Welcome Guest, please login or register.
Username:
Password:

News: 2.1.5 has been released.  Visit the portal or SourceForge page to download
Development has begun on 3.0.0.  See the the announcement in the Core Development Forum for details!
Pages: [1]   Go Down
Topic Tools  
Read
August 17, 2007, 07:19:22 AM
HCL Admin
Administrator
HCL Superstar
*****
Offline Offline

Posts: 844



It appears that there maybe a security issue with certain administrative files on all recent versions of HCL.  We are aware of the issue, and are working to expedite a fix for these issues.  I should have at least a hotfix tonight, and a new version up in a few days with the security patch installed on the sourceforge page.

This issue is detailed here and may cause the admin to be locked out, or for your HCL install to be hacked.  Until the hotfix is released (in the next few hours) I recommend putting an .htaccess in your admin folder such as this:

Code: (.htaccess)
Order Deny, Allow
Deny from all
Allow from 000.000.000.000

Change the 000.000.000.000 to your IP address.  If you need multiple address' then separate each address with a space.
This is on necessary until the hotfix is released, again, this should be sometime this morning (Friday, August 17th)

Remember, if you hear of ANY security related issue with HCL, Please, please, please let us know.  These types of issues can cause serious repercussions for others. 
« Last Edit: August 17, 2007, 07:36:45 AM by mlzhosting » Logged

how may I help you today?
 
Read
August 17, 2007, 08:03:24 AM
HCL Admin
Administrator
HCL Superstar
*****
Offline Offline

Posts: 844



Here is the hotfix file, which I shall be posting on the portal page in a few minutes, simply extract the auth.php file from the archive and replace the hcl/class/auth.php on your webserver.

NOTE:  This hotfix is untested at this time, and while it should cause no problems, there may be issues with it.

Frankly the fix involved adding one line to the auth.php code, a simple exit statement appears to have been missing.  Please, if your using 2.1.2, 2.1.3, 2.1.3a, or 2.1.4, replace the auth.php with the one attached to this message. 
 

Again, remember, if you spot even a suspected vulnerability, please at least PM me a message about it, or post on the forums here.  I'd rather chase a few wild geese then have even on vulnerability out in the wild. Smiley

Edit: Doh, I forgot to add the file...
« Last Edit: August 17, 2007, 08:17:31 AM by mlzhosting » Logged

how may I help you today?
 
Read
August 17, 2007, 02:55:55 PM
HCL Admin
Administrator
HCL Superstar
*****
Offline Offline

Posts: 844



As a further note, I'll be releasing another version (2.1.5) this weekend or Monday, Because of the potential of this security fix, I'd rather bump another version number due to it.
Logged

how may I help you today?
 
Read
August 26, 2007, 12:46:17 AM
beLite
Global Moderator
Not too much to say...
*****
Offline Offline

Posts: 37



As a further note, I'll be releasing another version (2.1.5) this weekend or Monday, Because of the potential of this security fix, I'd rather bump another version number due to it.
You should hurry up since Windows IIS is not able to read those @#$@ing .htaccess files.. No really, take your time Smiley
Logged
 
Read
August 26, 2007, 01:08:31 AM
HCL Admin
Administrator
HCL Superstar
*****
Offline Offline

Posts: 844



Hehehe, I was just working on the transcript garbling issue, I'll either get it today or not, either way I'm pushing 2.1.5 out the door since I don't like the current release having a security issue.
Logged

how may I help you today?
 
Read
August 27, 2007, 04:45:27 PM
victor
Global Moderator
HCL Member
*****
Offline Offline

Posts: 266



great, so we must wait for 2.1.5 correction... do you have any temptative date of release it?

thanks!  Smiley
Logged

 
Read
August 27, 2007, 05:05:16 PM
HCL Admin
Administrator
HCL Superstar
*****
Offline Offline

Posts: 844



Should be this morning sometime.
Logged

how may I help you today?
 
Read
August 27, 2007, 05:39:11 PM
HCL Admin
Administrator
HCL Superstar
*****
Offline Offline

Posts: 844



Ok, might be just a tad longer, the route to my datacenter is down, the ISP knows about it, now I just have to wait until it's back up.  This is where the SVN is stored and I've never had an issue like this before, so we just need to be patient.  I'm going to take the uncommited sources and work on the demo site here in the mean time.
Logged

how may I help you today?
 

Pages: [1]   Go Up
Jump to:  

Theme by Your Hosting Professionals :: DClune
Page created in 0.082 seconds with 25 queries.
sexual dysfunction Viagra tadalafil work
sildenafil citrate 50mg Cialis tadalafil lowest cost
sildenafil hypertension Levitra sildenafil nitrate
tadalafil mastercard Viagra Professional where to buy sildenafil
effects of sildenafil Cialis Professional tadalafil 20
generic sildenafil citrate 100mg Viagra Super Active eckerds pharmacy
tadalafil from india Cialis Super Active buy generic tadalafil
tadalafil from Viagra Soft Tabs between sildenafil
erectile dysfunction devices Cialis Soft Tabs hydroxypropyl cellulose
sildenafil revatio Soma 4
sildenafil citrate sample Viagra, Cialis, Levitra alcohol and erectile dysfunction Bestsellers, buy viagra, buy cialis, buy levitra diabetes erectile dysfunction Female viagra sildenafil chemical structure
erectile dysfunction products Levitra professional sildenafil solubility
teen nude sex sex video clips gay sexy teens
amateur sex porno sex video clips gay sexcom
gay sex in jeans upskirt voyeur nude sex photos
male gay sex sex video clips amateur sex pics
athens gay sex clubs redhead pussy gay sex trade
gay sexcom sex video clips gay sex free clips
caribbean nude sex models sexy photos google gay sex
hot black gay sex sexy photos dirty gay sex
amateur gay sex best porn gay sexy sissy men in panty pics
anonamous gay sex free photo sexy photos str8 guys love gay sex
black gay sex sites teen news black gay sex sites
caribbean nude sex models sexy photos black gay sex sites
free gay sex pics and clips naked coeds dad gay sex
her first gay sex sexy photos gay sex parties in new jersey
pussy playboy porne nude sex college girls naked what are the different gay sex position
can str8 guys have gay sex sex video clips free black nude sex pics
hardcore nude sex pics rate my hot body anonamous gay sex free photo
amateur sex clips sex video clips chubby gay sex
gay sex in jeans nude thumbs gay sex free clips
amateur sex pics sex video clips gay sex party
gay sex postitions simpsons fuck gay sex trade
black pre-teens gay sex.com sex video clips kinky gay sex
nude sex photos tankless hot water heaters gay sex parties in new jersey
amateur gay sex sex video clips real gay sex stories
free free free pictures of hardcore gay sex beautiful lesbians free amateur sex videos
her first gay sex sex video clips black gay sex sites
free amateur sex videos gay lads amateur sex porno
athens gay sex clubs sexy photos self sex or gay sex
gay sex maui naturist girl nude sex analsex
teen nude sex sexy photos gay sex storie
gay sex daddys magazine teen teen tgp dad gay sex
kinky gay sex sexy photos nude sex photos
str8 guys love gay sex sex hot black gay sex
hisfirst gay sex.com sex kinky gay sex