Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

A place to discuss recent announcements made by the Joomla! Core Team. Let's hear what you have to say.
User avatar
Jinx
Joomla! Engineer
Joomla! Engineer
Posts: 269
Joined: Fri Aug 12, 2005 12:47 am
Contact:

Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by Jinx » Mon Nov 21, 2005 4:05 pm

Discussion area for the announcement that:

Upgrade to Joomla! 1.0.4 Security Release now!
http://www.joomla.org/content/view/498/74/
Core Team member - Lead developer
'Making good things happen'

http://www.joomlatools.org - training, consulting and extension development

User avatar
Chinaman
Joomla! Apprentice
Joomla! Apprentice
Posts: 13
Joined: Sun Aug 21, 2005 8:46 am
Location: Perth, Western Australia
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by Chinaman » Mon Nov 21, 2005 4:12 pm

Well done to all the team, and thank you.
Joomla! - enjoying every minute of the journey!

User avatar
55thinking
Joomla! Apprentice
Joomla! Apprentice
Posts: 17
Joined: Mon Sep 05, 2005 8:58 am
Location: Madrid
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by 55thinking » Mon Nov 21, 2005 4:14 pm

I can see that this patch affects the english.php file located in the language directory. Can we know what changes have been done to this file such as other languages file may be updated too ?

Thank you
55 Thinking - Strategy Design Technology 
Good looking, Fast and Usable web solutions   
http://www.55thinking.com/

User avatar
guilliam
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 159
Joined: Thu Aug 18, 2005 10:27 am
Location: Sunny City Cebu, Philippines!
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by guilliam » Mon Nov 21, 2005 4:14 pm

wonderful!!

--> Sundial

the team surely prioritizes SECURITY at the top most of the list!

thank you!

- g
"I was one of those who wondered why people would pay so much $$$$ to do something that was so much fun!" -R. Harkrider, Fortran Code Engr.
^If u read that in $GREEN, you clearly missed the HIGHLIGHTS!
http://www.joomlancers.com | http://www.joomlaconsultancy.net

User avatar
pushfrog98
Joomla! Apprentice
Joomla! Apprentice
Posts: 12
Joined: Thu Sep 01, 2005 7:48 pm
Location: Greenville, Il

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by pushfrog98 » Mon Nov 21, 2005 4:17 pm

just wondering if this patch has anything to do with the $ambo exploit...

http://isc.sans.org/diary.php?storyid=870

User avatar
infograf768
Joomla! Engineer
Joomla! Engineer
Posts: 366
Joined: Fri Aug 12, 2005 3:47 pm
Location: •Translation Matters•

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by infograf768 » Mon Nov 21, 2005 4:20 pm

55thinking wrote:I can see that this patch affects the english.php file located in the language directory. Can we know what changes have been done to this file such as other languages file may be updated too ?

Thank you


ISO has been reset to 8559-1 instead of utf-8.
A few strings have been added.
Better use a diff program to check all.
Last edited by infograf768 on Mon Nov 21, 2005 4:59 pm, edited 1 time in total.
Jean-Marie Simonet / infograf · http://www.info-graf.fr · GMT +1
Qui vult dare parva non debet magna rogare.

User avatar
infograf768
Joomla! Engineer
Joomla! Engineer
Posts: 366
Joined: Fri Aug 12, 2005 3:47 pm
Location: •Translation Matters•

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by infograf768 » Mon Nov 21, 2005 4:33 pm

Powdered Toast Man wrote:Oh come on - are we not waiting for the 1.1 release this month?? Does this mean that the 1.1 release date will creep over into December? Maybe january even? Why couldn't you have put the security fixes into 1.1?

Hugely annoying..

PTM



Some like to wait until later on to patch their apps. It is their decision.

We have decided not to as many sites have been hacked.
1.0.4 had a few bugs fixed by the Maintenance team. It was just a matter of releasing it sooner than planned.

The time taken to do this has not been taken over the 1.1 development.  ;)

FYI: concerning 1.1, a second alpha will be released next week, then a beta.

Don't be so annoyed ;)
Jean-Marie Simonet / infograf · http://www.info-graf.fr · GMT +1
Qui vult dare parva non debet magna rogare.

User avatar
pcigre
Joomla! Apprentice
Joomla! Apprentice
Posts: 30
Joined: Mon Sep 05, 2005 11:21 am
Location: Nis, Serbia
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by pcigre » Mon Nov 21, 2005 4:44 pm

55thinking wrote:I can see that this patch affects the english.php file located in the language directory. Can we know what changes have been done to this file such as other languages file may be updated too ?

