Page 12 of 12 FirstFirst ... 2101112
Results 111 to 118 of 118

Thread: My plugin removed from WP.org extend directory

  1. #111
    Ryan's Avatar
    Ryan is offline WordPress Legend
    Join Date
    Jan 2009
    Location
    New Zealand
    Posts
    2,797

    Default

    I'm far from an expert, but I've had a good poke through the code recently and from what I can tell, the security exploit would take an interesting combination of factors to become a problem.

    If we were rating threads for their usefulness, I'd put this one at the very top. I've learned more about security from this topic than I ever have before. Even though there isn't a lot of information in here about how the security vulnerability could work, it motivated me to do a lot of research into how such attacks "could" happen and this has been incredibly helpful in my own understanding of web security.

    It has also made me more paranoid

  2. #112
    aldenml's Avatar
    aldenml is offline Hello World
    Join Date
    Jan 2010
    Location
    USA
    Posts
    62

    Default

    Ok, the new version is the 1.6.10.1, let me tell you the differences

    aioseop.class.php

    line 5: var $version = "1.6.10.1";

    all_in_one_seo_pack.php

    line 7: Version: 1.6.10.1
    line 557: return '1.6.10.1';
    line 640: // $aioseop_options['aiosp_donate'] = "0";


    I can't see any change regarding the security issues.

  3. #113
    chipbennett's Avatar
    chipbennett is offline WordPress Legend
    Join Date
    Feb 2009
    Location
    St. Louis, MO
    Posts
    1,993

    Default

    Quote Originally Posted by Ryan View Post
    I'm far from an expert, but I've had a good poke through the code recently and from what I can tell, the security exploit would take an interesting combination of factors to become a problem.
    Which brings us full-circle, back to the original question: why was Alden's plugin removed from the repository in the first place?

    If we were rating threads for their usefulness, I'd put this one at the very top. I've learned more about security from this topic than I ever have before. Even though there isn't a lot of information in here about how the security vulnerability could work, it motivated me to do a lot of research into how such attacks "could" happen and this has been incredibly helpful in my own understanding of web security.

    It has also made me more paranoid
    That isn't always a bad thing. Remember Steve Gibson's security axiom: TNO (Trust No One).
    WP TurnKey - Turn-Key WordPress installation and maintenance services
    WordPress user since 2005 | @chip_bennett | chipbennett.net | cbnet Plugins

  4. #114
    aldenml's Avatar
    aldenml is offline Hello World
    Join Date
    Jan 2010
    Location
    USA
    Posts
    62

    Default

    Quote Originally Posted by Jeffro View Post
    Based on new information today, the security changes went into AIOSEO and the pro version.
    Can you confirm the information? I can't see any relevant change in the source code besides the version number.

  5. #115
    andreasnrb's Avatar
    andreasnrb is offline Kegger
    Join Date
    Jun 2009
    Posts
    594

    Default

    Quote Originally Posted by Ryan View Post
    I'm far from an expert, but I've had a good poke through the code recently and from what I can tell, the security exploit would take an interesting combination of factors to become a problem.
    I know. Which was my initial reaction also. Which is why I thought Mark J should come and tell us the security problems he found.

  6. #116
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,358

    Default

    Quote Originally Posted by aldenml View Post
    Can you confirm the information? I can't see any relevant change in the source code besides the version number.
    I thought I heard from others that the security updates went into the new version. Maybe I was wrong. Hard to contemplate a security fix going this long without being implemented.

  7. #117
    FolioVision's Avatar
    FolioVision is offline Hello World
    Join Date
    Jan 2010
    Location
    Vienna/Bratislava
    Posts
    4

    Default

    The pulling of Alden's plug and ours was extremely suspicious. I would not trust Michael Torbert at this point. Mark Jacquith appears to have been the one to clean up a very dubious situation. Which he did efficiently and cordially. I'd still like to know the identity of the hidden informer.

    For those who would like to keep complete cross-compatibility with All in One but benefit from safe code, our FV All in One SEO Pack has both. In any case, I would suggest moving to either Alden's SEO plugin or ours. Both of us drop the obnoxious advertising and improve the interface.

  8. #118
    chipbennett's Avatar
    chipbennett is offline WordPress Legend
    Join Date
    Feb 2009
    Location
    St. Louis, MO
    Posts
    1,993

    Default

    Quote Originally Posted by FolioVision View Post
    The pulling of Alden's plug and ours was extremely suspicious. I would not trust Michael Torbert at this point. Mark Jacquith appears to have been the one to clean up a very dubious situation. Which he did efficiently and cordially. I'd still like to know the identity of the hidden informer.
    I really think what happened here should be fully brought to light. Those involved - as well as the half-million AIOSEOP users - really do have a right to know the details of what happened here.

    For those who would like to keep complete cross-compatibility with All in One but benefit from safe code, our FV All in One SEO Pack has both. In any case, I would suggest moving to either Alden's SEO plugin or ours. Both of us drop the obnoxious advertising and improve the interface.
    And thanks to both of you, for demonstrating the best of the free software philosophy, by improving on code and contributing it back to the community.
    WP TurnKey - Turn-Key WordPress installation and maintenance services
    WordPress user since 2005 | @chip_bennett | chipbennett.net | cbnet Plugins

Page 12 of 12 FirstFirst ... 2101112

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •