Security Vulnerability Part 2

Register an Account
Pligg Chat Room
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-28-2007, 06:22 PM
AshDigg's Avatar
Mayor of PliggVille/Coder
 
Join Date: Dec 2005
Posts: 1,515
I'm very sorry to inform you that the patch I posted the other day created another very serious problem. We have a patch available here and advise you to apply this immediately. If you have not installed the first patch, you don't need to, just install this one. If you did install the first patch, then just replace the login file.

I'm very sorry for the inconvenience and thank you for your support.




If you upgrade to Beta 9.6 it already has the fix included.


Instructions for Beta 9.0, 9.1 and 9.5

1) upload the upgrade_login.php into your root Pligg folder. Not the install folder. Then open the file in your browser. If you have *any* errors, let us know as many details as you can so we can help you fix it. This only needs to be done once, so if you did it within the last 2 days you don't need to again.

2) upload the appropriate login.php file. Rename your existing /login.php file to /login.php.bak, rename the new one you just uploaded to /login.php. Please note, this is NOT the /libs/login.php file.

3) If you can login / logout without any problems, then delete the .bak file.
Attached Files
File Type: php upgrade_login.php (352 Bytes, 332 views)
File Type: php 9.5_login.php (5.7 KB, 307 views)
File Type: php 9.1_login.php (5.3 KB, 243 views)
File Type: php 9.0_login.php (5.4 KB, 163 views)

Last edited by AshDigg; 05-28-2007 at 07:50 PM.
Reply With Quote
  #2 (permalink)  
Old 05-28-2007, 06:22 PM
AshDigg's Avatar
Mayor of PliggVille/Coder
 
Join Date: Dec 2005
Posts: 1,515
Instructions for Beta 8.2

1) upload the upgrade_0.8.2.php into your root Pligg folder. Not the install folder. Then open the file in your browser. If you have *any* errors, let us know as many details as you can so we can help you fix it. This only needs to be done once, so if you did it within the last 2 days you don't need to again.

2) upload the 8.2_login.php file. Rename your existing /login.php file to /login.php.bak, rename the new one you just uploaded to /login.php. Please note, this is NOT the /libs/login.php file.

3) If you can login / logout without any problems, then delete the .bak file.

If the upgrade file just shows a blank page, try to run this in phpMyAdmin.

Code:
ALTER TABLE `users` ADD `last_reset_code` varchar(255) default NULL
Attached Files
File Type: php upgrade_0.8.2.php (250 Bytes, 156 views)
File Type: php 8.2_login.php (4.9 KB, 156 views)

Last edited by AshDigg; 05-28-2007 at 07:03 PM.
Reply With Quote
  #3 (permalink)  
Old 05-28-2007, 06:22 PM
AshDigg's Avatar
Mayor of PliggVille/Coder
 
Join Date: Dec 2005
Posts: 1,515
Instructions for Beta 7.2

1) upload the upgrade_0.7.2.php into your root Pligg folder. Not the install folder. Then open the file in your browser. If you have *any* errors, let us know as many details as you can so we can help you fix it. This only needs to be done once, so if you did it within the last 2 days you don't need to again.

2) upload the 7.2_login.php file. Rename your existing /login.php file to /login.php.bak, rename the new one you just uploaded to /login.php. Please note, this is NOT the /libs/login.php file.

3) If you can login / logout without any problems, then delete the .bak file.

If the upgrade file just shows a blank page, try to run this in phpMyAdmin.

Code:
ALTER TABLE `users` ADD `last_reset_code` varchar(255) default NULL
Attached Files
File Type: php upgrade_0.7.2.php (250 Bytes, 160 views)
File Type: php 7.2_login.php (4.3 KB, 141 views)

Last edited by AshDigg; 05-28-2007 at 07:03 PM.
Reply With Quote
  #4 (permalink)  
Old 05-28-2007, 08:19 PM
Fernandojs's Avatar
New Pligger
 
Join Date: Feb 2007
Location: Curitiba - BR
Posts: 19
Thanks!

upgrade is complete!
Reply With Quote
  #5 (permalink)  
Old 05-28-2007, 08:48 PM
dollars5's Avatar
Pligg Donor
 
Join Date: Dec 2006
Location: India
Posts: 1,961
NP m8, atleast you found it earlier and fixed it sooner before it hasbeen exploited - kudoos to you and thanks for the fix.
Reply With Quote
  #6 (permalink)  
Old 05-28-2007, 09:11 PM
New Pligger
 
Join Date: Mar 2007
Posts: 5
Thanks for the heads up!
Reply With Quote
  #7 (permalink)  
Old 05-28-2007, 09:17 PM
Constant Pligger/Designer
Pligg Version: 1.0
Pligg Template: silverbullet
 
Join Date: Mar 2007
Posts: 144
Send a message via MSN to skins4webs
Thanks again.

Upgrade was successful.
Reply With Quote
  #8 (permalink)  
Old 05-28-2007, 09:24 PM
New Pligger
 
Join Date: Dec 2006
Posts: 3
this worked really well - and this time there was no white page here :-)
Reply With Quote
  #9 (permalink)  
Old 05-28-2007, 10:35 PM
bichopro's Avatar
New Pligger
 
Join Date: Feb 2007
Posts: 9
Thanks so much
Reply With Quote
  #10 (permalink)  
Old 05-29-2007, 12:29 AM
Casual Pligger
 
Join Date: Mar 2007
Location: Salem, Oregon
Posts: 31
Send a message via Skype™ to harlem
thanks for catching it early and for an even quicker response.
Reply With Quote
Reply

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Pligg Security Vulnerability - Password Change Request sunstardude Questions and Comments 19 06-01-2007 01:53 PM
Security Vulnerability AshDigg Questions and Comments 36 05-28-2007 07:10 PM


Pligg Modules and Pligg Templates from Pligg Pro Find support on the Pligg CMS Forum - 24 hours a day! Make a donation to support Pligg CMS development