Security Vulnerability

Register an Account
Pligg Chat Room
Closed Thread
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 05-27-2007, 12:43 AM
New Pligger
 
Join Date: Mar 2007
Posts: 3
ya this is bad news, but thankfully anyone who seriously runs a site should receive the email.

btw the upgrade worked fine for me, version 9.1

thx for letting us know
  #12 (permalink)  
Old 05-27-2007, 12:47 AM
New Pligger
 
Join Date: Dec 2006
Posts: 3
Quote:
Originally Posted by AshDigg View Post
For 8.2 follow the same instructions but use these files.
Had the same problem, loading upgrade.php (I am also under a modified version 8 of pligg) I only got a white window - I'm on a Mac. In the past, white php files showed some cross-platform problems, like different line endings or smart quotes or something, but I went through all what I know and it still returned just a white page.

At this point I am not sure if it upgraded all the same, because I replaced my original login.php file with the new one and I could log in.

I guess this means that the patch worked even if I only saw a white upgrade.php ??

Thanks.

---marlyse
  #13 (permalink)  
Old 05-27-2007, 01:10 AM
Pligg Donor
 
Join Date: Nov 2006
Posts: 40
Do we delete the upgrade_login.php file as well if all worked?
  #14 (permalink)  
Old 05-27-2007, 01:22 AM
wwwSENSERELYcom's Avatar
Casual Pligger
 
Join Date: May 2007
Location: Tianjin, China
Posts: 67
yes you can delete the file. but look into the file and see what it is doing to your database, and then check in your database to see if it has been done, so you'll know.

I am not a hacker so I don't know exactly what was a problem in the reset password way of doing things, but if it was there for many versions and nobody reported being hacked then it means hackers don't care YET about webmasters using pligg :-)
  #15 (permalink)  
Old 05-27-2007, 01:32 AM
Pligg Donor
 
Join Date: Nov 2006
Posts: 40
Ah k, I think it's just altering the "last_reset_code" row.

Mine now says:

last_reset_code varchar(255) latin1_swedish_ci Yes NULL
  #16 (permalink)  
Old 05-27-2007, 02:58 AM
New Pligger
 
Join Date: Mar 2007
Posts: 1
Hello Pligg,
thanks for the tip!!
  #17 (permalink)  
Old 05-27-2007, 03:12 AM
eon eon is offline
Casual Pligger
 
Join Date: May 2007
Posts: 38
Thank you for the update.
  #18 (permalink)  
Old 05-27-2007, 06:14 AM
New Pligger
 
Join Date: Mar 2007
Posts: 22
I was hacked yeserday!
  #19 (permalink)  
Old 05-27-2007, 07:07 AM
New Pligger
 
Join Date: May 2007
Posts: 1
worked fine to me with version 9.0
thx guys
  #20 (permalink)  
Old 05-27-2007, 07:09 AM
not2serious's Avatar
Pligg Donor
Pligg Version: v0.96 w/modifications
Pligg Template: Yget w/modifications
 
Join Date: Apr 2007
Location: East Coast, USA
Posts: 205
Upgraded 9.5 successfully.

Thank You.
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Vulnerability Part 2 AshDigg Questions and Comments 17 06-17-2007 02:28 PM
Pligg Security Vulnerability - Password Change Request sunstardude Questions and Comments 19 06-01-2007 01:53 PM


Pligg Modules and Pligg Templates from Pligg Pro Find support on the Pligg CMS Forum - 24 hours a day! Make a donation to support Pligg CMS development