Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Discussion area for the announcement that:
Upgrade to Joomla! 1.0.4 Security Release now!
http://www.joomla.org/content/view/498/74/
Upgrade to Joomla! 1.0.4 Security Release now!
http://www.joomla.org/content/view/498/74/
Core Team member - Lead developer
'Making good things happen'
http://www.joomlatools.org - training, consulting and extension development
'Making good things happen'
http://www.joomlatools.org - training, consulting and extension development
- Chinaman
- Joomla! Apprentice
- Posts: 13
- Joined: Sun Aug 21, 2005 8:46 am
- Location: Perth, Western Australia
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Well done to all the team, and thank you.
Joomla! - enjoying every minute of the journey!
- 55thinking
- Joomla! Apprentice
- Posts: 17
- Joined: Mon Sep 05, 2005 8:58 am
- Location: Madrid
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
I can see that this patch affects the english.php file located in the language directory. Can we know what changes have been done to this file such as other languages file may be updated too ?
Thank you
Thank you
55 Thinking - Strategy Design Technology
Good looking, Fast and Usable web solutions
http://www.55thinking.com/
Good looking, Fast and Usable web solutions
http://www.55thinking.com/
- guilliam
- Joomla! Enthusiast
- Posts: 159
- Joined: Thu Aug 18, 2005 10:27 am
- Location: Sunny City Cebu, Philippines!
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
wonderful!!
--> Sundial
the team surely prioritizes SECURITY at the top most of the list!
thank you!
- g
--> Sundial
the team surely prioritizes SECURITY at the top most of the list!
thank you!
- g
"I was one of those who wondered why people would pay so much $$$$ to do something that was so much fun!" -R. Harkrider, Fortran Code Engr.
^If u read that in $GREEN, you clearly missed the HIGHLIGHTS!
http://www.joomlancers.com | http://www.joomlaconsultancy.net
^If u read that in $GREEN, you clearly missed the HIGHLIGHTS!
http://www.joomlancers.com | http://www.joomlaconsultancy.net
- pushfrog98
- Joomla! Apprentice
- Posts: 12
- Joined: Thu Sep 01, 2005 7:48 pm
- Location: Greenville, Il
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
just wondering if this patch has anything to do with the $ambo exploit...
http://isc.sans.org/diary.php?storyid=870
http://isc.sans.org/diary.php?storyid=870
- Jared Smith
http://www.greenville.edu
http://www.greenville.edu
- infograf768
- Joomla! Engineer
- Posts: 366
- Joined: Fri Aug 12, 2005 3:47 pm
- Location: •Translation Matters•
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
55thinking wrote:I can see that this patch affects the english.php file located in the language directory. Can we know what changes have been done to this file such as other languages file may be updated too ?
Thank you
ISO has been reset to 8559-1 instead of utf-8.
A few strings have been added.
Better use a diff program to check all.
Last edited by infograf768 on Mon Nov 21, 2005 4:59 pm, edited 1 time in total.
Jean-Marie Simonet / infograf · http://www.info-graf.fr · GMT +1
Qui vult dare parva non debet magna rogare.
Qui vult dare parva non debet magna rogare.
- infograf768
- Joomla! Engineer
- Posts: 366
- Joined: Fri Aug 12, 2005 3:47 pm
- Location: •Translation Matters•
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Powdered Toast Man wrote:Oh come on - are we not waiting for the 1.1 release this month?? Does this mean that the 1.1 release date will creep over into December? Maybe january even? Why couldn't you have put the security fixes into 1.1?
Hugely annoying..
PTM
Some like to wait until later on to patch their apps. It is their decision.
We have decided not to as many sites have been hacked.
1.0.4 had a few bugs fixed by the Maintenance team. It was just a matter of releasing it sooner than planned.
The time taken to do this has not been taken over the 1.1 development.
FYI: concerning 1.1, a second alpha will be released next week, then a beta.
Don't be so annoyed
Jean-Marie Simonet / infograf · http://www.info-graf.fr · GMT +1
Qui vult dare parva non debet magna rogare.
Qui vult dare parva non debet magna rogare.
