Home arrow Forum Joomla-SMF 1.1.4.2 Security Release
  Welcome, Guest. Please login or register.
Did you miss your activation email?
September 08, 2008, 12:56:20 AM
Home New Posts Search Calendar


Login with username, password and session length
+  Joomla Forum
|-+  Joomla Hacks
| |-+  Joomla-SMF Forum Support
| | |-+  Joomla-SMF 1.1.x (Moderators: -Wolverine, kai920)
| | | |-+  Joomla-SMF 1.1.4.2 Security Release
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] 2 3 4 Go Down Print
Author Topic: Joomla-SMF 1.1.4.2 Security Release  (Read 15815 times)
-Wolverine
Moderator
Joomla Guru
*****

Karma: +374/-34
Offline Offline

Posts: 3393


Lead Developer


View Profile WWW
Joomla-SMF 1.1.4.2 Security Release
« on: July 11, 2006, 09:54:02 PM »

This is simply a security release including two small bug fixes to 1.1.4.    Since there is a reported security problem in mambo-smf I was alerted to some potential problems with the current JSMF 1.1.4.  This build addresses those problems.  I have also included all the user submitted language files, thanks to everyone for them(Imago, Özgür Üzden, videoed, kirck, mikeho)!

In this version I have made sure that patches to the J! index.php are universal such that the same patched index.php will work on all sites.  In that regards, I am attaching a patched J! 1.0.10 index.php for those that continue to have issues patching their systems.  To install it YOU MUST FOLLOW THE INSTRUCTIONS IN THE _README_FIRST.txt FILE!  Making a mistake can cause your site to go down and I will not be there to help you pick up the pieces, so use this at your own risk!


Installation instructions
  • Uninstall previous version of Joomla-SMF
  • Extract Joomla-SMF_1_1_4_2.zip
  • Log in to Joomla Adminsitrator
  • Select components from the Installers menu
  • Browse to the file com_joomla-smf_forum_1_1_4_2.zip
  • Click upload and install

Further requirements and installation instructions can be found in _README_FIRST.txt.

« Last Edit: July 28, 2006, 08:14:34 PM by -Wolverine » Logged

Need help?  Check Here First!
Get the JSMF User Guide
SEARCH this forum.
fanfan11
Joomla Newbie
*

Karma: +0/-0
Offline Offline

Posts: 1


View Profile
Re: Joomla-SMF 1.1.4.1 Security Release
« Reply #1 on: July 12, 2006, 02:40:23 AM »

when i click Joomla-SMF-Forum -> Configuration .
then show

 Huh
Logged
j.kay81
Joomla Newbie
*

Karma: +0/-0
Offline Offline

Posts: 5


View Profile
Re: Joomla-SMF 1.1.4.1 Security Release
« Reply #2 on: July 12, 2006, 08:54:29 AM »

Al ok on my website.
www.clubalfa.it
Thx! X-man  Grin Grin
Logged
-Wolverine
Moderator
Joomla Guru
*****

Karma: +374/-34
Offline Offline

Posts: 3393


Lead Developer


View Profile WWW
Re: Joomla-SMF 1.1.4.1 Security Release
« Reply #3 on: July 12, 2006, 09:22:23 AM »

when i click Joomla-SMF-Forum -> Configuration .
then show

 Huh
ummmm, is that a local install of apache?  I am guessing something isnt' installed correctly, the error is coming from apache.
Logged

Need help?  Check Here First!
Get the JSMF User Guide
SEARCH this forum.
Jeremy
Joomla Newbie
*

Karma: +1/-0
Offline Offline

Posts: 31


View Profile
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #4 on: July 12, 2006, 04:21:26 PM »

Ok big problems. this new 1.1.4.2 installs fine but i can not configure it.  The save and cancel buttons on the admin panel are non functioning. Please help I don't have a an old copy of 1.1.4 anymore and now I am stuck without a bridge. 

update. I did find 1.1.4 on the download page and tried to install it but still no dice. Now all of sudden the save and cancel buttons are toast in on configuration panel. I uninstalled the correct way so I don't get this. Any ideas?
« Last Edit: July 12, 2006, 04:28:47 PM by Jeremy » Logged
-Wolverine
Moderator
Joomla Guru
*****

Karma: +374/-34
Offline Offline

Posts: 3393


Lead Developer


View Profile WWW
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #5 on: July 12, 2006, 05:04:24 PM »

Ok big problems. this new 1.1.4.2 installs fine but i can not configure it.  The save and cancel buttons on the admin panel are non functioning. Please help I don't have a an old copy of 1.1.4 anymore and now I am stuck without a bridge. 

update. I did find 1.1.4 on the download page and tried to install it but still no dice. Now all of sudden the save and cancel buttons are toast in on configuration panel. I uninstalled the correct way so I don't get this. Any ideas?
I'm not having any problems.... anything showing up in the JS console?
Logged

Need help?  Check Here First!
Get the JSMF User Guide
SEARCH this forum.
Jeremy
Joomla Newbie
*

Karma: +1/-0
Offline Offline

Posts: 31


View Profile
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #6 on: July 12, 2006, 05:21:23 PM »

I'm not having any problems.... anything showing up in the JS console?

