Google Groups Home
Help | Sign in
CSRF security issue
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  3 messages - Collapse all
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Rick Olson  
View profile
 More options Jul 4, 3:09 am
From: "Rick Olson" <technowee...@gmail.com>
Date: Fri, 4 Jul 2008 00:09:39 -0700
Local: Fri, Jul 4 2008 3:09 am
Subject: CSRF security issue
There's a CSRF vulnerability in Mephisto, I'd suggest patching your install:

http://github.com/technoweenie/mephisto/commit/90e2cc253d94e2e544bc8b...

If you're on SVN still, here's a raw patch that you can apply:

http://github.com/technoweenie/mephisto/commit/90e2cc253d94e2e544bc8b...

It applied cleanly to the 0.8 branch.

I know the project is basically dead, but I got a patch out just hours
of hearing about the issue.

--
Rick Olson
http://lighthouseapp.com
http://weblog.techno-weenie.net
http://mephistoblog.com


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Thomas R. Koll  
View profile
 More options Jul 4, 6:33 am
From: "Thomas R. Koll" <tom...@gmx.de>
Date: Fri, 4 Jul 2008 12:33:01 +0200
Local: Fri, Jul 4 2008 6:33 am
Subject: Re: [Mephisto] CSRF security issue

Am 04.07.2008 um 09:09 schrieb Rick Olson:

> I know the project is basically dead, but I got a patch out just hours
> of hearing about the issue.

looking at the network graph on the hub the project looks quite alive.
I just needs a day every week to merge all the changes into one
repository.

And, is anyone who works on the multisite stuff planning to do
a commercial host like they did with wordpress.com ?
Such a plattform might be a good way to promote mephisto.

ciao, tom

--
Thomas R. "TomK32" Koll || http://tomk32.de || http://ananasblau.com
just a geek trying to change the world
Skype: TomK32 || Mail: tom...@gmx.de


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Rick Olson  
View profile
 More options Jul 4, 11:40 am
From: "Rick Olson" <technowee...@gmail.com>
Date: Fri, 4 Jul 2008 08:40:41 -0700
Local: Fri, Jul 4 2008 11:40 am
Subject: Re: [Mephisto] Re: CSRF security issue

> looking at the network graph on the hub the project looks quite alive.
>  I just needs a day every week to merge all the changes into one
>  repository.

Feel free to take charge.  I don't like appointing 'core team'
members.  I figure if you want to do it, that you'll just do it :)

>  And, is anyone who works on the multisite stuff planning to do
>  a commercial host like they did with wordpress.com ?
>  Such a plattform might be a good way to promote mephisto.

I planned on it for a little bit, but I don't see the point to be
honest.  There are enough of them out there, I don't see it being a
huge hit or anything.  But, it's open source, so go for it.  I know of
at least one person that may be interested in doing an official
mephisto branded system though.

--
Rick Olson
http://lighthouseapp.com
http://weblog.techno-weenie.net
http://mephistoblog.com


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2008 Google