- pcigre
- Joomla! Apprentice
- Posts: 30
- Joined: Mon Sep 05, 2005 11:21 am
- Location: Nis, Serbia
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
55thinking wrote:I can see that this patch affects the english.php file located in the language directory. Can we know what changes have been done to this file such as other languages file may be updated too ?
Thank you
You can see there what is changed:
http://developer.joomla.org/integration ... f_format=h
http://www.pcigre.com -> game community
- 55thinking
- Joomla! Apprentice
- Posts: 17
- Joined: Mon Sep 05, 2005 8:58 am
- Location: Madrid
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
pcigre.com wrote:55thinking wrote:I can see that this patch affects the english.php file located in the language directory. Can we know what changes have been done to this file such as other languages file may be updated too ?
Thank you
You can see there what is changed:
http://developer.joomla.org/integration ... f_format=h
Thanks a lot, helpfull link
55 Thinking - Strategy Design Technology
Good looking, Fast and Usable web solutions
http://www.55thinking.com/
Good looking, Fast and Usable web solutions
http://www.55thinking.com/
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
infograf768 wrote:Powdered Toast Man wrote:Oh come on - are we not waiting for the 1.1 release this month?? Does this mean that the 1.1 release date will creep over into December? Maybe january even? Why couldn't you have put the security fixes into 1.1?
Hugely annoying..
PTM
Some like to wait until later on to patch their apps. It is their decision.
We have decided not to as many sites have been hacked.
1.0.4 had a few bugs fixed by the Maintenance team. It was just a matter of releasing it sooner than planned.
The time taken to do this has not been taken over the 1.1 development.
FYI: concerning 1.1, a second alpha will be released next week, then a beta.
Don't be so annoyed
So we still have at least a week 1/2 for 1.1? I was looking forward to the release sometime this week so I can integrate phpbb and go live with my site. =/
- nathandiehl
- Joomla! Intern
- Posts: 70
- Joined: Fri Aug 19, 2005 3:03 pm
- Location: Indiana, USA
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Powdered Toast Man wrote:Oh come on - are we not waiting for the 1.1 release this month?? Does this mean that the 1.1 release date will creep over into December? Maybe january even? Why couldn't you have put the security fixes into 1.1?
Hugely annoying..
PTM
i for one am happy that the Joomla! Core Team doesn't think that Medium-Threat risks are so insignificant that they can wait a couple weeks. If you want to remain vulnerable, i might recommend you switch to Mambo or another CMS where they don't offer near the updates of Joomla!.
Thanks again core team--your work is highly appreciated!
and believe you, I appreciate my icons in administrator not going wacko anymore! Thanks again!
nathan.
If you're new to Joomla, Please read Anna's Joomla! Tips: viewtopic.php?t=5503
http://nathandiehl.com | Find out what makes me tick
http://nathandiehl.com | Find out what makes me tick
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Are there any general instructions for applying the patch package? Or do I simply untar the package on top of my existing installation?
- infograf768
- Joomla! Engineer
- Posts: 366
- Joined: Fri Aug 12, 2005 3:47 pm
- Location: •Translation Matters•
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Upgrade Instructions
* To update from Joomla! 1.0.3, all you have to do is simply overwrite files from the 1.0.3 to 1.0.4 Patch Package
* To update from Joomla! 1.0.2, all you have to do is simply overwrite files from the 1.0.2 to 1.0.4 Patch Package
* To update from Joomla! 1.0.1, all you have to do is simply overwrite files from the 1.0.1 to 1.0.4 Patch Package
* To update from Joomla! 1.0.0, all you have to do is simply overwrite files from the 1.0.0 to 1.0.4 Patch Package
Jean-Marie Simonet / infograf · http://www.info-graf.fr · GMT +1
Qui vult dare parva non debet magna rogare.
Qui vult dare parva non debet magna rogare.
- guilliam
- Joomla! Enthusiast
- Posts: 159
- Joined: Thu Aug 18, 2005 10:27 am
- Location: Sunny City Cebu, Philippines!
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
infograf768 wrote:Powdered Toast Man wrote:Oh come on - are we not waiting for the 1.1 release this month?? Does this mean that the 1.1 release date will creep over into December? Maybe january even? Why couldn't you have put the security fixes into 1.1?
