News:

Bored?  Looking to kill some time?  Want to chat with other SMF users?  Join us in IRC chat or Discord

Main Menu

SMF 1.1.9 and 2.0 RC1-1 released

Started by Compuart, May 20, 2009, 08:22:19 PM

Previous topic - Next topic

lurkalot

Can someone explain what the patch actually fixes? 

We were advised to turn off attachments and avatar uploads etc.  Does this fix the problem, and can we now turn them back on?

Tanks

Upgrade was problem free even with a tons of mods installed.

Thanks :)

riker

Does anyone know when RC2 is out and how long has the smf 2.0 project been worked on now ?

Electro-X-

YAY!!! I thought its gonna be 2.0RC2 cuz I want the curve theme. Anyway good job developers of simple machines!!
My New site - consolexp.com

riker

Quote from: Electro-X- on May 21, 2009, 03:30:44 AM
YAY!!! I thought its gonna be 2.0RC2 cuz I want the curve theme. Anyway good job developers of simple machines!!
At this stage I just want a theme that works.  I dropped back to IE7 last night and noticed other thigns in the cpanel that didn't work so had to use a different browser again

HecKel

I know this is not a support topic, but I think I should warning you / asking you about this.

I have two forums with RC1, one test forum and one  really community. Now...

I ONLY have the upgrade link in the test forum, and NOTHING in the "real" forum (sorry, but in the morning my English is worse than ever...), why this happens?

Another thing, I tried to upgrade the test forum, and I have got an message saying the packages is empty. This is suppose to happen?
Quote from: riker on May 21, 2009, 03:23:45 AM
Does anyone know when RC2 is out and how long has the smf 2.0 project been worked on now ?

The answer is: When its ready :) (and I am not joking, this is really the answer)
Quote from: Eliana Tamerin on August 23, 2008, 04:10:10 PM
SMF 7 is where it gets good. That has time travel. You can go back and post before the guy who flamed you. :P

riker

Quote
The answer is: When its ready :) (and I am not joking, this is really the answer)

That was a complete and utter waste of time and no one likes a back seat driver either.  Anyway by the time SMF 2.0 is final I'm sure Mybb and Phpbb will new versions out!

(.:Al-Pacino:.)

Does this Patch fix the avataruploadhack of krisbarteo?
I fot an SMF 1.1.9!
With a lot of Mods.
And a cool ommunity xDD
http://gold-community.tk/ [nofollow]

Dzonny

Very nice job guys, i'm glad this is finally released... :D
Congrats!

ScopeXL

Nice update, always enjoy seeing security vulnerabilities fixed :)

Marcus Forsberg


Jorin

Quote from: GOAT15 on May 21, 2009, 04:25:08 AM
Does this Patch fix the avataruploadhack of krisbarteo?

I think that's what this fix is made for.

Powerbob




My SMF 2.1 Beta test site; http://www.pplb.net/smf21/index.php

(.:Al-Pacino:.)

ok!

Now my Users can upload finally tehir avatars!!!

THX SMF!

It RulEzZZ :D
I fot an SMF 1.1.9!
With a lot of Mods.
And a cool ommunity xDD
http://gold-community.tk/ [nofollow]

Fustrate

Quote from: riker on May 21, 2009, 04:24:53 AM
Quote
The answer is: When its ready :) (and I am not joking, this is really the answer)

That was a complete and utter waste of time and no one likes a back seat driver either.  Anyway by the time SMF 2.0 is final I'm sure Mybb and Phpbb will new versions out!
so the quality of the forum is based on how often new releases are made?

Regarding your above post, work on RC2+Curve slowed down and even stopped while we worked on this patch. Which would you rather have - an exploited forum, or Curve? Rest assured, work is starting right back up again. We want to get RC2+Curve out as soon as possible, but we want to make sure you get something that works, not just a pretty dud ;)
Steven Hoffman
Former Team Member, 2009-2012

stevie1001

thank you for the good work!

Steve

Antechinus

Upgrade went smooth as silk on my modified site. Had one failure on Sources/PackageGet.php but on checking the file in Winmerge the failure was only caused by a bit of whitespace anyway. Pushed the button and it's all good. :)

Quote from: riker on May 21, 2009, 04:24:53 AM
QuoteThe answer is: When its ready :) (and I am not joking, this is really the answer)
That was a complete and utter waste of time and no one likes a back seat driver either.  Anyway by the time SMF 2.0 is final I'm sure Mybb and Phpbb will new versions out!

Riker, you already know that SMF does not give release dates. Things like this series of hacks requiring a quick and effective solution are one of the reasons why release dates aren't given. You never know when something will come out of nowhere and force you to drop everything and deal with the new problem. HecKel gave you exactly the same answer that you know you would get from any SMF team member. What did you expect him to say?

Jorin

Quote from: Fustrate on May 21, 2009, 04:38:21 AM
Regarding your above post, work on RC2+Curve slowed down and even stopped while we worked on this patch. Which would you rather have - an exploited forum, or Curve?

I want amostly secure and stable forum. Not as many RCs as possible in a very short time.  :)

Thanks to the team again for the fast reaction.

Vincent Volmer

Perfect!

Thanks for the good work!!

Vincent

Tristan Perry

Quote from: lurkalot on May 21, 2009, 03:04:27 AM
Can someone explain what the patch actually fixes? 

We were advised to turn off attachments and avatar uploads etc.  Does this fix the problem, and can we now turn them back on?
Yes, the aim of this patch was to fix those security flaws - hence it should now be completely safe to turn your attachments and avatars back on :)

Advertisement: