Advertisement:

Author Topic: SMF 2.0.2 and 1.1.16 critical security patches released  (Read 1373815 times)

Offline oldfruitanting

  • Newbie
  • *
  • Posts: 1
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #160 on: February 24, 2012, 08:42:38 AM »
Hi,

This seems like a really stupid question but if I am on SMF 2.0.2 does the SMF 2.0.2 Update update my security or does it update my forum version to SMF 2.0.2. Which would obviously not work since I am already using SMF 2.0.2.

Basically, I have, all of a sudden received 130 posts in Polish about Viagra. So I thought I'd check out if there were any security updates available and low and behold there is,........'SMF 2.0.2 and 1.1.16 critical security patches released'. On uploading and installing it I get an error message stating it is not compatible with the forum version I am running, 'SMF 2.0.2'

Am I being stupid, and if so any ideas how to deal with my apparent security breach, can I block an IP address for posting, or are there any other patches I can install.

Any advice would be greatly appreciated.

Offline Kindred

  • The Mean One
  • Project Manager
  • SMF Master
  • *
  • Posts: 39,569
  • Gender: Male
  • Red Sox WIN!
    • wagner999 on Facebook
    • Kindred-999 on GitHub
    • www.linkedin.com/in/wdwagner/ on LinkedIn
    • @Kindred_999 on Twitter
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #161 on: February 24, 2012, 11:24:45 AM »
the 2.0.2 update is used to update and 2.0.1 forum to 2.0.2. If you are running 2.0.2 then you are at the current security revision.

That ebing said, spam is not usually a security issue, but rather a configuration issue...   you need to configure your registration and/or posting settings to avoid spam. There are dozens of threads discussing what settings and/or mods to add for this.
Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support forums.  Thank you.

Offline headguy

  • Newbie
  • *
  • Posts: 7
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #162 on: February 25, 2012, 09:16:00 PM »
Thanks for the update notification.

My admin section has been rendered useless since you took over my site and any link I click to up date just takes me back to this useless board.

Why do you force us to update and then not have a link to the updated files?


Offline Kindred

  • The Mean One
  • Project Manager
  • SMF Master
  • *
  • Posts: 39,569
  • Gender: Male
  • Red Sox WIN!
    • wagner999 on Facebook
    • Kindred-999 on GitHub
    • www.linkedin.com/in/wdwagner/ on LinkedIn
    • @Kindred_999 on Twitter
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #163 on: February 25, 2012, 09:49:59 PM »
Answered in your other thread.

Please don't double post... Plus, we do not do what you are suggesting
Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support forums.  Thank you.

Offline fashion99

  • Newbie
  • *
  • Posts: 1
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #164 on: February 28, 2012, 11:10:19 PM »
Thanks!

Update went fine!


Offline danickent

  • Newbie
  • *
  • Posts: 1
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #165 on: March 21, 2012, 02:09:17 AM »
good work and god bless you all the time   :)

Offline wanchai

  • Newbie
  • *
  • Posts: 1
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #166 on: April 01, 2012, 12:38:59 AM »
Thanks. ;D

Offline MLG Tanner

  • Newbie
  • *
  • Posts: 1
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #167 on: April 02, 2012, 03:29:52 PM »
Thanks

Offline garry383

  • Semi-Newbie
  • *
  • Posts: 11
  • Gender: Male
    • Stockport Solicitor
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #168 on: April 22, 2012, 09:18:05 AM »
I just started to use SMF.  Thank you for your continued updates.
Laws aren't meant to be broken, any bent, squashed and shanghai'd.

Offline searchgr

  • Sophist Member
  • *****
  • Posts: 1,244
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #169 on: June 20, 2012, 01:54:30 AM »
No updates for the last 6 months. This is very disappointing. What's going on?

Offline a10

  • Charter Member
  • Full Member
  • *
  • Posts: 451
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #170 on: June 20, 2012, 06:18:15 AM »
Quote
No updates for the last 6 months. This is very disappointing. What's going on?
No need for (security) updates for a long time. This is very positive!
2.0.8, mods: Remove Started By, Contact Page, Like Posts.

Offline Nodaz

  • Jr. Member
  • **
  • Posts: 320
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #171 on: June 20, 2012, 02:33:39 PM »
I logged into and loder forum i had up and found the upgrade for 1.1.5 to 1.1.16:
SMF File                   Your Version                 Current Version
SMF Package   SMF 1.1.15                           SMF 1.1.16
Sources                  1.1.11                           1.1.16
Default Templates  1.1.12                           1.1.12
Language Files          1.1.9                                   1.1.15

But when i click on : Update your forum, i get :
The package you are trying to download or install is either corrupt or not compatible with this version of SMF.
What do i need to do here.