Hugely annoying..
PTM
Some like to wait until later on to patch their apps. It is their decision.
We have decided not to as many sites have been hacked.
1.0.4 had a few bugs fixed by the Maintenance team. It was just a matter of releasing it sooner than planned.
The time taken to do this has not been taken over the 1.1 development.
FYI: concerning 1.1, a second alpha will be released next week, then a beta.
Don't be so annoyed
this post from toastman is more annoying than anything else. hmmnn.. isnt he supposed to be happy the core team has released this patch for the benifit of ALL. oh well..
- g
"I was one of those who wondered why people would pay so much $$$$ to do something that was so much fun!" -R. Harkrider, Fortran Code Engr.
^If u read that in $GREEN, you clearly missed the HIGHLIGHTS!
http://www.joomlancers.com | http://www.joomlaconsultancy.net
^If u read that in $GREEN, you clearly missed the HIGHLIGHTS!
http://www.joomlancers.com | http://www.joomlaconsultancy.net
- focalguy
- Joomla! Apprentice
- Posts: 35
- Joined: Fri Aug 19, 2005 2:46 am
- Location: Washington State, USA
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Thanks again for all the hard work! Keep it up and 1.1 will be here when it's ready.
- MolBio
- Joomla! Apprentice
- Posts: 8
- Joined: Wed Oct 12, 2005 9:30 pm
- Location: Princeton, NJ
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Security releases should be the first priority and thanks to dev team that for these upgrades.
We can always wait a bit for the new version, but we certainly don’t want to be hacked!
Thanks again
We can always wait a bit for the new version, but we certainly don’t want to be hacked!
Thanks again
- mediamagnate
- Joomla! Intern
- Posts: 82
- Joined: Fri Aug 12, 2005 2:09 pm
- Location: Yorkshire
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
It should also be remembered that some non-Joomla security issues may still exist depending on security measures and configuration of where your site is hosted. It is not unusual for some hosts to be better than others.
The team's fast response to what amounts to a serious issue is why I love this community.
Applause to our code commandos who've worked so hard during the past couple of days to make this happen.
The team's fast response to what amounts to a serious issue is why I love this community.
Applause to our code commandos who've worked so hard during the past couple of days to make this happen.
Vote for Joomla! http://www.packtpub.com/article/overall ... nal-joomla
4,775 Ways to Joomla!
Podmaster of http://www.joomlajuice.com/
4,775 Ways to Joomla!
Podmaster of http://www.joomlajuice.com/
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Thanks guys. Security has priority of course, but the patch (103 to 104) screwed up all my diacritical-marked words, of which I have *many* on the site I'm building. Words like
Bahá'í
show up as
Bahá'Ã
Not fun. An upfront alert to this might be helpful next time. Thanks for the hard work.
pieter
Bahá'í
show up as
Bahá'Ã
Not fun. An upfront alert to this might be helpful next time. Thanks for the hard work.
pieter
Last edited by pruiter on Mon Nov 21, 2005 8:28 pm, edited 1 time in total.
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Thanks guys, now on to the patching. :)
--Slixter
--Slixter
--Search the forums and you will find your answer
-
- Joomla! Fledgling
- Posts: 3
- Joined: Sat Oct 22, 2005 7:12 pm
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
infograf768 wrote:ISO has been reset to 8559-1 instead of utf-8.
As this is causing some problems on my site, I wonder if there is a simple way to fix it? Instead of "..." I see now "…" (check my site for an example: http://www.spiritofhouse.com/).
Thanks for your help,
Mike
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
I'm screwed!
It said the patch will work with Mambo 4.5.2.3 (I'm not ready to upgrade to Joomla just yet!).
So I did apply the patch via FTP.
Guess what??? my website is screwed! index.php is for Joomla!
Can anyone send me an index.php for Mambo? Is that the only file I shouldn't overwrite?
Thanks,
JSG
Update: Nevermind... found the file at mambo and uploaded and all's well! Whew! BUT TELL THAT TO SOMEONE STILL USING MAMBO!
It said the patch will work with Mambo 4.5.2.3 (I'm not ready to upgrade to Joomla just yet!).