I was doing the work on my mac and safari would not report any errors but trying it over on my pc using IE i get an error on page:

Line:350
char: 2
Error: 'document.adminForm.task' is null or not an object
code: 0
URL: http://www.wwnazarene.org/cms/administrator/index2.php?option=com_smf&task=config
Logged
-Wolverine
Moderator
Joomla Guru
*****

Karma: +374/-34
Offline Offline

Posts: 3393


Lead Developer


View Profile WWW
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #7 on: July 12, 2006, 05:31:06 PM »

ok, still not working in IE apparently, but checking the source of the page the element it says is not there is definitely there... so effin IE sucks, yet again.  I'll keep looking at it...
« Last Edit: July 12, 2006, 05:37:05 PM by -Wolverine » Logged

Need help?  Check Here First!
Get the JSMF User Guide
SEARCH this forum.
Jeremy
Joomla Newbie
*

Karma: +1/-0
Offline Offline

Posts: 31


View Profile
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #8 on: July 12, 2006, 05:37:51 PM »

...

Huh Uh oh that reply must mean I am screwed  Undecided
Logged
-Wolverine
Moderator
Joomla Guru
*****

Karma: +374/-34
Offline Offline

Posts: 3393


Lead Developer


View Profile WWW
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #9 on: July 12, 2006, 05:38:49 PM »

no, I made a reply and then saw something different, so edited quickly
Logged

Need help?  Check Here First!
Get the JSMF User Guide
SEARCH this forum.
Jeremy
Joomla Newbie
*

Karma: +1/-0
Offline Offline

Posts: 31


View Profile
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #10 on: July 12, 2006, 05:41:32 PM »

no, I made a reply and then saw something different, so edited quickly

ok cool i will check back later..out of town for business and need dinner. Thanks for checking. I guess I will reload joomla if I hosed something big but can't figure out what it is hehe.
Logged
-Wolverine
Moderator
Joomla Guru
*****

Karma: +374/-34
Offline Offline

Posts: 3393


Lead Developer


View Profile WWW
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #11 on: July 12, 2006, 07:15:38 PM »

should be all set, a big part of the problem was the rdf feeds had all kinds of html special chars in there.  That caused IE to fail and not include the task(which is at the bottom of the form).  Should be good to go now, I updated the download.
Logged

Need help?  Check Here First!
Get the JSMF User Guide
SEARCH this forum.
Darren
Joomla Newbie
*

Karma: +0/-0
Offline Offline

Posts: 6


View Profile
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #12 on: July 12, 2006, 07:33:20 PM »

You know, I still have the problem I had with 1.1.3, and 1.1.1. The page loads to a point, but does not go beyond. I also have tried copying in the index.php file. What version of PHP has this been tested with? I am wondering if that might be a problem. Another thought might be something doing with the php.ini file, as I also have problem running the googlemap component from another person. Variables seem to be funky depending on the php version has been developed for.

See below for the other post I had...

Quote
I have the following:
Joomla 1.0.10
SMF 1.1RC2
CB 1.0 Stable
JSMF 1.1.4

I get the same blank page as Gustavo on vmset.com/index.php source code looks like:

Code:
<table class="blog" cellpadding="0" cellspacing="0"><tr><td valign="top"><div>

On the wrapped com_smf page I get this much shown:

Code:
<?xml version="1.0" encoding="iso-8859-1"?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>GarlandGuru - Bringing out your inner princess - Garland Gathering - Index</title>
<meta name="description" content="Joomla - the dynamic portal engine and content management system, Garland Gathering - Index." />
<meta name="keywords" content="Joomla, joomla, Garland, Gathering, Index" />
<meta name="Generator" content="Joomla! - Copyright (C) 2005 - 2006 Open Source Matters. All rights reserved." />
<meta name="robots" content="index, follow" />
<link rel="shortcut icon" href="http://vmset.com/images/favicon.ico" />
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />
<link href="http://vmset.com/templates/rhuk_solarflare_ii/css/template_css.css" rel="stylesheet" type="text/css"/>
</head>
<body>

<div align="center">
<table border="0" cellpadding="0" cellspacing="0" width="808">
<tr>
<td class="outline">
  <div id="buttons_outer">
    <div id="buttons_inner">
<div id="buttons">
</div>
</div>