Thank you


You can see there what is changed:

http://developer.joomla.org/integration ... f_format=h
http://www.pcigre.com -> game community

User avatar
55thinking
Joomla! Apprentice
Joomla! Apprentice
Posts: 17
Joined: Mon Sep 05, 2005 8:58 am
Location: Madrid
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by 55thinking » Mon Nov 21, 2005 4:50 pm

pcigre.com wrote:
55thinking wrote:I can see that this patch affects the english.php file located in the language directory. Can we know what changes have been done to this file such as other languages file may be updated too ?

Thank you


You can see there what is changed:

http://developer.joomla.org/integration ... f_format=h


Thanks a lot, helpfull link
55 Thinking - Strategy Design Technology 
Good looking, Fast and Usable web solutions   
http://www.55thinking.com/

davidva
Joomla! Apprentice
Joomla! Apprentice
Posts: 10
Joined: Thu Sep 01, 2005 6:45 pm

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by davidva » Mon Nov 21, 2005 5:01 pm

infograf768 wrote:
Powdered Toast Man wrote:Oh come on - are we not waiting for the 1.1 release this month?? Does this mean that the 1.1 release date will creep over into December? Maybe january even? Why couldn't you have put the security fixes into 1.1?

Hugely annoying..

PTM



Some like to wait until later on to patch their apps. It is their decision.

We have decided not to as many sites have been hacked.
1.0.4 had a few bugs fixed by the Maintenance team. It was just a matter of releasing it sooner than planned.

The time taken to do this has not been taken over the 1.1 development.  ;)

FYI: concerning 1.1, a second alpha will be released next week, then a beta.

Don't be so annoyed ;)

So we still have at least a week 1/2 for 1.1? I was looking forward to the release sometime this week so I can integrate phpbb and go live with my site. =/

User avatar
nathandiehl
Joomla! Intern
Joomla! Intern
Posts: 70
Joined: Fri Aug 19, 2005 3:03 pm
Location: Indiana, USA
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by nathandiehl » Mon Nov 21, 2005 5:37 pm

Powdered Toast Man wrote:Oh come on - are we not waiting for the 1.1 release this month?? Does this mean that the 1.1 release date will creep over into December? Maybe january even? Why couldn't you have put the security fixes into 1.1?

Hugely annoying..

PTM



i for one am happy that the Joomla! Core Team doesn't think that Medium-Threat risks are so insignificant that they can wait a couple weeks. If you want to remain vulnerable, i might recommend you switch to Mambo or another CMS where they don't offer near the updates of Joomla!.

Thanks again core team--your work is highly appreciated!

and believe you, I appreciate my icons in administrator not going wacko anymore! Thanks again!
nathan.
If you're new to Joomla, Please read Anna's Joomla! Tips: viewtopic.php?t=5503

http://nathandiehl.com | Find out what makes me tick

jasonmartens

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by jasonmartens » Mon Nov 21, 2005 5:39 pm

Are there any general instructions for applying the patch package? Or do I simply untar the package on top of my existing installation?

User avatar
infograf768
Joomla! Engineer
Joomla! Engineer
Posts: 366
Joined: Fri Aug 12, 2005 3:47 pm
Location: •Translation Matters•

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by infograf768 » Mon Nov 21, 2005 5:44 pm

Upgrade Instructions

    * To update from Joomla! 1.0.3, all you have to do is simply overwrite files from the 1.0.3 to 1.0.4 Patch Package
    * To update from Joomla! 1.0.2, all you have to do is simply overwrite files from the 1.0.2 to 1.0.4 Patch Package
    * To update from Joomla! 1.0.1, all you have to do is simply overwrite files from the 1.0.1 to 1.0.4 Patch Package
    * To update from Joomla! 1.0.0, all you have to do is simply overwrite files from the 1.0.0 to 1.0.4 Patch Package

;)
Jean-Marie Simonet / infograf · http://www.info-graf.fr · GMT +1
Qui vult dare parva non debet magna rogare.

User avatar
guilliam
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 159
Joined: Thu Aug 18, 2005 10:27 am
Location: Sunny City Cebu, Philippines!
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by guilliam » Mon Nov 21, 2005 5:50 pm

infograf768 wrote:
Powdered Toast Man wrote:Oh come on - are we not waiting for the 1.1 release this month?? Does this mean that the 1.1 release date will creep over into December? Maybe january even? Why couldn't you have put the security fixes into 1.1?

Hugely annoying..

PTM



Some like to wait until later on to patch their apps. It is their decision.

We have decided not to as many sites have been hacked.
1.0.4 had a few bugs fixed by the Maintenance team. It was just a matter of releasing it sooner than planned.

The time taken to do this has not been taken over the 1.1 development.  ;)

FYI: concerning 1.1, a second alpha will be released next week, then a beta.

