HomeNotesIMPORTANT. Dolphin 6.1.3 Security Patch Release
1296 days ago in 
 

IMPORTANT. Dolphin 6.1.3 Security Patch Release

The Dolphin 6.1.3 Security patch is released. This patch fixes vulnerabilities when the PHP setting "register_globals" is on.

Hence, it covers much code re-work overall. This patch should be applied only to 6.1.2 (no earlier versions) to move to 6.1.3 using these instructions. You are recommended to apply it, even though you have applied solutions provided by other members here, as this is more comprehensive.

For those who are taking steps by upgrading from earlier versions up to the latest release above, please make sure that "register_globals" is set to OFF on your host.

Plussed by

 
 
 
 

Comments

Oldest First
|
Threaded
 
 
Please login to post a comment.
LightWolf
Awesome work Victor, thanks to all who created this wonderful software. I am installing the new dolphin as we speak. Hope this stops most of those mean hackers..urghhh
VictorT
You are welcome. Hope on this too.
jerry79
Thanks Victor! But could you support a Dif of the files? Cause my site is heavily moded, so i have to know what is changed to the original once.
Or maybe i dont have to use this, cause my registerd_globals are setted to off, this means i dont need it, right?

Cheers,
Jerry
VictorT
Sure, Diff is available at the instructions page to download.
jerry79
Hehe, NOW its there, when i wrote the post, there was no link ;)
sammie
Works like a charm, glad to see some of the bugs fixed too thank you team boonex i know you worked hard to get this done as quickly as possible. and it was a huge job.

just to clarify, although this patch makes it safer for dolphin site on hosts with register globals on. boonex still recommend, (as it is much safer all round) to choose a host with register globals off.
Dwain
Thanks Victor,

That was quick easy and painless... now let's see what the hackers do to counter.
realmasterd
hello VictorT,

many thanks from germany!
TheGateKeeper
I thank you also Victor for your efforts on behalf of us all
Tango
Big thanks for the patch....

On another but related subject... I checked my 'cache' folder and found a sub-folder named "PPP" which contains two "acct.php" and "index.html" files.

Are these normal? I have tried to download a copy and delete the files from my server but i can't do it.

Also, I have deleted the files under the 'cache' folder" just for my own security measure. is this OK.

Please advise.
AndreyP
Better clean your cache file, but before rename it to txt file and share with us - need to learn this scripts too to understand hack attacks better ;)
Tango
i cant delete the "ppp" sub-folder and its content.

1) What shall I do/change to delete these files?

2) How could i transmit you the 'unknown' files?

thanks and let me know.
killerhaai
You have to this from your server account, if you have root access.
That map is owned by the server, thats the reasons you can't delete or rename it.
hakknslash
I get the following error when I try to compile the ORCA language file. (I changed EVERY file and folder in ORCA to 777 and still get this message)

Warning: fopen(/MYSITE/orca/conf/params.conf): failed to open stream: Permission denied in /MYSITE/orca/inc/util.inc.php on line 263

Warning: Cannot modify header information - headers already sent by (output started at /MYSITE/orca/inc/util.inc.php:263) in /MYSITE/orca/inc/util.inc.php on line 36

Warning: Cannot modify header information - headers see more already sent by (output started at /MYSITE/orca/inc/util.inc.php:263) in /MYSITE/orca/inc/util.inc.php on line 37

Warning: Cannot modify header information - headers already sent by (output started at /MYSITE/orca/inc/util.inc.php:263) in /MYSITE/orca/inc/util.inc.php on line 38

Warning: Cannot modify header information - headers already sent by (output started at /MYSITE/orca/inc/util.inc.php:263) in /MYSITE/orca/inc/util.inc.php on line 39

