Greenguy's Board

Greenguy's Board (http://www.greenguysboard.com/board/index.php)
-   General Business Knowledge (http://www.greenguysboard.com/board/forumdisplay.php?f=10)
-   -   Security advisories for phpAdsNew & blogging software (http://www.greenguysboard.com/board/showthread.php?t=21627)

airdick 2005-07-04 11:24 PM

Security advisories for phpAdsNew & blogging software
 
I saw this advisory linked over on Slashdot for vulenabilities in php xml-rpc libraries used in a lot of blogging packages:

http://news.netcraft.com/archives/20..._exploits.html

The xml-rpc library in phpAdsNew is also vulnerable:

http://phpadsnew.com/two/nucleus/index.php

The good news is that you can protect phpAdsNew right now by simply deleting or moving a single file if you don't feel comfortable installing the upgrade on your own.

PhoneMistress 2005-07-05 09:20 AM

Thanks for the heads up.

If you are using WordPress, you need to upgrade to the 1.5.1.3. immediately. It is the only version that is not vulnerable.

http://wordpress.org/support/topic/38263

Useless 2005-07-05 11:43 AM

I just upgraded my phpadsnew this morning, yet I still feel vulnerable, but in an emotional sense, not a server security sense.

ArtWilliams 2005-07-05 02:40 PM

Thanks UW for the info!

Do you just have to replace that file or all files when you upgrade to the new version?

---art

Useless 2005-07-05 02:49 PM

Quote:

Originally Posted by artwilliams
Thanks UW for the info!

Do you just have to replace that file or all files when you upgrade to the new version?

---art

Thank airdick, not me. ;)

Your best bet is to just upgrade to the newest stable package. Download the new version. Untar or unzip it, back-up your old config.inc.php. Upload the new package to your server allowing it to overwrite all of the old files. Upload the old config.inc.php, which will overwrite the new one you just uploaded. Chmod that config.inc.php to 777. Log in to your phpadsnew control panel and proceed from there. It's quick and painless, just a couple of clicks. When it's complete (like 15-30 seconds later), chmod the config.inc.php back to 644. You're done.

ArtWilliams 2005-07-05 03:08 PM

Quote:

Originally Posted by Useless Warrior
Thank airdick, not me. ;)

Your best bet is to just upgrade to the newest stable package. Download the new version. Untar or unzip it, back-up your old config.inc.php. Upload the new package to your server allowing it to overwrite all of the old files. Upload the old config.inc.php, which will overwrite the new one you just uploaded. Chmod that config.inc.php to 777. Log in to your phpadsnew control panel and proceed from there. It's quick and painless, just a couple of clicks. When it's complete (like 15-30 seconds later), chmod the config.inc.php back to 644. You're done.

Thanks airdick and ... now thanks UW. ---art

natalie 2005-07-05 08:18 PM

I did the upgrade on phpadsnew and it wasnt hard.. just the db backups I did first were HUGE. hehe the server even locked me out of phpmyadmin for a few minutes lol. I had been putting it off till I read this so thanks guys for pulling my finger out :P


All times are GMT -4. The time now is 04:14 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc