Advertisement
DocMAN 1.3.0 RC2
Moderator: General Support Moderators
Forum rules
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1408
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
DocMAN 1.3.0 RC2
DocMAN 1.3.0 RC2
http://cve.mitre.org/cgi-bin/cvename.cg ... -2007-0380
http://cve.mitre.org/cgi-bin/cvename.cg ... -2007-0380
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
Advertisement
- Jinx
- Joomla! Champion
- Posts: 6508
- Joined: Fri Aug 12, 2005 12:47 am
- Contact:
Re: DocMAN 1.3.0 RC2
Thanks, we are working on a 1.4 beta which is expected to be release at the beginning of september. I have forwared this to the current maintainer of DOCman to make sure it is fixed for the new release.
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5
http://www.joomlatools.com - Joomla extensions that just work
http://www.joomlatools.com - Joomla extensions that just work
- infograf768
- Joomla! Master
- Posts: 19133
- Joined: Fri Aug 12, 2005 3:47 pm
- Location: **Translation Matters**
Re: DocMAN 1.3.0 RC2
@PhilTaylor
I sort of understand you know how to protect Docman users at reading it.
Could you provide the patch?
I received your mail.PhilTaylor-Prazgod wrote: DocMAN 1.3.0 RC2
http://cve.mitre.org/cgi-bin/cvename.cg ... -2007-0380
I sort of understand you know how to protect Docman users at reading it.
Could you provide the patch?
Jean-Marie Simonet / infograf
---------------------------------
ex-Joomla Translation Coordination Team • ex-Joomla! Production Working Group
---------------------------------
ex-Joomla Translation Coordination Team • ex-Joomla! Production Working Group
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1408
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: DocMAN 1.3.0 RC2
I have no solution - I cant even find the problem after a quick glance. I am chatting to Beat about this - whatever the vulnerability, its not an obvious one.
Beat has identified some problem areas to look into following this, but cannot replicate any injections yet.
I have contacted the original reporter (the "hacker") and hope to get more technical details.
Beat has identified some problem areas to look into following this, but cannot replicate any injections yet.
I have contacted the original reporter (the "hacker") and hope to get more technical details.
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- Jinx
- Joomla! Champion
- Posts: 6508
- Joined: Fri Aug 12, 2005 12:47 am
- Contact:
Re: DocMAN 1.3.0 RC2
Phil,
I'm seriously dissapointed by the way you have handled this issue. You have spread ungrounded fear amongst many DOCman users abusing your company and personal communication channels. What makes it even worse is that you now openly admit you didn't do any due diligence on the security issue reported, you didn't check it nor did you email the current DOCman maintainer or myself about it before taking any other steps. It really makes me wonder about your intentions ?
For the record, DOCMan is one of the most secure components available for Joomla! and Mambo. DOCman is around since the very early days has always been very popular and we have never encountered any major security issues. Those we found where addressed as soon as possible.
This is pretty amazing seen the fact that DOCman has always been a voluntary project worked on by a number of different people over the past 5 years. It has a great community that relies on it and helps to move it forward. It has offcourse it's weaknesses and it's strength, security being definitely a strength.
One good piece of advice Phil, you are free to take it or leave it, next time instead of spreading fear try to do things the Joomla! way. Send the maintainer of the extension a personal email about the security issue. Maybe even try to verify the actual issue that is being reported. Creating a quick patch to solve it once found shouldn't be that hard for a seasoned 'joomla security expert' like yourselves no ? I'm sure the maintainer of the extension will appreciate it and so will all Joomla! users.
Open source development and "Jumla" development is about contributing, think about it !
Sincerely,
Johan Janssens
DOCman project manager
I'm seriously dissapointed by the way you have handled this issue. You have spread ungrounded fear amongst many DOCman users abusing your company and personal communication channels. What makes it even worse is that you now openly admit you didn't do any due diligence on the security issue reported, you didn't check it nor did you email the current DOCman maintainer or myself about it before taking any other steps. It really makes me wonder about your intentions ?
For the record, DOCMan is one of the most secure components available for Joomla! and Mambo. DOCman is around since the very early days has always been very popular and we have never encountered any major security issues. Those we found where addressed as soon as possible.
This is pretty amazing seen the fact that DOCman has always been a voluntary project worked on by a number of different people over the past 5 years. It has a great community that relies on it and helps to move it forward. It has offcourse it's weaknesses and it's strength, security being definitely a strength.
One good piece of advice Phil, you are free to take it or leave it, next time instead of spreading fear try to do things the Joomla! way. Send the maintainer of the extension a personal email about the security issue. Maybe even try to verify the actual issue that is being reported. Creating a quick patch to solve it once found shouldn't be that hard for a seasoned 'joomla security expert' like yourselves no ? I'm sure the maintainer of the extension will appreciate it and so will all Joomla! users.