So I did apply the patch via FTP.
Guess what??? my website is screwed! index.php is for Joomla!
Can anyone send me an index.php for Mambo? Is that the only file I shouldn't overwrite?
Thanks,
JSG
Update: Nevermind... found the file at mambo and uploaded and all's well! Whew! BUT TELL THAT TO SOMEONE STILL USING MAMBO!
Last edited by deafbiz on Mon Nov 21, 2005 8:22 pm, edited 1 time in total.
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Well cant say im happy with this security update.... since i did that i get the following message on my homepage [pop up message ]
overLIB 4.10 is required for the HideForm plugin.... whatever?!?
Resetting my account now to old installation... thx... will cost me 1 hour..
overLIB 4.10 is required for the HideForm plugin.... whatever?!?
Resetting my account now to old installation... thx... will cost me 1 hour..
Power to the devs!!!
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Thanks for the upgrade.
I have one (very) little remark, though.
On the main Joomla site, the download button still says 1.0.3.
I guess there hasn't been time yet to change this since 1.0.4 is only 4 hours old. But the 1.0.3-button looks a bit silly next to the article about 1.0.4
Keep up the great work guys!
I have one (very) little remark, though.
On the main Joomla site, the download button still says 1.0.3.
I guess there hasn't been time yet to change this since 1.0.4 is only 4 hours old. But the 1.0.3-button looks a bit silly next to the article about 1.0.4
Keep up the great work guys!
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
As you found out, it indeed doesn't work. You would have to completely migrate to Joomla to run the patch. First piece of advice is to ALWAYS create a backup of files and database before doing any patches, maintenance or big content updates. You can download the latest Mambo 4.5.2.3 version, and replace the files that were copied over by the Joomla patch. You should replace all files that Joomla replaced. Good luck!
Antonie de Wilde - Forum admin
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
deafbiz wrote:It said the patch will work with Mambo 4.5.2.3 (I'm not ready to upgrade to Joomla just yet!).
from http://www.joomla.org:
For those converting from Mambo 4.5.2.x please read these Migration instructions. You need to download the Joomla 1.0.4 Full package
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
benedikt wrote:Thanks for the upgrade.
I have one (very) little remark, though.
On the main Joomla site, the download button still says 1.0.3.
I guess there hasn't been time yet to change this since 1.0.4 is only 4 hours old. But the 1.0.3-button looks a bit silly next to the article about 1.0.4
Keep up the great work guys!
Button has been updated for several hours, i think you need to refresh your browser.
rhuk
http://www.rockettheme.com - RocketTheme Template Club
http://www.rockettheme.com/aff - RocketTheme Affiliate Program
http://www.rockettheme.com - RocketTheme Template Club
http://www.rockettheme.com/aff - RocketTheme Affiliate Program
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Oops .. you're right (again)
Well, I guess it's a perfect job then
Thanks again.
Well, I guess it's a perfect job then
Thanks again.
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Manoxtra wrote:Well cant say im happy with this security update.... since i did that i get the following message on my homepage [pop up message ]
overLIB 4.10 is required for the HideForm plugin.... whatever?!?
Resetting my account now to old installation... thx... will cost me 1 hour..
I installed a fresh Joomla 1.0.3 site just to test the patch before patching 30+ Joomla 1.0.3 sites, and I get the same problem when applying the patch. So... what's the work around? Could someone explain so we can patch our actual working sites?
Thanks.
- brad
- Joomla! Hero
- Posts: 2212
- Joined: Fri Aug 12, 2005 12:38 am
- Skype: tested
- Location: Sydney - Australia
- Contact:
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
Have you got a link to your site? This is not something I have seen on any sites that I have upgraded.. or even on the official Joomla sites.
Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!
- ProjectMayhem
- Joomla! Apprentice
- Posts: 5
- Joined: Thu Aug 18, 2005 3:01 pm
Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!
yeah I'd like to see what the deal is before I upgrade all of my sites aswell. so if you find out anything please share.
You are not your job. You are not how much money you have in the bank. You are not the car you drive. You are not the contents of your wallet. You are not your f!@#ing khakis. We are the all-singing, all-dancing crap of the world.