PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > General Forums > General Discussion

General Discussion General use discussion forum for PhotoPost products.

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old March 28th, 2005, 06:11 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: Feb 2002
Posts: 47
Security Alert: XSS and MySQL injection flaws

I've just noticed a security alert that apparently affects all current photopost installations. The alert goes into detail on how to attack/hack our software installations. This doesn't appear to be published on the securityfocus website yet.

Are you aware of this yet Michael? Did hackerscenter contact you about this prior to publishing their findings?

Last edited by c0bra; March 28th, 2005 at 06:14 PM.
c0bra is offline   Reply With Quote
Old March 28th, 2005, 06:13 PM   #2 (permalink)
Member
Verified Customer
 
Join Date: Feb 2002
Posts: 47
Here is the advisory:
http://icis.digitalparadox.org/~dcrab/ppgs.txt
c0bra is offline   Reply With Quote
Old March 28th, 2005, 06:14 PM   #3 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,695
No one has contacted our main email account on any issues

I know any VALID flaws have been fixed to date.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old March 28th, 2005, 06:16 PM   #4 (permalink)
Member
Verified Customer
 
Join Date: Feb 2002
Posts: 47
This was just released about two hours ago. These look like new findings to me.
c0bra is offline   Reply With Quote
Old March 28th, 2005, 06:24 PM   #5 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,695
There have been no reports to our photopost contact email.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old March 28th, 2005, 08:12 PM   #6 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,834
They aren't new; they are rehashed old reports resolved months ago in the 4.8x series. I see nothing new to these issues posted here (in fact, the GulfTech who reported the issues to us months ago took offense to their rehashing of his old info).
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Old March 29th, 2005, 02:25 PM   #7 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Michael:

We ran across one in our list as well:

http://secunia.com/advisories/14742/

I think that might be from the same source as mentioned by cobra but JIC can you verify that those aren't new as well?

Thanks.
WB is offline   Reply With Quote
Old March 29th, 2005, 03:49 PM   #8 (permalink)
PhotoPost Developer
Verified Customer
 
Join Date: Jan 2002
Posts: 11,834
Once again, these appear to be rehashed issues with a release that was out for a day or two (5.0) and were quickly fixed. Their report is inaccurate as they are no longer issues with the 5.01 or 5.02 releases.
__________________
Please do not PM me for support or sales questions. Thank you for your understanding.
Michael P is offline   Reply With Quote
Old March 29th, 2005, 03:53 PM   #9 (permalink)
WB
Member
Verified Customer
 
Join Date: Jan 2002
Posts: 265
Great, thanks for confirming.
WB is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
vb3.0.8 XSS question vbusers11 Before You Buy 1 August 23rd, 2005 10:37 PM
Security Announcement: PhotoPost Immune from EXIF PHP Security Flaw Michael P General Discussion 0 December 22nd, 2004 08:10 AM
character flaws tribedude Photopost Pro Installation & Upgrades 1 October 26th, 2004 09:49 PM
sql injection attacks stmpspaz General Discussion 1 July 3rd, 2004 09:55 AM


All times are GMT -5. The time now is 04:55 PM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0