Akopia Akopia Services

[Date Prev][Date Next][Thread Prev][Thread Next][Minivend by date ][Minivend by thread ]

Re: [mv] 4.04a security update



Curt,
 
Thanks for your help =) I really appreciate it.
----- Original Message -----
From: Curt Hauge
Sent: Friday, July 21, 2000 3:15 PM
Subject: RE: [mv] 4.04a security update

If you haven't received an answer yet...

(quoting Mike Heins)

[snip]

I do recognize the problem with Util.pm, and have corrected it,

I believe.

I recommend all people remove view_page.html from their sites and

apply this patch:

*** minivend-4.04/lib/Vend/Util.pm Wed Apr 12 11:07:04 2000

--- minivend-4.04a/lib/Vend/Util.pm Wed Jul 5 07:06:06 2000

*************** sub readfile {

*** 807,812 ****

--- 807,813 ----

return undef;

}

+ return undef if ! -f $file;

return undef if ! open(READIN, $file);

binmode(READIN) if $Global::Windows;

### END PATCH

If you need the functionality of view_page.html, you can apply

this patch to close up the hole temporarily:

*** minivend-4.04/dist/simple/pages/view_page.html Thu Mar 9 14:08:17 2000

--- minivend-4.04a/dist/simple/pages/view_page.html Wed Jul 5 07:10:49 2000

***************

*** 1,7 ****

[new]

[if !session arg]

No argument given.

! [elsif session arg =~ /^\/|\.\./]

<H1>Why would you do something <FONT COLOR=__CONTRAST__>naughty</FONT>like putting

a leading slash or a .. in your URL? HMM???? I will use a new feature: Log("Attack from " . $Session->{remote_addr}). [mvasp] <% Log($Session->{remote_addr}) %>[/mvasp]

[/elsif]

--- 1,7 ----

[new]

[if !session arg]

No argument given.

! [elsif session arg =~ /^\/|\.\.|\|/]

<H1>Why would you do something <FONT COLOR=__CONTRAST__>naughty</FONT>like putting

a leading slash or a .. in your URL? HMM???? I will use a new feature: Log("Attack from " . $Session->{remote_addr}). [mvasp] <% Log($Session->{remote_addr}) %>[/mvasp]

[/elsif]

-----Original Message-----
From: owner-minivend-users@minivend.com [mailto:owner-minivend-users@minivend.com]On Behalf Of Steven J Morrison
Sent: Wednesday, July 19, 2000 11:45 PM
To: minivend-users@minivend.com
Subject: [mv] 4.04a security update

Hi everyone,
 
I recently configured 4.04 and am just now learning of the security issues.  What is the easiest way to move to 4.04a without losing anything? Can I just make a fresh install and then copy all my pages/catalog.cfg/databases over, or is it easier just to replace a couple of offending files?
 
Please respond.  Thanks.

--------
 
Steven Morrison
ICQ 862420
This message was printed on 100% recycled electrons.

Search for: Match: Format: Sort by: