JoomlaXplorer 1.6.1 FTP violation

For all Non-Joomla! security issues. ie 3pd Components etc.

Moderator: General Support Moderators

Forum rules
Locked
User avatar
N6REJ
Joomla! Explorer
Joomla! Explorer
Posts: 355
Joined: Sun Nov 27, 2005 9:25 am
Location: Ponca City, OK
Contact:

JoomlaXplorer 1.6.1 FTP violation

Post by N6REJ » Tue Sep 18, 2007 2:59 pm

When using JoomlaXplorer 1.6.1 to upload files via ftp mode, it changes the ownership of the root folder to the apache user!  This causes a 403 error because apache can't own those directorys.  I've had this happen several times on 2 different machines.
Bear

User avatar
soeren
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 111
Joined: Mon Aug 29, 2005 10:58 am
Location: Germany
Contact:

[No Security Issue!] JoomlaXplorer 1.6.1 FTP violation

Post by soeren » Tue Sep 18, 2007 5:10 pm

Hi,
to clarify: this is no security issue which can be exploited by malicious people!
It's "just" a critical bug.
I longer planned an update because of this bug.
joomlaXplorer 1.6.2 is now available, fixing this critical bug.

Download joomlaXplorer 1.6.2

ciao, Sören
Last edited by soeren on Tue Sep 18, 2007 5:14 pm, edited 1 time in total.

jkneebone
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Wed Aug 01, 2007 7:55 pm
Location: West Coast, United States

Re: JoomlaXplorer 1.6.1 FTP violation

Post by jkneebone » Thu Sep 27, 2007 9:48 pm

After clicking on "ftp mode" I got locked out of joomla completely! :) 403.

After a few minutes on hold with the hosting company, it was all reset. Thanks for the tip!!

User avatar
N6REJ
Joomla! Explorer
Joomla! Explorer
Posts: 355
Joined: Sun Nov 27, 2005 9:25 am
Location: Ponca City, OK
Contact:

Re: JoomlaXplorer 1.6.1 FTP violation

Post by N6REJ » Tue Oct 02, 2007 1:55 pm

no problem.  I lost a LOT of data because of it because my host didn't know how to handle things properly.  Stay away from Pimahost.com
Bear

User avatar
N6REJ
Joomla! Explorer
Joomla! Explorer
Posts: 355
Joined: Sun Nov 27, 2005 9:25 am
Location: Ponca City, OK
Contact:

Re: JoomlaXplorer 1.6.1 FTP violation

Post by N6REJ » Fri Oct 05, 2007 2:29 pm

Thanks for the quick release soren.
Troy
Bear


Locked

Return to “3rd Party/Non Joomla! Security Issues”