Warning: Cannot modify header information - headers already sent by (output started at /MYSITE/orca/inc/util.inc.php:263) in /MYSITE/orca/classes/en/BxXslTransform.php on line 61
VictorT
Please delete "/MYSITE/orca/conf/params.conf" file and try to compile Orca language file again.
killerhaai
I got this: Language files compilation have been failed. Please check folders permissions.?? its not compiled
hakknslash
yes... deleting that file worked... but now, since I have changed every file in my orca directory to 777 what are the proper permissions I need to set my folders and files at to maintain security?
killerhaai
I got the same errors as first writer... and deleting the the file you advized has not effect...
killerhaai
I mean as hakknslash.... Its on top at every page, included admin pages
AndreyP
6.1.3 just begin to protect your dolphin much better,
Patch will not erase viruses :)
You should clean your dolphin before
avhow
Thanks for the patch. Can I also suggest you stop promoting Host For Web since they have register globals on by default.
AndreyP
Hard to find one good and stable host with enabled all params as required ..
We recommend HFW just because this is very stable and allow change all params just using .htaccess file (use php_flag register_globals Off here)
Swiftcreek1
I use Host For Web and had Boonex do my install.....my globals were set to "OFF" from day one. Whoever did your install should have reviewed this, and I would be inclined to put some of the responsibility on that person.
jamesbowie
Can you tell me where I can fin d the security patch please. I cannot find the link anywhere.
hakknslash
Above, Click on the link in the sentence "to move to 6.1.3 using these instructions."
It will take you to http://www.boonex.com/trac/dolphin/wiki/6.1.2to6.1.3 Where the directions and links to patches are.
avhow
Its in the top blog post. They are calling it an upgrade from 6.1.2 to 6.1.3. It seems if you run an earlier version you arent covered. For security reasons they recommend you have the latest version.
killerhaai
Oke now get strange things... I can't login to my own admin center after the patch, not only the same errors like Hakknslash, but also to admin login. I fill in my data and it say's "wating" and returns to index.php login.

I use firefox 3... Dolphin updated from 6.1.2 to 6.1.3 before the patch no problems...
killerhaai
This is the error I get:


Warning: Cannot modify header information - headers already sent by (output started at /home/harry2/domains/hobipoint.nl/public_html/inc/header.inc.php:1) in /home/harry2/domains/hobipoint.nl/public_html/inc/design.inc.php on line 633

Warning: Cannot modify header information - headers already sent by (output started at /home/harry2/domains/hobipoint.nl/public_html/inc/header.inc.php:1) in /home/harry2/domains/hobipoint.nl/public_html/inc/design.inc.php on line see more 634

Warning: Cannot modify header information - headers already sent by (output started at /home/harry2/domains/hobipoint.nl/public_html/inc/header.inc.php:1) in /home/harry2/domains/hobipoint.nl/public_html/inc/design.inc.php on line 635

Warning: Cannot modify header information - headers already sent by (output started at /home/harry2/domains/hobipoint.nl/public_html/inc/header.inc.php:1) in /home/harry2/domains/hobipoint.nl/public_html/inc/design.inc.php on line 636
AndreyP
If you still have site troubles you can send your site details to me (for example) to PM (don`t forget point what I need to do :) )
gameutopia
You might want to review the update instructions for updating yoursite.com/inc/header.inc.php

Sounds like you might have omitted the line where you should insert a new.

1 little line or missed file could potentially cause errors or problems. The good news with this one is no database updating.

I'd double check the instructions and back trace all your steps for starters.
Synergy
Thanks for the patch.
Stuart038
I am getting this:

Warning: require_once(BX_DIRECTORY_PATH_INCprofiles.inc.php) [function.require-once]: failed to open stream: No such file or directory in /home/connect/public_html/admin/index.php on line 26

Fatal error: require_once() [function.require]: Failed opening required 'BX_DIRECTORY_PATH_INCprofiles.inc.php' (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/connect/public_html/admin/index.php on line 26

And this under Orca

Warning: require_once(BX_DIRECTORY_PATH_ROOTgroups/orca/layout/uni/params.php) see more [function.require-once]: failed to open stream: No such file or directory in /home/connect/public_html/groups/orca/xml/config.php on line 89

Fatal error: require_once() [function.require]: Failed opening required 'BX_DIRECTORY_PATH_ROOTgroups/orca/layout/uni/params.php' (include_path='.:/usr/lib/php:/usr/local/lib/php') in /home/connect/public_html/groups/orca/xml/config.php on line 89

Help!

Stuart
AndreyP
1. recheck in your header.inc.php
are here present line
define('BX_DIRECTORY_PATH_INC', $dir['inc']);
and
define('BX_DIRECTORY_PATH_ROOT', $dir['root']);
?
Stuart038
and I cannot access Admin

Help!

Stuart
Evandromar
Hello, personnel boonex, I update my dolphin to 6.1.3, even taking register_globals, off? I have doubts!
VictorT
Well, there is nothing to worry about at the moment. We look attentively at every report or suspicious things all over.
theGhost
Thanks for the patch Victor.

I built a brand new Dolphin upgraded all the way from 6.1.1 to 6.1.3 had no problems. Forgot to update the header.inc.php and guess what error I got :) Updated language files no problem. I am currently running RG_off.

When I did the upgrade on GGsite all went fine but I am still being punched :) IT DID tweek the attack thou...I'll send you the Log File. Still No Infections!
VictorT
Yes, please send me. We will look into. Thanks.
coolbuddy
do we need to apply this patch even if we download the latest version today and start a fresh website ?
Stuart038
The version for download is 6.1.3. no probs!
 
 
 
PET:0.11502909660339