Webmaster Forum

Go Back   Webmaster Forum > Blogging > Blogging Forum

Blogging Forum Discuss general blogging issues here - design, integration, posting, trackbacks, ETC. Also discuss blogs you like.


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 09-09-2008, 06:24 AM
minstrel's Avatar
Senior Member
 
Join Date: 06-28-04
Location: Ottawa, Canada
Posts: 385
iTrader: 0 / 0%
minstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to beholdminstrel is a splendid one to behold
WordPress 2.6.2 released

WordPress 2.6.2
September 8, 2008

Quote:
Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand(). With his help we worked around these problems and are now releasing WordPress 2.6.2. If you allow open registration on your blog, you should definitely upgrade. With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password. The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit. However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password. Stefan Esser will release details of the complete attack shortly. The attack is difficult to accomplish, but its mere possibility means we recommend upgrading to 2.6.2.

Other PHP apps are susceptible to this class of attack. To protect all of your apps, grab the latest version of Suhosin. If you’ve already updated Suhosin, your existing WordPress install is already protected from the full exploit. You should still upgrade to 2.6.2 if you allow open user registration so as to prevent the possibility of passwords being randomized.

2.6.2 also contains a handful of bug fixes. Check out the full changeset and list of changed files.
Digg this Post!Add Post to del.icio.us
Reply With Quote
  #2 (permalink)  
Old 09-09-2008, 06:42 PM
KristysKnots's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 04-12-08
Location: Illinois
Posts: 1,313
iTrader: 0 / 0%
KristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web pro
geez, I haven't even gotten 2.6.1 upgrade.
Didn't know they came out with 2.6.2 already.
__________________
"Painting is poetry that is seen rather than felt, and poetry is painting that is felt rather than seen."
~Leonardo da Vinci
Digg this Post!Add Post to del.icio.us
Reply With Quote
  #3 (permalink)  
Old 09-09-2008, 11:38 PM
StarLab's Avatar
Super Moderator
 
Join Date: 10-29-07
Location: Ontario, Canada
Posts: 2,958
iTrader: 0 / 0%
StarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest orderStarLab is a web professional of the highest order
Send a message via MSN to StarLab Send a message via Yahoo to StarLab Send a message via Skype™ to StarLab
Quote:
Originally Posted by KristysKnots View Post
geez, I haven't even gotten 2.6.1 upgrade.
Didn't know they came out with 2.6.2 already.
Same here. Keeping up to the WP upgrades is starting to become a full time job. lol
__________________
Larry Monte
[Torn Elements] - Regaining the Passion for Design
[Gorgeous On Life] - The world from a Cat's point of view.

"Writing is the most fun you can have by yourself!" -Terry Pratchett
Digg this Post!Add Post to del.icio.us
Reply With Quote
  #4 (permalink)  
Old 09-10-2008, 05:37 AM
KristysKnots's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 04-12-08
Location: Illinois
Posts: 1,313
iTrader: 0 / 0%
KristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web pro
Quote:
Originally Posted by StarLab View Post
Same here. Keeping up to the WP upgrades is starting to become a full time job. lol
Yes it is! It is bad enough to have to keep up with plugin updates lol
__________________
"Painting is poetry that is seen rather than felt, and poetry is painting that is felt rather than seen."
~Leonardo da Vinci
Digg this Post!Add Post to del.icio.us
Reply With Quote
  #5 (permalink)  
Old 09-10-2008, 01:42 PM
Member
 
Join Date: 08-11-08
Location: Fargo
Posts: 60
iTrader: 0 / 0%
lukemeister is liked by many
All these updates make me glad I run the auto updater plugin. Easy enough to click on that whenever prompted in Wordpress to uprade and let the app do it for me.
Digg this Post!Add Post to del.icio.us
Reply With Quote
  #6 (permalink)  
Old 09-10-2008, 03:33 PM
KristysKnots's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 04-12-08
Location: Illinois
Posts: 1,313
iTrader: 0 / 0%
KristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web pro
Quote:
Originally Posted by lukemeister View Post
All these updates make me glad I run the auto updater plugin. Easy enough to click on that whenever prompted in Wordpress to uprade and let the app do it for me.
I have this uploaded but have never turned it on and used it.
hmm maybe its time I do it.
__________________
"Painting is poetry that is seen rather than felt, and poetry is painting that is felt rather than seen."
~Leonardo da Vinci
Digg this Post!Add Post to del.icio.us
Reply With Quote
  #7 (permalink)  
Old 09-10-2008, 03:50 PM
KristysKnots's Avatar
v7n Mentor
Latest Blog:
None

 
Join Date: 04-12-08
Location: Illinois
Posts: 1,313
iTrader: 0 / 0%
KristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web proKristysKnots is a highly respected web pro
Ok, I have a question before I try to use this auto upgrader plugin.

Is it really that easy? Turn it on and click it? Will it mess up my site in any way?

Guess I am afraid to screw somethin up
__________________
"Painting is poetry that is seen rather than felt, and poetry is painting that is felt rather than seen."
~Leonardo da Vinci
Digg this Post!Add Post to del.icio.us
Reply With Quote
  #8 (permalink)  
Old 09-10-2008, 04:02 PM
Member
 
Join Date: 08-11-08
Location: Fargo
Posts: 60
iTrader: 0 / 0%
lukemeister is liked by many
Quote:
Originally Posted by KristysKnots View Post
Ok, I have a question before I try to use this auto upgrader plugin.

Is it really that easy? Turn it on and click it? Will it mess up my site in any way?

Guess I am afraid to screw somethin up
You'll need to enter your ftp info for your web site the first time, and need to enter your ftp password each time (unless your browser remembers it)...

But it pretty much is that easy. The first bunch of times I updated my Wordpress sites with the auto-updater I was kinda nervous and crossed my fingers each time, but it always works for me and I've never had a site crash or anything during upgrade.
Digg this Post!Add Post to del.icio.us
Reply With Quote
Go Back   Webmaster Forum > Blogging > Blogging Forum

Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
WordPress 2.3 Released Jeffro2pt0 Blogging Forum 9 10-03-2007 11:14 PM
New Version Of WordPress Released Jeffro2pt0 Blogging Forum 0 09-07-2007 11:20 PM
WordPress 2.2.2 Released Jeffro2pt0 Blogging Forum 11 08-18-2007 12:16 PM
WordPress 2.0.5 (RONAN) has been released. Avinash Blogging Forum 2 11-01-2006 03:39 AM


Sponsor Links
Get exposure! Contextual Links V7N SEO Blog V7N Directory


Site Navigation: v7n Home .::. Graphics .::. Scripts .::. V7N Web Directory .::. V7N Technology Blog .::. V7N Affiliate Program .::. Advertise

Partners: Search Engine Optimisation .::. Dedicated Server Hosting .::. Webmaster Talk .::. CPA Affiliates .::. Dedicated Server Hosting

Site Sponsored by a Hivelocity Dedicated Server.
SEO Consult, International SEO Experts
Dedicated Server Hosting
All times are GMT -7. The time now is 02:04 PM.
© Copyright 2008 V7 Inc
Powered by vBulletin
Copyright © 2000-2009 Jelsoft Enterprises Limited.


Search Engine Optimization by vBSEO 3.3.0 ©2009, Crawlability, Inc.