Security Vulnerability

Register an Account
Pligg Chat Room
Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-26-2007, 11:08 PM
AshDigg's Avatar
Mayor of PliggVille/Coder
 
Join Date: Dec 2005
Posts: 1,515
A very serious bug has been found in _all_ versions of Pligg. We have a patch available here. We advise you to apply this immediately.

For 9.0, 9.1, 9.5 versions
1) upload the upgrade_login.php into your root Pligg folder. Not the install folder. Then open the file in your browser. If you have *any* errors, let us know as many details as you can so we can help you fix it.

2) upload the appropriate login.php file. Rename your existing /login.php file to /login.php.bak, rename the new one you just uploaded to /login.php. Please note, this is NOT the /libs/login.php file.

3) If you can login / logout without any problems, then delete the .bak file.

We expect to release a beta 9.5.1 (security update) before the end of the month to fix this and a few other bugs we found.

Thanks.

ps: if you want to manually edit your login file, look here.
Attached Files
File Type: php upgrade_login.php (352 Bytes, 680 views)
File Type: php 9.1_login.php (5.3 KB, 361 views)
File Type: php 9.5_login.php (5.6 KB, 569 views)
File Type: php 9.0_login.php (5.3 KB, 252 views)

Last edited by AshDigg; 05-27-2007 at 12:23 AM.
  #2 (permalink)  
Old 05-26-2007, 11:59 PM
New Pligger
 
Join Date: Dec 2006
Posts: 2
What exactly was the problem, and how bad of a risk is it to not apply this update?

(These questions should be addressed in all Security updates if possible)
  #3 (permalink)  
Old 05-27-2007, 12:05 AM
dollars5's Avatar
Pligg Donor
 
Join Date: Dec 2006
Location: India
Posts: 1,961
Pls check here Pligg Security Vulnerability - Password Change Request, there was a security hole which had the risk of site takeover - but thankfully Ash got it fixed sooner.

Pls take some additional precautions also as outlined in that thread to protect your site better.

Last edited by dollars5; 05-27-2007 at 12:44 AM.
  #4 (permalink)  
Old 05-27-2007, 12:09 AM
New Pligger
 
Join Date: Sep 2006
Posts: 2
One point I'd like to share is the note to change /login.php to /login.php.bak

I wouldn't leave any .bak extension files of any kind on a server. I've seen those exploited by hackers before.
  #5 (permalink)  
Old 05-27-2007, 12:15 AM
AshDigg's Avatar
Mayor of PliggVille/Coder
 
Join Date: Dec 2005
Posts: 1,515
Quote:
Originally Posted by robaubie View Post
One point I'd like to share is the note to change /login.php to /login.php.bak

I wouldn't leave any .bak extension files of any kind on a server. I've seen those exploited by hackers before.
Good point, update my instructions, thanks
  #6 (permalink)  
Old 05-27-2007, 12:15 AM
Constant Pligger
 
Join Date: Apr 2006
Posts: 100
What about earlier versions of Pligg? I am running a modified 8.2.
  #7 (permalink)  
Old 05-27-2007, 12:25 AM
AshDigg's Avatar
Mayor of PliggVille/Coder
 
Join Date: Dec 2005
Posts: 1,515
Quote:
Originally Posted by DuckFat View Post
What about earlier versions of Pligg? I am running a modified 8.2.
For 8.2 follow the same instructions but use these files.
Attached Files
File Type: php 8.2_login.php (4.8 KB, 207 views)
File Type: php upgrade_0.8.2.php (334 Bytes, 230 views)

Last edited by AshDigg; 05-27-2007 at 01:01 AM.
  #8 (permalink)  
Old 05-27-2007, 12:52 AM
Constant Pligger
 
Join Date: Apr 2006
Posts: 100
Okay, I did as instructed but when I brought up the upgrade_0.8.2.php file in my browser nothing is displayed but a blank white page. I am using FireFox. Is that what is supposed to happen? I was expecting at least a "patch applied" message.
  #9 (permalink)  
Old 05-27-2007, 01:02 AM
AshDigg's Avatar
Mayor of PliggVille/Coder
 
Join Date: Dec 2005
Posts: 1,515
Quote:
Originally Posted by DuckFat View Post
Okay, I did as instructed but when I brought up the upgrade_0.8.2.php file in my browser nothing is displayed but a blank white page.
I just replaced the file. Please try it again. thanks
  #10 (permalink)  
Old 05-27-2007, 01:08 AM
New Pligger
 
Join Date: Feb 2007
Posts: 24
Just thought I would throw this out there. As a Pligg community lets not throw this up on DIGG or any other information source that will attract hackers attention . If I am totally wrong I apologize
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Vulnerability Part 2 AshDigg Questions and Comments 17 06-17-2007 03:28 PM
Pligg Security Vulnerability - Password Change Request sunstardude Questions and Comments 19 06-01-2007 02:53 PM


Pligg Modules and Pligg Templates from Pligg Pro Find support on the Pligg CMS Forum - 24 hours a day! Make a donation to support Pligg CMS development