Don't be so annoyed ;)


this post from toastman is more annoying than anything else. hmmnn.. isnt he supposed to be happy the core team has released this patch for the benifit of ALL. oh well..

- g
"I was one of those who wondered why people would pay so much $$$$ to do something that was so much fun!" -R. Harkrider, Fortran Code Engr.
^If u read that in $GREEN, you clearly missed the HIGHLIGHTS!
http://www.joomlancers.com | http://www.joomlaconsultancy.net

User avatar
focalguy
Joomla! Apprentice
Joomla! Apprentice
Posts: 35
Joined: Fri Aug 19, 2005 2:46 am
Location: Washington State, USA
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by focalguy » Mon Nov 21, 2005 6:12 pm

Thanks again for all the hard work! Keep it up and 1.1 will be here when it's ready.
New to Joomla? :) Make sure2 visit:
\_Anna's Joomla Tips - index.php/topic,5503.0.html

User avatar
MolBio
Joomla! Apprentice
Joomla! Apprentice
Posts: 8
Joined: Wed Oct 12, 2005 9:30 pm
Location: Princeton, NJ
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by MolBio » Mon Nov 21, 2005 6:17 pm

Security releases should be the first priority and thanks to dev team that for these upgrades.
We can always wait a bit for the new version, but we certainly don’t want to be hacked!

Thanks again

User avatar
mediamagnate
Joomla! Intern
Joomla! Intern
Posts: 82
Joined: Fri Aug 12, 2005 2:09 pm
Location: Yorkshire
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by mediamagnate » Mon Nov 21, 2005 7:45 pm

It should also be remembered that some non-Joomla security issues may still exist depending on security measures and configuration of where your site is hosted. It is not unusual for some hosts to be better than others.

The team's fast response to what amounts to a serious issue is why I love this community.

Applause to our code commandos who've worked so hard during the past couple of days to make this happen.

User avatar
pruiter
Joomla! Fledgling
Joomla! Fledgling
Posts: 2
Joined: Sun Sep 25, 2005 4:52 pm
Location: New Jersey, USA

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by pruiter » Mon Nov 21, 2005 7:52 pm

Thanks guys. Security has priority of course, but the patch (103 to 104) screwed up all my diacritical-marked words, of which I have *many* on the site I'm building. Words like

Bahá'í

show up as

Bahá'Ã

Not fun. An upfront alert to this might be helpful next time. Thanks for the hard work.

pieter
Last edited by pruiter on Mon Nov 21, 2005 8:28 pm, edited 1 time in total.

User avatar
Slixter
Joomla! Intern
Joomla! Intern
Posts: 80
Joined: Wed Aug 17, 2005 9:48 pm
Location: St Cloud, MN

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by Slixter » Mon Nov 21, 2005 7:52 pm

Thanks guys, now on to the patching.  :)

--Slixter
--Search the forums and you will find your answer

MikeFossati
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Sat Oct 22, 2005 7:12 pm
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by MikeFossati » Mon Nov 21, 2005 8:10 pm

infograf768 wrote:ISO has been reset to 8559-1 instead of utf-8.


As this is causing some problems on my site, I wonder if there is a simple way to fix it? Instead of "..." I see now "…" (check my site for an example: http://www.spiritofhouse.com/).

Thanks for your help,
Mike

deafbiz
Joomla! Apprentice
Joomla! Apprentice
Posts: 5
Joined: Sun Aug 28, 2005 3:09 am

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by deafbiz » Mon Nov 21, 2005 8:18 pm

I'm screwed!

It said the patch will work with Mambo 4.5.2.3 (I'm not ready to upgrade to Joomla just yet!).

So I did apply the patch via FTP.

Guess what???  my website is screwed!  index.php is for Joomla!

Can anyone send me an index.php for Mambo? Is that the only file I shouldn't overwrite?

Thanks,
JSG :o

Update: Nevermind... found the file at mambo and uploaded and all's well! Whew!  BUT TELL THAT TO SOMEONE STILL USING MAMBO!
Last edited by deafbiz on Mon Nov 21, 2005 8:22 pm, edited 1 time in total.

User avatar
Manoxtra
Joomla! Apprentice
Joomla! Apprentice
Posts: 16
Joined: Thu Aug 18, 2005 5:35 pm
Location: Holland
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by Manoxtra » Mon Nov 21, 2005 8:20 pm

Well cant say im happy with this security update.... since i did that i get the following message on my homepage [pop up message  :'( ]

overLIB 4.10 is required for the HideForm plugin.... whatever?!?

Resetting my account now to old installation... thx... will cost me 1 hour..

:'(
Power to the devs!!!

