments 2 01-30-2008 01:00 AM
[SOLVED] Version number doesn't update after upgrade AshMCairo Questions and Comments 8 12-13-2007 12:02 PM


Pligg Modules and Pligg Templates from Pligg Pro Find support on the Pligg CMS Forum - 24 hours a day! Make a donation to support Pligg CMS development