Sticky

Sticky

When a item or topic is "Sticky" it means it will stay on top to track your attention in reading it. This is mostly done because there is important information to be found in such a item or topic.
[ Close ]

Announcement

Announcement

When an important issues arrises for this item or topic an Announcement will be made. Here you can read about this important matter and respond to it.
[ Close ]

Global announcement

Global announcement

When an important issues arrises for this section, item list or category a Global Announcement will be made. Here you can read about this important matter and respond to it. A Global Announcement is more important than an Announcement.
[ Close ]

Site announcement

Site announcement

When an important issues arrises for the etire website an Site Announcement will be made. Here you can read about this important matter and respond to it. This is really important so read it.
[ Close ]

Normal

Normal

This is a normal page, topic or item. It is a normal informative page, topic or item.
[ Close ]

Closed

Closed

This item or topic is closed. The reason can be read inside it. If not? Then it will probably be closed because of the age of the matter or inactivity.
[ Close ]

Bug report

Bug report

When someone has found a bug in an application, or something else, he or she can report it using this function. Then we will look at it and see if we can fix it.
[ Close ]

Solved

Solved

When ever a bug report (problem, error, etc.) has been solved it gets this type assigned.
[ Close ]

Open

Open

This is an open item. Research is beeing done to learn about the people that need this or requested it. We are making a project file to record all things that have to be done to complete this project.
[ Close ]

Paused

Paused

This item paused. Meaning all progress on it is halted. Progress might be started again or it will be stopped. Depending if it is needed and if it can be done.
[ Close ]

In development

In development

This item is in development. It's not done yet, but we are working on it to finnish it. This is the step that takes the longest time.
[ Close ]

Beeing written

Beeing written

The writers are still writing this item. For now it is not done yet. Writers can take a long time to write something so give them some time.
[ Close ]

Stopped

Stopped

This item is stopped. All development and progress is stopped and will not be started again.
[ Close ]

Closed

Closed

This item is closed. All development and progress is stopped and will not be started again.
[ Close ]

Upgrading

Upgrading

This item is beeing upgraded. A new version is beeing developed.
[ Close ]

Finnished

Finnished

This page, item, etc. is Finnished. For now nothing is done about it.
[ Close ]

Finnished, upgrading

Finnished, upgrading

This item is Finnished. Now probably by popular demand a new version is beeing developed.
[ Close ]

Done

Done

This item is complete and nothing will be done with it for now.
[ Close ]

Under review

Under review

When an item is under review means it is done, but some minor bugs, layout changes or missing features needs to be finnished. After that it will be really done.
[ Close ]
Location: Newanz » (One of) our worst NiGhTmArE(s)

(One of) our worst NiGhTmArE(s)

(One of) our worst NiGhTmArE(s)

Apr 13th, 2008 at 12:00:00

First of: Download the New NewsOffice 1.1.1 Version.

About the new version

Well this a day we will remember for a while, the first (public) bug ever in a script of Newanz. Oh the joy Default
What happend?
Today I woke up. Just like any other sunday. I was thinking: what to do? "Mike and Mike's", Shore or just relaxing?

NO!

I logged in, went to check for some errors in our error log, and damnit there were some hack ATTEMPTS to crack NewsOffice. That's just the worst my day could start! I did a quick Google to NewsOffice and yes there it was, the bugsite milw0rm.

RoMaNcYxHaCkEr, found a bug in news_show.php. (for the ones that look for a link to the site, I gave enough keywords for a quick google search?)

So what did I do?
Well first contact some people to start up the project again, this was a bug that was dying to be fixed. And so said, we got right to it.
...3 hours later...

Done, he he, about time security bug fixed and prevent some other access methods we were eager to fix. In the mean time I helped out three people with installing NewsOffice and except for one person, it all worked.

What did we learn? We will keep googeling our projects for reported bugs, but then again, we find them in our error logs too.

One last thing: We got an open letter to RoMaNcYxHaCkEr:
Hello RxH,

We caught your "NewsOffice 1.1 Remote File Include Vulnerabilitiy" page on [filtered]
But of course you know that Wink

Well we didn't like it of course, but are on the other hand happy that someone found it.
So we are happy that you informed people about it, but we aren't happy that people tried to hack our website aswell.
What we know of they failed, our server doesn't allow php to include files from other servers.

Would you be so kind that when you find another leak/bug/exploid to inform us too in advance?
Instead of letting it find us in our error logs?

Thank you,

Tom de Bruijn - Newanz.com

Thank you for reading,

Tom de Bruijn - Newanz Staff

Error: No comments system active - No topic found