<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MyTestBox.com :: web software reviews, news, tips and tricks &#187; security</title>
	<atom:link href="http://www.mytestbox.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mytestbox.com</link>
	<description>experimenting with the future</description>
	<lastBuildDate>Tue, 18 May 2010 21:17:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Security update from Wordpress: version 2.6.2</title>
		<link>http://www.mytestbox.com/news/wordpress-open-source-blog-software-version262/</link>
		<comments>http://www.mytestbox.com/news/wordpress-open-source-blog-software-version262/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 17:15:42 +0000</pubDate>
		<dc:creator>Mircea Goia</dc:creator>
				<category><![CDATA[MyTestBox News]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blog software]]></category>
		<category><![CDATA[open-source]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[version]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.mytestbox.com/news/wordpress-open-source-blog-software-version262/</guid>
		<description><![CDATA[


			
				
			
		
If you have a blog and allow open registration, then you definitely need to upgrade to this version!
&#160;
There&#8217;s a security hole in the actual version of Wordpress which allows an attacker to randomly change passwords of other registered users (done by crafting an username). The passwords won&#8217;t be revealed to the attacker himself, but it [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start -->
<!-- ALL ADSENSE ADS DISABLED -->
<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.mytestbox.com%2Fnews%2Fwordpress-open-source-blog-software-version262%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.mytestbox.com%2Fnews%2Fwordpress-open-source-blog-software-version262%2F&amp;source=mytestbox&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.mytestbox.com/wp-content/uploads/2008/06/wordpress_logo.gif" title="Wordpress logo"><img src="http://www.mytestbox.com/wp-content/uploads/2008/06/wordpress_logo.gif" style="border-width: 0px; margin: 10px; width: 319px; height: 85px" title="Wordpress logo" alt="Wordpress logo" align="left" border="0" vspace="10" width="319" height="85" hspace="10" /></a>If you have a blog and allow open registration, then you definitely need to upgrade to this version!</p>
<p align="left">&nbsp;</p>
<p>There&#8217;s a security hole in the actual version of Wordpress which allows an attacker to randomly change passwords of other registered users (done by crafting an username). The passwords won&#8217;t be revealed to the attacker himself, but it is annoying for users to have their passwords changed suddenly. This attack, coupled with a weakness in the random number seeding in mt_rand(), could be used to predict the randomly-generated password (which is not something you want).</p>
<p><a href="http://www.suspekt.org/" target="_blank">Stefan Esser</a> brought the attack to the attention of the Wordpress team, which also helped them fix another problem (<a href="http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/" target="_blank">SQL Column truncation danger</a>  and <a href="http://www.suspekt.org/2008/08/17/mt_srand-and-not-so-random-numbers/" target="_blank">weakness of mt_rand()</a> ).</p>
<p>The new version of Wordpress also has a handful of bug fixes (checkout the <a href="http://trac.wordpress.org/query?status=closed&amp;milestone=2.6.2&amp;resolution=fixed&amp;order=priority" target="_blank">forum</a>). See the <a href="http://trac.wordpress.org/changeset?old_path=tags%2F2.6.1&amp;old=8849&amp;new_path=tags%2F2.6.2&amp;new=8849" target="_blank">full changeset and list of changed files</a>.</p>
<p>To keep up with Wordpress development, checkout their <a href="http://wordpress.org/development/2008/09/wordpress-262/" target="_blank">blog</a>.</p>
<p>&copy;2010 <a href="http://www.mytestbox.com">MyTestBox.com :: web software reviews, news, tips and tricks</a>. All Rights Reserved.</p>.<!-- sphereit end --><span style="margin-bottom:40px; border-bottom:none;"><a class="iconsphere" title="Sphere: Related Content" onclick="return Sphere.Widget.search('http://www.mytestbox.com/news/wordpress-open-source-blog-software-version262/')" href="http://www.sphere.com/search?q=sphereit:http://www.mytestbox.com/news/wordpress-open-source-blog-software-version262/"><strong>Sphere: Related Content</strong></a></span><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.mytestbox.com/news/wordpress-open-source-blog-software-version262/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dolphin Smart Community Builder 6.1.4 Security Patch Release</title>
		<link>http://www.mytestbox.com/news/boonex-dolphin-community-software-release614/</link>
		<comments>http://www.mytestbox.com/news/boonex-dolphin-community-software-release614/#comments</comments>
		<pubDate>Wed, 30 Jul 2008 15:00:36 +0000</pubDate>
		<dc:creator>Mircea Goia</dc:creator>
				<category><![CDATA[MyTestBox News]]></category>
		<category><![CDATA[boonex]]></category>
		<category><![CDATA[community software]]></category>
		<category><![CDATA[dolphin]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social network]]></category>

		<guid isPermaLink="false">http://www.mytestbox.com/news/boonex-dolphin-community-software-release614/</guid>
		<description><![CDATA[


			
				
			
		
BoonEx  (the australian company behind Dolphin Smart Community Builder and other software) release a security patch for its dating and social network software.
This fixes the XSS (Cross Site Scripting) vulnerability found the last week (Orca version allows inserting malicious code into a new topic title).
&#160;
It is an easy patch to apply so you should do [...]]]></description>
			<content:encoded><![CDATA[<!-- sphereit start -->
<!-- ALL ADSENSE ADS DISABLED -->
<div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.mytestbox.com%2Fnews%2Fboonex-dolphin-community-software-release614%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.mytestbox.com%2Fnews%2Fboonex-dolphin-community-software-release614%2F&amp;source=mytestbox&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.mytestbox.com/wp-content/uploads/2008/07/boonex_dolphin_logo.gif" title="Boonex Dolphin logo"><img src="http://www.mytestbox.com/wp-content/uploads/2008/07/boonex_dolphin_logo.gif" style="border-width: 0px; margin: 10px; width: 243px; height: 83px" title="Boonex Dolphin community software logo" alt="Boonex Dolphin logo" align="left" border="0" vspace="10" width="243" height="83" hspace="10" /></a><a href="http://www.boonex.com" target="_blank" title="Boonex">BoonEx</a>  (the australian company behind Dolphin Smart Community Builder and other software) release a security patch for its dating and social network software.<br />
This fixes the XSS (Cross Site Scripting) vulnerability found the last week (Orca version allows inserting malicious code into a new topic title).</p>
<p align="left">&nbsp;</p>
<p>It is an easy patch to apply so you should do it immediately!Here are the steps to be followed:<br />
<strong>*</strong> Backup the Orca and groups/orca folders (a regular backup never hurts anyway!)<br />
<strong>*</strong> Get the patch named Dolphin 6.1 Patch 4. This is compatible with any Dolphin package: SmartPro, AdFree, Free<br />
<strong>*</strong> Unzip the archive and upload its content to the folder where you have Dolphin installed (overwriting the files with the same names)</p>
<p>Example: Open the &#8220;orca&#8221; directory on your server, and at the same time open the &#8220;orca&#8221; directory in the extracted patch on your PC. Upload all files contained in the &#8220;orca&#8221; directory of the patch to your server&#8217;s &#8220;orca&#8221; directory overwriting those with the same names.</p>
<p><strong>*</strong> Edit the build number in the inc/header.inc.php file, replacing $site['build'] = &#8216;3&#8242;; with $site['build'] = &#8216;4&#8242;;<br />
<strong>*</strong> Go and login to the admin panel and recompile Orca languages as described there.</p>
<p align="left">&nbsp;</p>
<p>After all these steps you should have Dolphin 6.1.4 patch successfully installed.</p>
<p>The company can be contacted for support, if you need to at, <em>support@boonex.com</em> (you can also login to <a href="http://boonex.com/unity/forums/" target="_blank">their Forums and ask questions</a>  or see the <a href="http://www.boonex.com/unity/answers/home" target="_blank">Answers questions)</a></p>
<p align="left">&nbsp;</p>
<p><em><strong>About Dolphin community builder</strong></em><br />
<a href="http://www.boonex.com/products/dolphin/" target="_blank">Dolphin Smart Community Builder</a> is a free, open source software that allows you to build any kind of online community. Social networks, dating sites, content sharing portals&#8230;all these can be created very easily and deployed in an instant. You can have Myspace, Youtube, Flickr, Facebook and Match combined in one package.<br />
With a huge variety of features &amp; options, you can quickly develop your very unique and successful website. <a href="http://www.boonex.com/products/dolphin/features/" target="_blank">Checkout the full features here</a>!</p>
<p>It is written in PHP/MySQL so it runs well on Unix/Linux but also it can run on Windows (but you have to use Apache for Windows, not IIS web server).</p>
<p>See a demo of their product here: http://www.boonex.us/ (a demo of <a href="http://www.demozzz.com/dolphin/admindemo/admin/" target="_blank">their admin section is here</a>)</p>
<p align="left"> <a href="http://www.boonex.com/products/dolphin/download/">Download Dolphin smart community builder here</a>!  (the free version, you can also order a paid version which will be ad free).</p>
<p>&copy;2010 <a href="http://www.mytestbox.com">MyTestBox.com :: web software reviews, news, tips and tricks</a>. All Rights Reserved.</p>.<!-- sphereit end --><span style="margin-bottom:40px; border-bottom:none;"><a class="iconsphere" title="Sphere: Related Content" onclick="return Sphere.Widget.search('http://www.mytestbox.com/news/boonex-dolphin-community-software-release614/')" href="http://www.sphere.com/search?q=sphereit:http://www.mytestbox.com/news/boonex-dolphin-community-software-release614/"><strong>Sphere: Related Content</strong></a></span><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.mytestbox.com/news/boonex-dolphin-community-software-release614/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