Offline K@

  • Lead Support Specialist
  • SMF Master
  • *
  • Posts: 46,196
  • Gender: Male
  • Yum!
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #172 on: June 20, 2012, 03:44:00 PM »
Try downloading this:

http://download.simplemachines.org/index.php?thanks;filename=smf_1-1-16_update.zip

Upload it, still archived, into your Packages directory.

Then, go to Package Manager to apply it.

READ MY SIG!

Offline

  • SMF Friend
  • SMF Legend
  • *
  • Posts: 60,573
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #173 on: June 20, 2012, 03:44:46 PM »
Is the 1.1.16 package still broken? I thought it was fixed ages ago >_<
Payin' anything to roll the dice, just one more time
Some will win, some will lose, some were born to sing the bluess
Oh the movie never ends
It goes on and on and on and on

Offline K@

  • Lead Support Specialist
  • SMF Master
  • *
  • Posts: 46,196
  • Gender: Male
  • Yum!
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #174 on: June 20, 2012, 03:45:37 PM »
It was, supposedly.

Ain't life grand? ;)

Offline 青山 素子

  • Server Team
  • SMF Super Hero
  • *
  • Posts: 16,483
  • 戦場ヶ原、蕩れ!
    • motokochan on GitHub
    • @motokochan on Twitter
    • Animeneko Network
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #175 on: June 20, 2012, 05:17:34 PM »
The update download is not a modification package. It is designed to be extracted and the contents uploaded over the top of your existing instalation. Updating in this manner will remove any modification changes to the affected files.

Updates which can be applied through the package manager are located at http://custom.simplemachines.org/upgrades/.

Note that some hosting configurations have weird issues with compressed files. You can either try re-tarring (I've verified that manually using GNU tar 1.26 and gzip 1.4 will work 98% of the time), or wrapping in a zip if you absolutely must.
Motoko-chan
Director, Simple Machines

Just like... making of enemies / 負ける気しない やめるきない / You are cool but fool - Charisma.com 『HATE』

Note: I am not a member of the Simple Machines Forum project.


Offline

  • SMF Friend
  • SMF Legend
  • *
  • Posts: 60,573
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #176 on: June 20, 2012, 05:23:10 PM »
No, but the 1.1.15 to 1.1.16 patch, the one linked specifically through the admin panel, to be installed like a mod is supposed to be a modification package - except it's been broken since 1.1.16 came out.
Payin' anything to roll the dice, just one more time
Some will win, some will lose, some were born to sing the bluess
Oh the movie never ends
It goes on and on and on and on

Offline 青山 素子

  • Server Team
  • SMF Super Hero
  • *
  • Posts: 16,483
  • 戦場ヶ原、蕩れ!
    • motokochan on GitHub
    • @motokochan on Twitter
    • Animeneko Network
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #177 on: June 20, 2012, 05:58:24 PM »
No, but the 1.1.15 to 1.1.16 patch, the one linked specifically through the admin panel, to be installed like a mod is supposed to be a modification package - except it's been broken since 1.1.16 came out.

The first part of my response was concerning K@ directing users to use the update archive as a package manager package, which will not work.

As for the actual update patch, the direct-download functionality has always been hit-or-miss. What about the patch at the link I provided?
Motoko-chan
Director, Simple Machines

Just like... making of enemies / 負ける気しない やめるきない / You are cool but fool - Charisma.com 『HATE』

Note: I am not a member of the Simple Machines Forum project.


Offline Nodaz

  • Jr. Member
  • **
  • Posts: 320
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #178 on: June 20, 2012, 06:18:34 PM »
Try downloading this:

http://download.simplemachines.org/index.php?thanks;filename=smf_1-1-16_update.zip

Upload it, still archived, into your Packages directory.

Then, go to Package Manager to apply it.

READ MY SIG!

When i uploaded it i got the same error:
The package you are trying to download or install is either corrupt or not compatible with this version of SMF.

BUT then i went to browse packagse, it was there, i clicked on it and it installed fine...

Offline sharks

  • Sr. Member
  • ****
  • Posts: 891
  • Gender: Male
  • There's always a way.
Re: SMF 2.0.2 and 1.1.16 critical security patches released
« Reply #179 on: June 21, 2012, 04:35:45 AM »
It's been a while since the last SMF updates. I hope 2.1 is coming soon, along with 2.0.3 and 1.1.17? :)
SMF 2.0 Theme Color Editor
http://www.colorizeit.com/browse/24/smf-20-themes.html

SMF Package Parser to view all edits made by any modification package:
http://resourcez.biz/PackageParser/

Firefox is the best browser for SMF!
http://www.mozilla.com/en-US/firefox/fx/