Advertisement

DocMAN 1.3.0 RC2

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
User avatar
PhilTaylor-Prazgod
Joomla! Ace
Joomla! Ace
Posts: 1408
Joined: Sat Aug 20, 2005 12:32 pm
Location: Jersey, Channel Islands
Contact:

DocMAN 1.3.0 RC2

Post by PhilTaylor-Prazgod » Thu Aug 23, 2007 8:40 pm

Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/

Advertisement
User avatar
Jinx
Joomla! Champion
Joomla! Champion
Posts: 6508
Joined: Fri Aug 12, 2005 12:47 am
Contact:

Re: DocMAN 1.3.0 RC2

Post by Jinx » Thu Aug 23, 2007 9:02 pm

Thanks, we are working on a 1.4 beta which is expected to be release at the beginning of september. I have forwared this to the current maintainer of DOCman to make sure it is fixed for the new release.
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5

http://www.joomlatools.com - Joomla extensions that just work

User avatar
infograf768
Joomla! Master
Joomla! Master
Posts: 19133
Joined: Fri Aug 12, 2005 3:47 pm
Location: **Translation Matters**

Re: DocMAN 1.3.0 RC2

Post by infograf768 » Fri Aug 24, 2007 4:35 pm

@PhilTaylor
PhilTaylor-Prazgod wrote: DocMAN 1.3.0 RC2
http://cve.mitre.org/cgi-bin/cvename.cg ... -2007-0380
I received your mail.
I sort of understand you know how to protect Docman users at reading it.
Could you provide the patch?
Jean-Marie Simonet / infograf
---------------------------------
ex-Joomla Translation Coordination Team • ex-Joomla! Production Working Group

User avatar
PhilTaylor-Prazgod
Joomla! Ace
Joomla! Ace
Posts: 1408
Joined: Sat Aug 20, 2005 12:32 pm
Location: Jersey, Channel Islands
Contact:

Re: DocMAN 1.3.0 RC2

Post by PhilTaylor-Prazgod » Fri Aug 24, 2007 4:39 pm

I have no solution - I cant even find the problem after a quick glance.  :-\ I am chatting to Beat about this - whatever the vulnerability, its not an obvious one.

Beat has identified some problem areas to look into following this, but cannot replicate any injections yet.

I have contacted the original reporter (the "hacker") and hope to get more technical details.
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/

User avatar
Jinx
Joomla! Champion
Joomla! Champion
Posts: 6508
Joined: Fri Aug 12, 2005 12:47 am
Contact:

Re: DocMAN 1.3.0 RC2

Post by Jinx » Fri Aug 24, 2007 10:40 pm

Phil,

I'm seriously dissapointed by the way you have handled this issue. You have spread ungrounded fear amongst many DOCman users abusing your company and personal communication channels. What makes it even worse is that you now openly admit you didn't do any due diligence on the security issue reported, you didn't check it nor did you email the current DOCman maintainer or myself about it before taking any other steps. It really makes me wonder about your intentions ?

For the record, DOCMan is one of the most secure components available for Joomla! and Mambo. DOCman is around since the very early days has always been very popular and we have never encountered any major security issues. Those we found where addressed as soon as possible.

This is pretty amazing seen the fact that DOCman has always been a voluntary project worked on by a number of different people over the past 5 years. It has a great community that relies on it and helps to move it forward. It has offcourse it's weaknesses and it's strength, security being definitely a strength.

One good piece of advice Phil, you are free to take it or leave it, next time instead of spreading fear try to do things the Joomla! way. Send the maintainer of the extension a personal email about the security issue.  Maybe even try to verify the actual issue that is being reported. Creating a quick patch to solve it once found shouldn't be that hard for a seasoned 'joomla security expert' like yourselves no ? I'm sure the maintainer of the extension will appreciate it and so will all Joomla! users.

Open source development and "Jumla" development is about contributing, think about it !

Sincerely,

Johan Janssens
DOCman project manager
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5

http://www.joomlatools.com - Joomla extensions that just work

User avatar
PhilTaylor-Prazgod
Joomla! Ace
Joomla! Ace
Posts: 1408
Joined: Sat Aug 20, 2005 12:32 pm
Location: Jersey, Channel Islands
Contact:

Re: DocMAN 1.3.0 RC2

Post by PhilTaylor-Prazgod » Fri Aug 24, 2007 10:54 pm

Johan

I choose to take my advice from people I respect, unfortunately you are not one of those.

Phil
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/

User avatar
mediamagnate
Joomla! Explorer
Joomla! Explorer
Posts: 315
Joined: Fri Aug 12, 2005 2:09 pm
Location: Shepparton
Contact:

Re: DocMAN 1.3.0 RC2

Post by mediamagnate » Fri Aug 24, 2007 11:53 pm

PhilTaylor-Prazgod wrote: Johan

I choose to take my advice from people I respect, unfortunately you are not one of those.

Phil
Phil, I think you could do well to take some of Johan's advice.  Were you not the person who told the world that Joomla! was not going to be GPL — then the blog amazingly disappeared?  You have a history of rather humiliating faux pas — generally opening your mouth before engaging your brain.

Please try to think before you post in future.  You're the one this reflects badly upon.  Common courtesy is a two way street.
Joomla is a project, not a product! www.nooku.org

User avatar
PhilTaylor-Prazgod
Joomla! Ace
Joomla! Ace
Posts: 1408
Joined: Sat Aug 20, 2005 12:32 pm
Location: Jersey, Channel Islands
Contact:

Re: DocMAN 1.3.0 RC2

Post by PhilTaylor-Prazgod » Fri Aug 24, 2007 11:57 pm

Stand for something or fall for everything
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/

User avatar
mcsmom
Joomla! Exemplar
Joomla! Exemplar
Posts: 7897
Joined: Thu Aug 18, 2005 8:43 pm
Location: New York
Contact:

Re: DocMAN 1.3.0 RC2

Post by mcsmom » Sat Aug 25, 2007 1:49 am

Wait, you sent that email because of a report of an unconfirmed problem reported in Persian (I guess really Farsi) by one "hacker" that was made in January?

Do you read Farsi?
So we must fix our vision not merely on the negative expulsion of war, but upon the positive affirmation of peace. MLK 1964.
http://officialjoomlabook.com Get it at http://www.joomla.org/joomla-press-official-books.html Buy a book, support Joomla!.

User avatar
mjaz
Joomla! Guru
Joomla! Guru
Posts: 821
Joined: Thu Nov 10, 2005 10:08 am
Contact:

Re: DocMAN 1.3.0 RC2

Post by mjaz » Sat Aug 25, 2007 4:07 am

Just wanted to confirm that I fixed a couple of *minor* vulnerabilities about two months ago. These fixes will be included in the upcoming v1.4beta2 release.
I have yet to read any report of a site being hacked through DOCman. If anyone does know of issues in the current code, please:
- send me everything you know, so I can fix it.
- do not make the details public, so no sites are compromised.
thanks
Better SEO & multi-lingual Joomla sites with Nooku Content
http://www.nooku.org
Nooku Framework for advanced Joomla extension development
http://www.nooku.org/framework

User avatar
72dpi
Joomla! Intern
Joomla! Intern
Posts: 55
Joined: Thu Mar 16, 2006 12:47 am

Re: DocMAN 1.3.0 RC2

Post by 72dpi » Sat Aug 25, 2007 9:47 am

I Respect you Johan ;)

I suggest a full dump of this thread, as I have seen a major turn in Edits to the content.
Less "personal" feelings, more "facts" needed.

Keep up the great work all, remember, Joomla is a community, and you all make a difference.

BTW, I almost crapped myself, as we have 2000 Docs in Docman, in 100 categories, on a site with 2500 pages.

