Jamroom Logo   Get Jamroom now for as low as $19!
The Powerful Social Media Platform
 Jamroom Support Forum Log in »  Forum Search »
** Important ** Jamroom 3.3.6 has been released!  Previous topic  Next topic 
bigguy
Jamroom Team


Joined: 09 Jul 2003
Posts: 34926
Location: Seattle, WA

Posted: 06/21/08 13:36 
The Jamroom Core downloads page has been updated with the latest release of Jamroom - version 3.3.6.

This new release contains a very important security fix, and everyone running any version of Jamroom 3.3.x (or 3.2.x with Payment Pack installed) should upgrade immediately. If you are running Jamroom 3.2.6 and older, are are not running the Jamroom Payment Pack, you are not affected by this issue. Also - if PHP is running with "register_globals" turned OFF, then you are also not affected.

If you cannot update immediately, it is highly recommend to delete the following files until you can upgrade:

jamroom/include/plugins/jrBrowser/payment.php
jamroom/include/plugins/jrBrowser/purchase.php

This will prevent the "payments" and "purchases" tab from working in your Admin Browser, but will remove the vulnerability from your Jamroom until you can upgrade.

A full list of changes in Jamroom 3.3.6 can be found here:

http://www.jamroom.net/index.php?m=td_tracker&o=browse&v=3.3.6

If anyone has any questions, please let me know.

Thanks!

- Brian


_________________
Make sure and check out:
* The Jamroom FAQ
* The Jamroom Documentation

Last edited by bigguy on 07/09/08 09:31; edited 2 times in total
Back to top
johnypneumo



Joined: 15 Jan 2004
Posts: 954
Location: united kingdom

Posted: 06/22/08 16:00 
Thanks Brian !

your a busy guy Wink


_________________
V7 music.com
Back to top
SteveX
Ultrabubble


Joined: 30 Aug 2005
Posts: 7601
Location: Ultrabubble

Posted: 06/22/08 17:10 
Thanks man, it is very reassuring to see such a fast and effective response in a potential crisis. (Didn't effect me though, I think I now only have sites on servers with register globals off).

For public information, reading Brian's and DJ's responses to a potential security issue is a short but sweet experience.

It brings to mind a quality wildlife programme in which a bewilderbeast steps stupidly into field of view, spots a potentially tasty morsel, and plonders towards it in true bewilderbeast fashion. Brian and DJ stir from beneath their shady trees. A few quiet signals, flanking maneuvers, some building up of speed (think cheetah), and the bewilderbeast is down, and seconds later dead. Gorily.

Takes a few minutes to chill down and carry the security spoils back to the cubs, but half an hour after first sighting, we are eating bewilderbeast tonight.

Great to see you guys in action! Thankyou!


_________________
Lush!

"Stranger from another planet, welcome to our hole. Just strap on your guitar and we'll play some rock and roll"

Ultrabubble create things.
Back to top
pasher
Motagator


Joined: 20 Aug 2003
Posts: 3862
Location: Nottingham, UK

Posted: 06/23/08 01:08 
A great and amusing allegory Steve Very Happy

And thanks to Brian and DJ for closing the door and so rapidly Very Happy

(DJ spent his day off on Sat. repairing all the JR sites he hosts - a bet a lot of you didn't even realise there was a problem Wink )

Cheers
Pa


_________________
What a long, strange, trip its been.

www.paulasher.com
www.motagator.net
www.gigmemories.com
Back to top
Conbud



Joined: 21 Jun 2006
Posts: 797
Location: New Orleans - Louisiana

Posted: 06/23/08 12:06 
Thanks for the update bigguy!


_________________
Back to top
minusme



Joined: 01 Jun 2004
Posts: 331

Posted: 06/24/08 07:55 
I checked my logs this afternoon and had almost 100 attempts to access these files. I came to the forum and there's a fix (which is good).

However if I didn't have globals turned off, I fear I would be in bad shape right now.

Is there a way to send a security warning to paid jamroom members before they are posted on the public tracker page?

Back to top
bigguy
Jamroom Team


Joined: 09 Jul 2003
Posts: 34926
Location: Seattle, WA

Posted: 06/24/08 15:44 

minusme:
I checked my logs this afternoon and had almost 100 attempts to access these files. I came to the forum and there's a fix (which is good).

However if I didn't have globals turned off, I fear I would be in bad shape right now.

