Security Release - CB 1.0.1 - RELEASED!

17 years 9 months ago #19035 by crash777
Replied by crash777 on topic Re:Security Release - CB 1.0.1 - RELEASED!

nant wrote:
Crash if you isntalled fresh the your version method should $have shown 1.0.1.
This means that something went wrong.
You can manually use ftp to upload the files over-writting the old ones.


Not sure what happened. I went back into mysql, redeleted everything... into FTP and redeleted everything and then uploaded via Joomla.. NOW it works.. it is the same thing I did last time.. weird.. onward and forward :)

Post edited by: crash777, at: 2006/08/18 05:49

Please Log in to join the conversation.

17 years 9 months ago #19038 by beat
Ok, work with new dedicated managed premium server completed (what a pleasure :), you should see the backend we have now...wow...More on this on another topic later this week. B)

jazmac wrote:

Upgrade went smoothly. Thanks for all your hard work!

I read the posting re register_globals emulation mentioned above. I'd like to implement it, but my CB installs have a problem. I've completed the CB 1.0.1 upgrade (running J! 1.0.10 w/.htaccess set to RG=off). If I also change the setting in globals.php, on my user list the navigation stops working. Only the 1st page is displayed. The next, 1, 2, 3, etc, links only return the 1st page. Registration, login & all else is fine. It's just the user list. Has anyone else seen this? Any ideas on how to fix?


Looking into this. Confirming this small problem of CB. Will PM/Email you shortly to test to check if other things go wrong ;) .

crash777 wrote:

I know this might be a bit offtopic.. does this Joomla setting have any adverse effects by itself or just with the unpatched version of CB?


Actually, this Joomla setting may break some extensions, or some functions of some extensions. This topic on joomla forum seems to track those:

forum.joomla.org/index.php?topic=86525.new;topicseen#new


rswennen wrote:

Joomlaboard 1.1.2 is not working any more either with the RG_EMULATION setting changed in the globals.php

How did you fix that ? Joomlapolis is running JB 1.1.2


Joomlapolis just got to the new server today, and myself I just became aware same time of this setting (aka remembered it from long time ago fergotten). It's not OFF on this site yet, as we first want to see today if all works as before (we moved from php 4.3 to latest 5.1, among many many other fine-tunings), but will be very soon turning that setting to OFF. I will also look into the JB problem and hopefully come back with a solution soon in the joomla thread mentioned.

crash777 wrote:

nant wrote:
Crash if you isntalled fresh the your version method should $have shown 1.0.1.
This means that something went wrong.
You can manually use ftp to upload the files over-writting the old ones.


Not sure what happened. I went back into mysql, redeleted everything... into FTP and redeleted everything and then uploaded via Joomla.. NOW it works.. it is the same thing I did last time.. weird.. onward and forward :)

Post edited by: crash777, at: 2006/08/18 05:49


When you overwrite by ftp, you should get the site offline first, wait for a minute, then overwrite. Depending on your server permissions settings and OS, the files used by the webserver will be locked for deleting/replacing/overwriting simultaneously by ftp. And some ftp implementations don't report those errors...

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in to join the conversation.

17 years 9 months ago #19045 by globule
Replied by globule on topic Re:Security Release - CB 1.0.1 - RELEASED!
beat wrote:

Ok, work with new dedicated managed premium server completed (what a pleasure :), you should see the backend we have now...wow...More on this on another topic later this week. B)

One server only for CB, wow!!!
I'm happy you could get one (with donations?)

Please Log in to join the conversation.

17 years 9 months ago #19047 by mediaguru
Replied by mediaguru on topic Re:Security Release - CB 1.0.1 - RELEASED!
Did the upgrade via expert mode. All seems ok, version shows correctly and plugs are working.

I did lose the user url in profile hack...

It would have been nice for expert mode if there was a listing of which exact files go where rather than trying to figure it out by comparing all the files.

CB/Joomla golf site: www.thegolfspace.com
Geek/joomla site: www.tkserver.com

Check out my Joomla/CB projects:

* LIKE thumbs up system for "liking" content items
* Karma - CB user rating system
* Golf Score Tracker
* Jitter - status update system. "What's on your mind?"
* CB Author Plug - Shows CB author link and avatar in content items. J1.5 compatible and very customizable!

Found on my web site or in the Joomlapolis Directory !

Please Log in to join the conversation.

17 years 9 months ago #19052 by beat
For those needing urgently the full compatibility with the globals.php register_globals emulation OFF recommended setting, here the

Quick fix for CB 1.0.1 on Joomla 1.0.x (we will integrate nicer, already tested, fix in next release):

in begining of components/com_comprofiler/comprofiler.php add:

[code:1]
if (isset($_REQUEST["limitstart"])) $limitstart  = mosGetParam ( $_REQUEST, 'limitstart' , '' ); //BBTEMPFIX
if (isset($_REQUEST["search"])) $search  = mosGetParam ( $_REQUEST, 'search' , '' ); //BBTEMPFIX
[/code:1]

just after:

[code:1]
defined( '_VALID_MOS' ) or die( 'Direct Access to this location is not allowed.' );
[/code:1]

Post edited by: beat, at: 2006/08/18 11:26
Last edit: changed $_GET to $_REQUEST for searches fix (sorry tested only the final fix, which is different...)

Post edited by: beat, at: 2006/08/18 23:27

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info

Please Log in to join the conversation.

17 years 9 months ago #19053 by jazmac
Replied by jazmac on topic Re:Security Release - CB 1.0.1 - RELEASED!
Yes Beat, I can confirm that this worked great! Perfecto!

Thanks so much!!!

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.251 seconds

Facebook Twitter LinkedIn