WordCamp Philippines

WordCamp Philippines

If you’re a Pinoy blogger or a WordPress user/fan then most likely you’ve heard or read of this already. But in case you haven’t, I have good news for you. There will be a WordCamp held in the Philippines this coming September 6, 2008. If you don’t know what I’m talking about here’s a little info.

What is WordCamp?

WordCamp is a conference type of event that focuses squarely on everything WordPress. Everyone from casual end users all the way up to core developers show up to these events. These events are usually highlighted by speeches or keynotes by various people. WordCamp is a spin off from the popular BarCamp which was a spin off of FooCamp. - Weblog Tools Collection

WordCamp Philippines will be the first ever WordCamp organized and held in Asia. WordCamp Philippines is being organized by a group of Filipino bloggers based in Mindanao who were also responsible for organizing the successful 1st Mindanao Bloggers Summit held last year.

What are the objectives of WordCamp Philippines?

…to encourage more developers to use and deploy WordPress, not only as a blogging engine but also as a full-featured content management system for Web sites. Another is to increase the number of WordPress users and developers in the country. By developers, we mean programmers of WordPress plugins and designers of themes & templates.



Permalinks Migration Plugin Vulnerability
9 Comments 1008 Views

« WPDesigner’s $5 Themes Club Weekend Roundup #17 »



EDIT: Thank you Connie for bringing up the issue about the PacketStorm advisory regarding this issue. I’ve added a link to that advisory at the bottom of this post.

Over at Weblog Tools Collection, an article was posted earlier today regarding a vulnerability in version 1.0 of the Deans Permalinks Migration Plugin. The said vulnerability involves XSRF or Cross-site request forgery and allow the attacker to steal valid credentials.

The person who found out about this vulnerability and goes by the name g30rg3_x has an explanation for this vulnerability:

Since the variable $dean_pm_config[’oldstructure’] its not correctly sanitized (when retrieving), this allow any user to store/save “malicious code� inside the database and later be injected this “malicious code� when the data is retrieved. Using the XSRF as a “combo� we can create crafted pages that will force users to conduct this injection and steal some valid credentials to the WordPress based CMS.

As a normal procedure or etiquette for developers and programmers, g30rg3_x contacted the plugin author first to notify him about the vulnerability. But after several failed attempts, he took it upon himself to create and provide a fix for this plugin vulnerability.

If you’re currently using the Dean’s Permalink Migration Plugin version 1.0, it is strongly advised that you deactivate it and/or download/install the modified version to keep your blog secure. You can download the special sub-version 1.1-gx here.

If you want to read the PacketStorm advisory regarding the Dean’s Permalinks Migration Plugin vulnerability, click here. You can find this at page 20 of PacketStorm’s January advisory archives.

Hopefully no one gets victimized by this vulnerability. Have a fun and safe weekend everyone!

(2 votes, average: 5 out of 5)
If you enjoyed the article, why not subscribe?

Related Ads

Related Posts



9 Responses to “Permalinks Migration Plugin Vulnerability”

  1. MyAvatars 0.2   jhay PHILIPPINES Ubuntu Linux Mozilla Firefox 2.0.0.11 on Jan 25, 2008 | 6:27 pm | Reply

    It’s a good thing I don’t use this plugin, or any plugin that tinkers with my permalinks. Messing around with it is too risky in my thinking. Once a plugin screws up, your permalinks gets screwed up, and say good bye to PR and traffic. :lol:

    BTW, read from iRonnie that you’re planning on switching hosts? Could you tell the story why? I’m just curious, coz you’re leaving DreamHost? lol

    jhay’s last blog post..The FEJ Theme Reboot

  2. MyAvatars 0.2   Jaypee UNITED STATES Windows Vista Mozilla Firefox 2.0.0.11 on Jan 25, 2008 | 6:30 pm | Reply

    @jhay - I almost used this plugin when I changed my permalink structure. Good thing I decided to use the Permalink Redirect plugin.

    Haha you read that comment? Anyways, yeah I’m on the lookout for a new reliable webhost. If you want the detailed version, I’ll tell you via IM. :D

  3. MyAvatars 0.2   bluep PHILIPPINES Windows XP Mozilla Firefox 2.0.0.11 on Jan 25, 2008 | 9:53 pm | Reply

    hello jaypee. I haven’t tried this before. Dami ko talaga nahuhukay na plugins dito sa blog mo.

    anyhow your new theme is very grand. its like the mimbo theme which resembles an online magazine. I love this magazine type of theme. the mimbo was supposed to be my current theme pero i find it hard to meddle with the codes kaya i just went for the usual widget friendly.

    Have a nice weekend jaypee.

    bluep’s last blog post..Malayang Isipan

  4. MyAvatars 0.2   Jaypee UNITED STATES Windows Vista Mozilla Firefox 2.0.0.11 on Jan 25, 2008 | 9:55 pm | Reply

    @bluep - Ei, how you doin? Long time no see. Good to know that someone is learning and gaining new knowledge or acquiring new information from my blog. That’s the main reason I blog and what keeps me going.

    Glad you like the theme. There are many magazine type themes that are widget ready so maybe you can try the other ones if you’re having a hard time with Mimbo. Btw, your current theme looks very nice and you did a great job with it.

    You have a good weekend too & God bless! :)

  5. MyAvatars 0.2   trench GUAM Windows XP Mozilla Firefox 2.0.0.11 on Jan 27, 2008 | 4:20 am | Reply

    yeah, Im to chicken sh*t to try and change my permalinks now! very risky business! I’ve been getting incredible traffic and my latest PR was 5. So, got to stay focused! haha

    trench’s last blog post..Sweeney Todd: The Demon Barber of Fleet Street (Theaters)

  6. MyAvatars 0.2   Jaypee UNITED STATES Windows Vista Mozilla Firefox 2.0.0.11 on Jan 27, 2008 | 8:22 pm | Reply

    @trench - Before I changed my permalink structure, I was also scared to do it. But when I saw other bloggers do it and figured out how to do it, I got enough courage to do it. The Permalink Redirect plugin helped a lot because all traffic that was going to the old permalinks was directed to the new ones.

    Btw, I noticed that after I changed the permalinks structure, my SERP rankings improved. :)

  7. MyAvatars 0.2   Connie PHILIPPINES Mac OS X Mozilla Firefox 2.0.0.11 on Feb 3, 2008 | 12:43 am | Reply

    So where’s the link to the packetstorm advisory? I checked the weblogtools link, found none. I checked all advisories released by packetstorm for January 2008 (http://packetstormsecurity.org/0801-advisories/) and there’s nothing there either.

    Isn’t it just as possible that he who claims vulnerability in Dean Lee’s plugin was the one who injected the vulnerability in the revised version?

    Shouldn’t the revised version be double checked first before advising people to download it?

    Connie’s last blog post..Some thoughts about shrimp crackers and entrepreneurship

  8. MyAvatars 0.2   Jaypee UNITED STATES Windows Vista Mozilla Firefox 2.0.0.11 on Feb 3, 2008 | 3:53 am | Reply

    @Connie - Hi there! Thanks for bringing that up. I totally forgot to mention about the PacketStorm advisory and to provide the link to it. Anyways, I’ve added a link to the original Packetstorm advisory which you can find in page 20. Again, thanks for the heads up! :D

Sign up for PayPal and start accepting credit card payments instantly.

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

« WPDesigner’s $5 Themes Club Weekend Roundup #17 »


 Subscribe in a reader Or, subscribe via email:
Enter your email address: 
 
Feedburner
Google