Webmaster Forum

Go Back   Webmaster Forum > Blogging > Blogging Forum

Blogging Forum Discuss general blogging issues here - design, integration, posting, trackbacks, ETC. Also discuss blogs you like.


Reply
 
LinkBack Thread Tools Display Modes
Old 09-09-2008, 06:24 AM   #1 (permalink)
Senior Member
 
minstrel's Avatar
 
Join Date: 06-28-04
Location: Ottawa, Canada
Posts: 385
iTrader: 0 / 0%
minstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to behold
WordPress 2.6.2 released

WordPress 2.6.2
September 8, 2008

Quote:
Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand(). With his help we worked around these problems and are now releasing WordPress 2.6.2. If you allow open registration on your blog, you should definitely upgrade. With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password. The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit. However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password. Stefan Esser will release details of the complete attack shortly. The attack is difficult to accomplish, but its mere possibility means we recommend upgrading to 2.6.2.

Other PHP apps are susceptible to this class of attack. To protect all of your apps, grab the latest version of Suhosin. If you’ve already updated Suhosin, your existing WordPress install is already protected from the full exploit. You should still upgrade to 2.6.2 if you allow open user registration so as to prevent the possibility of passwords being randomized.

2.6.2 also contains a handful of bug fixes. Check out the full changeset and list of changed files.
minstrel is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-09-2008, 06:42 PM   #2 (permalink)
v7n Mentor
 
KristysKnots's Avatar
 
Join Date: 04-12-08
Location: Illinois
Posts: 1,287
iTrader: 0 / 0%
Latest Blog:
Year's End

KristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web pro
geez, I haven't even gotten 2.6.1 upgrade.
Didn't know they came out with 2.6.2 already.
__________________
"Painting is poetry that is seen rather than felt, and poetry is painting that is felt rather than seen."
~Leonardo da Vinci
KristysKnots is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-09-2008, 11:38 PM   #3 (permalink)
Super Moderator
 
StarLab's Avatar
 
Join Date: 10-29-07
Location: Ontario, Canada
Posts: 2,745
iTrader: 0 / 0%
StarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest order
Send a message via MSN to StarLab Send a message via Yahoo to StarLab
Quote:
Originally Posted by KristysKnots View Post
geez, I haven't even gotten 2.6.1 upgrade.
Didn't know they came out with 2.6.2 already.
Same here. Keeping up to the WP upgrades is starting to become a full time job. lol
__________________
Larry Monte
[Torn Elements] - Regaining the Passion for Design
[Gorgeous On Life] - The world from a Cat's point of view.

"Writing is the most fun you can have by yourself!" -Terry Pratchett
StarLab is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-10-2008, 05:37 AM   #4 (permalink)
v7n Mentor
 
KristysKnots's Avatar
 
Join Date: 04-12-08
Location: Illinois
Posts: 1,287
iTrader: 0 / 0%
Latest Blog:
Year's End

KristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web pro
Quote:
Originally Posted by StarLab View Post
Same here. Keeping up to the WP upgrades is starting to become a full time job. lol
Yes it is! It is bad enough to have to keep up with plugin updates lol
__________________
"Painting is poetry that is seen rather than felt, and poetry is painting that is felt rather than seen."
~Leonardo da Vinci
KristysKnots is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-10-2008, 01:42 PM   #5 (permalink)
Member
 
Join Date: 08-11-08
Location: Fargo
Posts: 60
iTrader: 0 / 0%
lukemeister is liked by many
All these updates make me glad I run the auto updater plugin. Easy enough to click on that whenever prompted in Wordpress to uprade and let the app do it for me.
lukemeister is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-10-2008, 03:33 PM   #6 (permalink)
v7n Mentor
 
KristysKnots's Avatar
 
Join Date: 04-12-08
Location: Illinois
Posts: 1,287
iTrader: 0 / 0%
Latest Blog:
Year's End

KristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web pro
Quote:
Originally Posted by lukemeister View Post
All these updates make me glad I run the auto updater plugin. Easy enough to click on that whenever prompted in Wordpress to uprade and let the app do it for me.
I have this uploaded but have never turned it on and used it.
hmm maybe its time I do it.
__________________
"Painting is poetry that is seen rather than felt, and poetry is painting that is felt rather than seen."
~Leonardo da Vinci
KristysKnots is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-10-2008, 03:50 PM   #7 (permalink)
v7n Mentor
 
KristysKnots's Avatar
 
Join Date: 04-12-08
Location: Illinois
Posts: 1,287
iTrader: 0 / 0%
Latest Blog:
Year's End

KristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web pro
Ok, I have a question before I try to use this auto upgrader plugin.

Is it really that easy? Turn it on and click it? Will it mess up my site in any way?

Guess I am afraid to screw somethin up
__________________
"Painting is poetry that is seen rather than felt, and poetry is painting that is felt rather than seen."
~Leonardo da Vinci
KristysKnots is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-10-2008, 04:02 PM   #8 (permalink)
Member
 
Join Date: 08-11-08
Location: Fargo
Posts: 60
iTrader: 0 / 0%
lukemeister is liked by many
Quote:
Originally Posted by KristysKnots View Post
Ok, I have a question before I try to use this auto upgrader plugin.

Is it really that easy? Turn it on and click it? Will it mess up my site in any way?

Guess I am afraid to screw somethin up
You'll need to enter your ftp info for your web site the first time, and need to enter your ftp password each time (unless your browser remembers it)...

But it pretty much is that easy. The first bunch of times I updated my Wordpress sites with the auto-updater I was kinda nervous and crossed my fingers each time, but it always works for me and I've never had a site crash or anything during upgrade.
lukemeister is offline  
Add Post to del.icio.us
Reply With Quote
Go Back   Webmaster Forum > Blogging > Blogging Forum

Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
WordPress 2.3 Released Jeffro2pt0 Blogging Forum 9 10-03-2007 11:14 PM
New Version Of WordPress Released Jeffro2pt0 Blogging Forum 0 09-07-2007 11:20 PM
WordPress 2.2.2 Released Jeffro2pt0 Blogging Forum 11 08-18-2007 12:16 PM
WordPress 2.0.5 (RONAN) has been released. Avinash Blogging Forum 2 11-01-2006 03:39 AM


Sponsor Links
Get exposure! Contextual Links V7N SEO Blog V7N Directory


All times are GMT -7. The time now is 07:20 PM.
© Copyright 2008 V7 Inc
Powered by vBulletin
Copyright © 2000-2009 Jelsoft Enterprises Limited.


Search Engine Optimization by vBSEO 3.3.0 ©2009, Crawlability, Inc.