Is there a way to send a security warning to paid jamroom members before they are posted on the public tracker page?


I'm working on some updates to Jamroom.net, and will be rolling out a new "backstage" forum for licensed Jamoom members - it would probably be best to post issues like this in there.

However, the users hitting your site most likely did not find out about this from Jamroom.net - it was posted on 50+ different security sites several hours before it was posted here.

Hope this helps!

- Brian


_________________
Make sure and check out:
* The Jamroom FAQ
* The Jamroom Documentation
Back to top
SteveX
Ultrabubble


Joined: 30 Aug 2005
Posts: 7601
Location: Ultrabubble

Posted: 06/24/08 15:57 

bigguy:
I'm working on some updates to Jamroom.net, and will be rolling out a new "backstage" forum for licensed Jamoom members

Is there a bar?


_________________
Lush!

"Stranger from another planet, welcome to our hole. Just strap on your guitar and we'll play some rock and roll"

Ultrabubble create things.
Back to top
bigguy
Jamroom Team


Joined: 09 Jul 2003
Posts: 34926
Location: Seattle, WA

Posted: 06/24/08 16:00 
There is Wink And you'll provide the drinks right? Wink

- Brian


_________________
Make sure and check out:
* The Jamroom FAQ
* The Jamroom Documentation
Back to top
SteveX
Ultrabubble


Joined: 30 Aug 2005
Posts: 7601
Location: Ultrabubble

Posted: 06/24/08 16:27 
Real Ale is free and on me, but if it needs an umbrella and an olive on a stick it is very, very expensive. Very Happy


_________________
Lush!

"Stranger from another planet, welcome to our hole. Just strap on your guitar and we'll play some rock and roll"

Ultrabubble create things.
Back to top
Conbud



Joined: 21 Jun 2006
Posts: 797
Location: New Orleans - Louisiana

Posted: 06/25/08 04:23 

bigguy:
There is Wink And you'll provide the drinks right? Wink

- Brian


Yeah and I'll supply some Cajun food. Cool


_________________
Back to top
pasher
Motagator


Joined: 20 Aug 2003
Posts: 3862
Location: Nottingham, UK

Posted: 06/25/08 04:26 

Conbud:

bigguy:
There is Wink And you'll provide the drinks right? Wink

- Brian


Yeah and I'll supply some Cajun food. Cool


Now your talking Very Happy


_________________
What a long, strange, trip its been.

www.paulasher.com
www.motagator.net
www.gigmemories.com
Back to top
djmerlyn
Jamroom Ustad


Joined: 18 Dec 2003
Posts: 13043
Location: Behind You

Posted: 06/25/08 04:59 
I have a serious craving for some 5 star Thai Cool


_________________
Pro JR Hosting
-100% Guaranteed

"more server and network power than any host, dedicated to your jamroom site"
Back to top
Jamie



Joined: 18 May 2007
Posts: 118
Location: Strathmore Alberta,Canada

Posted: 06/25/08 13:24 
Very Happy Thanks for updating my site to the new version bigguy. Very Happy

The control panel system with the hot buttons are very cool.
First I was confused when logging in for the first time, but only after 2 minutes browsing and getting used to it. I realized how great it was.
Thanks alot.

Cant wait for future versions and all that you bring to jamroom.

-Jamie


_________________
I'll be back with a jamroom site someday!
Music Distribution And Artist Promotion Centre
Back to top
bigguy
Jamroom Team


Joined: 09 Jul 2003
Posts: 34926
Location: Seattle, WA

Posted: 06/25/08 16:36 

Jamie:
Very Happy Thanks for updating my site to the new version bigguy. Very Happy

The control panel system with the hot buttons are very cool.
First I was confused when logging in for the first time, but only after 2 minutes browsing and getting used to it. I realized how great it was.
Thanks alot.

Cant wait for future versions and all that you bring to jamroom.

-Jamie


Thank you Jamie - I'm glad you like the new look Wink

- Brian


_________________
Make sure and check out:
* The Jamroom FAQ
* The Jamroom Documentation
Back to top
Display posts from previous:   
Page 1 of 2 Goto page 1, 2  Next

 
Jump to:  
Home | Download | Support | FAQ | Demos | Members | Purchase | Marketplace | Contact | Privacy
Forum by phpBB © 2001, 2005 phpBB Group
©2003 - 2009 Talldude Networks, LLC.