Open source development and "Jumla" development is about contributing, think about it !
Sincerely,
Johan Janssens
DOCman project manager
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5
http://www.joomlatools.com - Joomla extensions that just work
http://www.joomlatools.com - Joomla extensions that just work
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1408
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: DocMAN 1.3.0 RC2
Johan
I choose to take my advice from people I respect, unfortunately you are not one of those.
Phil
I choose to take my advice from people I respect, unfortunately you are not one of those.
Phil
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- mediamagnate
- Joomla! Explorer
- Posts: 315
- Joined: Fri Aug 12, 2005 2:09 pm
- Location: Shepparton
- Contact:
Re: DocMAN 1.3.0 RC2
Phil, I think you could do well to take some of Johan's advice. Were you not the person who told the world that Joomla! was not going to be GPL — then the blog amazingly disappeared? You have a history of rather humiliating faux pas — generally opening your mouth before engaging your brain.PhilTaylor-Prazgod wrote: Johan
I choose to take my advice from people I respect, unfortunately you are not one of those.
Phil
Please try to think before you post in future. You're the one this reflects badly upon. Common courtesy is a two way street.
Joomla is a project, not a product! www.nooku.org
- PhilTaylor-Prazgod
- Joomla! Ace
- Posts: 1408
- Joined: Sat Aug 20, 2005 12:32 pm
- Location: Jersey, Channel Islands
- Contact:
Re: DocMAN 1.3.0 RC2
Stand for something or fall for everything
Phil Taylor
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- https://mySites.guru - Manage Multiple Joomla/WordPress Sites In One Dashboard for Security, Audits, Backups and more....
- https://www.phil-taylor.com/
- mcsmom
- Joomla! Exemplar
- Posts: 7897
- Joined: Thu Aug 18, 2005 8:43 pm
- Location: New York
- Contact:
Re: DocMAN 1.3.0 RC2
Wait, you sent that email because of a report of an unconfirmed problem reported in Persian (I guess really Farsi) by one "hacker" that was made in January?
Do you read Farsi?
Do you read Farsi?
So we must fix our vision not merely on the negative expulsion of war, but upon the positive affirmation of peace. MLK 1964.
http://officialjoomlabook.com Get it at http://www.joomla.org/joomla-press-official-books.html Buy a book, support Joomla!.
http://officialjoomlabook.com Get it at http://www.joomla.org/joomla-press-official-books.html Buy a book, support Joomla!.
- mjaz
- Joomla! Guru
- Posts: 821
- Joined: Thu Nov 10, 2005 10:08 am
- Contact:
Re: DocMAN 1.3.0 RC2
Just wanted to confirm that I fixed a couple of *minor* vulnerabilities about two months ago. These fixes will be included in the upcoming v1.4beta2 release.
I have yet to read any report of a site being hacked through DOCman. If anyone does know of issues in the current code, please:
- send me everything you know, so I can fix it.
- do not make the details public, so no sites are compromised.
thanks
I have yet to read any report of a site being hacked through DOCman. If anyone does know of issues in the current code, please:
- send me everything you know, so I can fix it.
- do not make the details public, so no sites are compromised.
thanks
Better SEO & multi-lingual Joomla sites with Nooku Content
http://www.nooku.org
Nooku Framework for advanced Joomla extension development
http://www.nooku.org/framework
http://www.nooku.org
Nooku Framework for advanced Joomla extension development
http://www.nooku.org/framework
- 72dpi
- Joomla! Intern
- Posts: 55
- Joined: Thu Mar 16, 2006 12:47 am
Re: DocMAN 1.3.0 RC2
I Respect you Johan
I suggest a full dump of this thread, as I have seen a major turn in Edits to the content.
Less "personal" feelings, more "facts" needed.
Keep up the great work all, remember, Joomla is a community, and you all make a difference.
BTW, I almost crapped myself, as we have 2000 Docs in Docman, in 100 categories, on a site with 2500 pages.
So yeah, I panicked. Not a good feeling
I suggest a full dump of this thread, as I have seen a major turn in Edits to the content.
Less "personal" feelings, more "facts" needed.
Keep up the great work all, remember, Joomla is a community, and you all make a difference.
BTW, I almost crapped myself, as we have 2000 Docs in Docman, in 100 categories, on a site with 2500 pages.
So yeah, I panicked. Not a good feeling
- Jinx
- Joomla! Champion
- Posts: 6508
- Joined: Fri Aug 12, 2005 12:47 am
- Contact:
Re: DocMAN 1.3.0 RC2
Thanks, but this is not about personal respect. It's about community ethics and acting in the best interest of the project that allows one to make his living. Scarring people for no reason is simple stupid.72dpi wrote: I Respect you Johan
I don't see a reason for that, we are an open and transparent community and I nothing to hide. The facts are there I'm simply pointing them out. Phil has abused his company channels to spread in-correct or at least not-verified security related information to third parties. We have very clear guidelines in the project and Q&T working group how to handle such reports. Information about them should only be made public after it has been verified and the maintainer of the project has been contacted. Phil has done neither, in DOCman's case, if it hadn't been for community members I wouldn't even have noticed this post on the Joomla! forums. Being a former core team member and long standing third party developer Phil knows these guidelines yet he chooses to ignore them. I can only guess his reasons for such actions.I suggest a full dump of this thread, as I have seen a major turn in Edits to the content.
Less "personal" feelings, more "facts" needed.
I believe that we (Mjaz, the current docman lead developer and myself) have the right to defend ourselves against mis-information and fear that is being spread. A simple public apology would be a good first step, but I don't expect this to happen seen Phil his earlier replies.
Exactly my point !BTW, I almost crapped myself, as we have 2000 Docs in Docman, in 100 categories, on a site with 2500 pages.
So yeah, I panicked. Not a good feeling
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5
http://www.joomlatools.com - Joomla extensions that just work
http://www.joomlatools.com - Joomla extensions that just work
- Jinx
- Joomla! Champion
- Posts: 6508
- Joined: Fri Aug 12, 2005 12:47 am
- Contact:
Re: DocMAN 1.3.0 RC2
Added : 25-08-2007 : information on the security issue posted
We have done research on the DOCman issues posted in the last two days and believe that this security issue is related or the same to an issue that was repoted a couple of months ago and was fixed back then. The original report also dates back to january 2007 which supports this theory. This issue was not deemed of high priority to release an immediat patch for DOCman 1.3 back and we have choosen to make it available in the new 1.4 version.
A full security sweep of the upcoming DOCman 1.4 beta has already been performend and so far no issues have been found. We are currently fixing legacy support for Joomla! 1.5 and once this is done and tested a public beta release will be made. People that already want to test a private build can contact us (mjaz or myself) through PM.
We would like to thank our DOCman community for their continuous support and feedback. We will continue to try and make DOCman the best free software document manager for Joomla!.
Thanks,
Johan and Matthias
Note : link to original report added.
We have done research on the DOCman issues posted in the last two days and believe that this security issue is related or the same to an issue that was repoted a couple of months ago and was fixed back then. The original report also dates back to january 2007 which supports this theory. This issue was not deemed of high priority to release an immediat patch for DOCman 1.3 back and we have choosen to make it available in the new 1.4 version.
A full security sweep of the upcoming DOCman 1.4 beta has already been performend and so far no issues have been found. We are currently fixing legacy support for Joomla! 1.5 and once this is done and tested a public beta release will be made. People that already want to test a private build can contact us (mjaz or myself) through PM.
We would like to thank our DOCman community for their continuous support and feedback. We will continue to try and make DOCman the best free software document manager for Joomla!.
Thanks,
Johan and Matthias
Note : link to original report added.
Last edited by Jinx on Sat Aug 25, 2007 12:20 pm, edited 1 time in total.
Johan Janssens - Joomla Co-Founder, Lead Developer of Joomla 1.5
http://www.joomlatools.com - Joomla extensions that just work
http://www.joomlatools.com - Joomla extensions that just work
- infograf768
- Joomla! Master
- Posts: 19133
- Joined: Fri Aug 12, 2005 3:47 pm
- Location: **Translation Matters**
Re: DocMAN 1.3.0 RC2
Global Mod cap:
-----------------------------------------------------------------
This thread has gone far away from forum rules and will now be locked.
May I remember to all that
Joomla user's cap
-----------------------
I, personally, look forward to Phil's e-mail to all the people who received the first one, stating what was wrong or not verified in it.
Thanks for your understanding.
-----------------------------------------------------------------
This thread has gone far away from forum rules and will now be locked.
May I remember to all that
That being said,Keep all commentary civil, and be courteous at all times. Constructive criticism is welcome, but insults directed towards other users or the site admins will not be tolerated. Coarse/insulting language will not be tolerated.
Joomla user's cap
-----------------------
I, personally, look forward to Phil's e-mail to all the people who received the first one, stating what was wrong or not verified in it.
Thanks for your understanding.
Jean-Marie Simonet / infograf
---------------------------------
ex-Joomla Translation Coordination Team • ex-Joomla! Production Working Group
---------------------------------
ex-Joomla Translation Coordination Team • ex-Joomla! Production Working Group
Advertisement