  </div>
  <div id="search_outer">
    <div id="search_inner">
   
<form action="index.php?option=com_search" method="get">
<div class="search">
<input name="searchword" id="mod_search_searchword" maxlength="20" alt="search" class="inputbox" type="text" size="20" value="search..."  onblur="if(this.value=='') this.value='search...';" onfocus="if(this.value=='search...') this.value='';" /> </div>

<input type="hidden" name="option" value="com_search" />
<input type="hidden" name="Itemid" value="" />

</form>     </div>
  </div>
  <div class="clr"></div>
  <div id="header_outer">
  <div id="header">
  &nbsp;
  </div>
  <div id="top_outer">
<div id="top_inner">

<div class="moduletable">

I have been running fine but this is a clean install I am doing for a client as I bring them to my new server.
I am running
Apache 2.0.54 (Fedora)
PHP 5.0.4-10.5
MySQL 4.1.20-1.FC4.1
RedHat Linux FC4

Quote
I was looking closer at the index.php file. from lines 237-249 the code is this:
Code:
if ($path = $mainframe->getPath( 'front' )) {
$task = strval( mosGetParam( $_REQUEST, 'task', '' ) );
$ret = mosMenuCheck( $Itemid, $option, $task, $gid );

if ($ret) {
require_once( $path );
} else {
mosNotAuth();
}
} else {
header( 'HTTP/1.0 404 Not Found' );
echo _NOT_EXIST;
}

It is this code specifically that throws the first monkey wrench as I am stepping through. It appears that $ret is not loaded correctly to me. First pass at this review and many hours looking this over by this point.
Code:
if ($ret) {
require_once( $path );
} else {
mosNotAuth();
}

Okay, so I sat up and stepped through the code and found that as I step through the $path, I end up with a failure on the call in com_content. I think this must be a masking of an issue from another spot. May there be a global variable in com_smf that might be interferring with Joomla and how it is displaying? Is there notes on doing a manual patch of index.php? I am willing to help look through this. You can PM me and I will try and make a work around.

I stepped through the index.php file and followed it to the content.php file where it finally stops showing at. Anyone have ideas?

BTW, this works on my other server, but going back to that server is not an option as I am going to go on to develop a full GIS server that needs to have the supporting forum to work with it.

Thanks for any assistance that can be given.
Logged
Jeremy
Joomla Newbie
*

Karma: +1/-0
Offline Offline

Posts: 31


View Profile
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #13 on: July 12, 2006, 07:36:22 PM »

should be all set, a big part of the problem was the rdf feeds had all kinds of html special chars in there.  That caused IE to fail and not include the task(which is at the bottom of the form).  Should be good to go now, I updated the download.

Just got back and tried it out. Worked like a champ!!!! Thanks YOU!!!!! Cool
Logged
mikeho1980
Joomla Newbie
*

Karma: +1/-2
Offline Offline

Posts: 49



View Profile WWW
Re: Joomla-SMF 1.1.4.2 Security Release
« Reply #14 on: July 13, 2006, 12:16:32 PM »

This is simply a security release including two small bug fixes to 1.1.4.    Since there is a reported security problem in mambo-smf I was alerted to some potential problems with the current JSMF 1.1.4.  This build addresses those problems.  I have also included all the user submitted language files, thanks to everyone for them(Imago, Özgür Üzden, videoed, kirck, mikeho)!

Thanks Wolverine
1. The chinese languages were not installed as they were not included in the xml
2. I got problem with IE6, error message line 350 char 2 "document.adminForm.task" is null or not an object at JSMF config page. No problem in Firefox  Huh
3. Error message on frontend with IE6, line 202 char 1 "document.getElementById(...)" is null or not an object. Also no problem in Firefox...


My setting:
J! v1.0.10 beta2 Traditional Chinese UTF-8 ver
JSMF v1.1.4.2
SMF 1.1 RC2
CB 1.0 stable
CBlogin with CB-SMF plugin
« Last Edit: July 13, 2006, 12:21:59 PM by mikeho1980 » Logged
Pages: [1] 2 3 4 Go Up Print 
« previous next »
Jump to:  



Login with username, password and session length

Powered by MySQL Powered by PHP Joomla Forum | Powered by SMF 1.1 RC1.
© 2001-2005, Lewis Media. All Rights Reserved.
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!

Joomla Hacks is a Joomla Components, Joomla Modules, Joomla Templates, & Joomla Mambots resource portal.
None of the text or images in this public website may be copied without the expressed written consent of the authors.
Copyright 2005 by JoomlaHacks.com. Powered by Joomla. All rights reserved.
Terms of Use