User avatar
benedikt
Joomla! Apprentice
Joomla! Apprentice
Posts: 37
Joined: Mon Aug 22, 2005 2:29 pm
Location: Gent - Belgium

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by benedikt » Mon Nov 21, 2005 8:21 pm

Thanks for the upgrade.

I have one (very) little remark, though.
On the main Joomla site, the download button still says 1.0.3.
I guess there hasn't been time yet to change this since 1.0.4 is only 4 hours old. But the 1.0.3-button looks a bit silly next to the article about 1.0.4  ;)

Keep up the great work guys!

User avatar
Tonie
Joomla! Ace
Joomla! Ace
Posts: 1585
Joined: Thu Aug 18, 2005 7:13 am
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by Tonie » Mon Nov 21, 2005 8:22 pm

As you found out, it indeed doesn't work. You would have to completely migrate to Joomla to run the patch. First piece of advice is to ALWAYS create a backup of files and database before doing any patches, maintenance or big content updates. You can download the latest Mambo 4.5.2.3 version, and replace the files that were copied over by the Joomla patch. You should replace all files that Joomla replaced. Good luck!
Antonie de Wilde - Forum admin

User avatar
benedikt
Joomla! Apprentice
Joomla! Apprentice
Posts: 37
Joined: Mon Aug 22, 2005 2:29 pm
Location: Gent - Belgium

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by benedikt » Mon Nov 21, 2005 8:25 pm

deafbiz wrote:It said the patch will work with Mambo 4.5.2.3 (I'm not ready to upgrade to Joomla just yet!).


from http://www.joomla.org:
For those converting from Mambo 4.5.2.x please read these Migration instructions. You need to download the Joomla 1.0.4 Full package

User avatar
rhuk
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 217
Joined: Fri Aug 12, 2005 3:02 pm

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by rhuk » Mon Nov 21, 2005 8:30 pm

benedikt wrote:Thanks for the upgrade.

I have one (very) little remark, though.
On the main Joomla site, the download button still says 1.0.3.
I guess there hasn't been time yet to change this since 1.0.4 is only 4 hours old. But the 1.0.3-button looks a bit silly next to the article about 1.0.4  ;)

Keep up the great work guys!


Button has been updated for several hours, i think you need to refresh your browser.
rhuk
http://www.rockettheme.com - RocketTheme Template Club
http://www.rockettheme.com/aff - RocketTheme Affiliate Program

User avatar
benedikt
Joomla! Apprentice
Joomla! Apprentice
Posts: 37
Joined: Mon Aug 22, 2005 2:29 pm
Location: Gent - Belgium

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by benedikt » Mon Nov 21, 2005 8:38 pm

Oops .. you're right (again)

Well, I guess it's a perfect job then  :)

Thanks again.

User avatar
alterego
Joomla! Fledgling
Joomla! Fledgling
Posts: 3
Joined: Fri Aug 19, 2005 4:18 am
Location: Kansas

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by alterego » Mon Nov 21, 2005 9:13 pm

Manoxtra wrote:Well cant say im happy with this security update.... since i did that i get the following message on my homepage [pop up message  :'( ]

overLIB 4.10 is required for the HideForm plugin.... whatever?!?

Resetting my account now to old installation... thx... will cost me 1 hour..

:'(


I installed a fresh Joomla 1.0.3 site just to test the patch before patching 30+  Joomla 1.0.3 sites, and I get the same problem when applying the patch. So... what's the work around? Could someone explain so we can patch our actual working sites?

Thanks.

User avatar
brad
Joomla! Hero
Joomla! Hero
Posts: 2212
Joined: Fri Aug 12, 2005 12:38 am
Skype: tested
Location: Sydney - Australia
Contact:

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by brad » Mon Nov 21, 2005 9:17 pm

Have you got a link to your site? This is not something I have seen on any sites that I have upgraded.. or even on the official Joomla sites.
Brad Baker - Joomla! Core Team, Sites & Infrastructure.
http://www.rochen.com - Managed Dedicated, Reseller & Multiple Domain Hosting.
http://www.joomlatutorials.com <-- Joomla! 1.5 & 1.0.x
^New Joomla 1.5 Tutorials are out!

User avatar
ProjectMayhem
Joomla! Apprentice
Joomla! Apprentice
Posts: 5
Joined: Thu Aug 18, 2005 3:01 pm

Re: Discuss about : Upgrade to Joomla! 1.0.4 Security Release now!

Post by ProjectMayhem » Mon Nov 21, 2005 9:49 pm

yeah I'd like to see what the deal is before I upgrade all of my sites aswell.  so if you find out anything please share. ;D
You are not your job. You are not how much money you have in the bank.  You are not the car you drive. You are not the contents of your wallet. You are not your f!@#ing khakis. We are the all-singing, all-dancing crap of the world.


Post Reply