Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - security update v9.72 take 2
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

security update v9.72 take 2

 Post Reply Post Reply Page  12>
Author
billd3 View Drop Down
Senior Member
Senior Member


Joined: 19 February 2003
Location: United States
Status: Offline
Points: 530
Post Options Post Options   Thanks (0) Thanks(0)   Quote billd3 Quote  Post ReplyReply Direct Link To This Post Topic: security update v9.72 take 2
    Posted: 10 May 2011 at 3:37pm
Bruce - you mentioned:
>>It is recommended that anyone running either Web Wiz Forums on Windows 2000 IIS5 or Windows 2003 IIS6 upgrade to these latest versions as soon as possible.<<

How about folks hosted with you - if I recall, you are running IIS7 on 2008R2.

Does this mean we're ok?

I intend to update soon anyway simply because now we're I think 2 builds behind and you keep putting really nifty stuff in the forums, but wonder about how quickly now due to a security thing...
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Answer Answer
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 10 May 2011 at 4:29pm
Windows 2008 IIS7 is more secure so would not run files uploaded with the files names that have the vulnerability.

Anyone hosting on our Windows 2008 platform would not be affected.
Back to Top
efscl View Drop Down
Newbie
Newbie


Joined: 13 May 2007
Status: Offline
Points: 37
Post Options Post Options   Thanks (0) Thanks(0)   Quote efscl Quote  Post ReplyReply Direct Link To This Post Posted: 10 May 2011 at 4:40pm
Just after "years" a message form myself again: thx for the great maintenance and support!
Back to Top
123Simples View Drop Down
Senior Member
Senior Member
Avatar

Joined: 08 July 2007
Location: United Kingdom
Status: Offline
Points: 1192
Post Options Post Options   Thanks (0) Thanks(0)   Quote 123Simples Quote  Post ReplyReply Direct Link To This Post Posted: 10 May 2011 at 7:37pm
Originally posted by WebWiz-Bruce WebWiz-Bruce wrote:

Windows 2008 IIS7 is more secure so would not run files uploaded with the files names that have the vulnerability.

Anyone hosting on our Windows 2008 platform would not be affected.


That means I take it that anyone running the software through web wiz servers would not be in any immediate danger then? Just to clarify Bruce?
Back to Top
derekcohen View Drop Down
Groupie
Groupie


Joined: 25 July 2009
Status: Offline
Points: 25
Post Options Post Options   Thanks (0) Thanks(0)   Quote derekcohen Quote  Post ReplyReply Direct Link To This Post Posted: 11 May 2011 at 7:44am
We have done some customisation of the asp code to integrate the forum code with the parent web site.

Is there a way of knowing what specific changes we need to make to the code to fix the security issue?

thanks

Derek
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 11 May 2011 at 8:37am
If you have made customisations and are running 9.55 or above just replace the file functions/functions_upload.asp with that from the latest version.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (1) Thanks(1)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 11 May 2011 at 8:44am
Originally posted by MrTWS MrTWS wrote:

Originally posted by WebWiz-Bruce WebWiz-Bruce wrote:

Windows 2008 IIS7 is more secure so would not run files uploaded with the files names that have the vulnerability.

Anyone hosting on our Windows 2008 platform would not be affected.


That means I take it that anyone running the software through web wiz servers would not be in any immediate danger then? Just to clarify Bruce?


Most customers who host with us will be on Windows 2008 R2 and so would not be vulnerable, but we do have a small minority of around 100 customers left the old Windows 2003 platform who would be.

If customers are using WebsitePanel as their Control Panel they are on Windows 2008 and so would not be vulnerable, those using Helm as their Control Panel wioll be on Windows 2003 and would be vulnerable if running Web Wiz Forums.
Back to Top
derekcohen View Drop Down
Groupie
Groupie


Joined: 25 July 2009
Status: Offline
Points: 25
Post Options Post Options   Thanks (0) Thanks(0)   Quote derekcohen Quote  Post ReplyReply Direct Link To This Post Posted: 11 May 2011 at 8:49am
excellent - thanks - now done
Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.