So yeah, I panicked. Not a good feeling  :o

User avatar
Jinx
Joomla! Champion
Joomla! Champion
Posts: 6508
Joined: Fri Aug 12, 2005 12:47 am
Contact:

Re: DocMAN 1.3.0 RC2

Post by Jinx » Sat Aug 25, 2007 11:57 am

72dpi wrote: I Respect you Johan ;)
Thanks, but this is not about personal respect. It's about community ethics and acting in the best interest of the project that allows one to make his living. Scarring people for no reason is simple stupid.
I suggest a full dump of this thread, as I have seen a major turn in Edits to the content.
Less "personal" feelings, more "facts" needed.
I don't see a reason for that, we are an open and transparent community and I nothing to hide. The facts are there I'm simply pointing them out. Phil has abused his company channels to spread in-correct or at least not-verified security related information to third parties. We have very clear guidelines in the project and Q&T working group how to handle such reports. Information about them should only be made public  after it has been verified and the maintainer of the project has been contacted. Phil has done neither, in DOCman's case, if it hadn't been for community members I wouldn't even have noticed this post on the Joomla! forums. Being a former core team member and long standing third party developer Phil knows these guidelines yet he chooses to ignore them. I can only guess his reasons for such actions.

I believe that we (Mjaz, the current docman lead developer and myself) have the right to defend ourselves against mis-information and fear that is being spread. A simple public apology would be a good first step, but I don't expect this to happen seen Phil his earlier replies.
BTW, I almost crapped myself, as we have 2000 Docs in Docman, in 100 categories, on a site with 2500 pages.
So yeah, I panicked. Not a good feeling  :o
Exactly my point !
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5

http://www.joomlatools.com - Joomla extensions that just work

User avatar
Jinx
Joomla! Champion
Joomla! Champion
Posts: 6508
Joined: Fri Aug 12, 2005 12:47 am
Contact:

Re: DocMAN 1.3.0 RC2

Post by Jinx » Sat Aug 25, 2007 12:13 pm

Added :  25-08-2007 : information on the security issue posted

We have done research on the DOCman issues posted in the last two days and believe that this security issue is related or the same to an issue that was repoted a couple of months ago and was fixed back then. The original report also dates back to january 2007 which supports this theory. This issue was not deemed of high priority to release an immediat patch for DOCman 1.3 back and we have choosen to make it available in the new 1.4 version.

A full security sweep of the upcoming DOCman 1.4 beta has already been performend and so far no issues have been found. We are currently fixing legacy support for Joomla! 1.5 and once this is done and tested a public beta release will be made. People that already want to test a private build can contact us (mjaz or myself) through PM.

We would like to thank our DOCman community for their continuous support and feedback. We will continue to try and make DOCman the best free software document manager for Joomla!.

Thanks,

Johan and Matthias

Note : link to original report added.
Last edited by Jinx on Sat Aug 25, 2007 12:20 pm, edited 1 time in total.
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5

http://www.joomlatools.com - Joomla extensions that just work

User avatar
infograf768
Joomla! Master
Joomla! Master
Posts: 19133
Joined: Fri Aug 12, 2005 3:47 pm
Location: **Translation Matters**

Re: DocMAN 1.3.0 RC2

Post by infograf768 » Sat Aug 25, 2007 12:45 pm

Global Mod cap:
-----------------------------------------------------------------
This thread has gone far away from forum rules and will now be locked.

May I remember to all that
Keep all commentary civil, and be courteous at all times. Constructive criticism is welcome, but insults directed towards other users or the site admins will not be tolerated. Coarse/insulting language will not be tolerated.
That being said,

Joomla user's cap
-----------------------
I, personally, look forward to Phil's e-mail to all the people who received the first one, stating what was wrong or not verified in it.

Thanks for your understanding.
Jean-Marie Simonet / infograf
---------------------------------
ex-Joomla Translation Coordination Team • ex-Joomla! Production Working Group

Advertisement

Locked

Return to “3rd Party/Non Joomla! Security Issues”