Archive for the ‘Technology|Security Updates’ Category
Quickies: 10 Minute Email Addresses? Yep.
In today’s world, Big Brother always seems to be watching. To post a comment, or even to get more information about many products and services merchants often require that you first register with a valid email address. This is annoying and exposes your web actions to prying eyes. No matter who you are, and how G-rated your surfing habbits may be, sometimes you just need an anonymous email address to avoid the risk if having your email address end up at the mercy of spammers.
If you need a temporary (and I do mean temporary) email address just to get a confirmation link for something, information you do not want sent to your real mail address, or to log in to make a comment somewhere try 10 Minute Mail.
How it works:
- Visit the site, and get a free temporary email address.
- Use it to.
- After ten minutes, the email address goes away.
You do not have to give out personal information and it is free.
Joomla Security Updates – January 2011
Joomla! Security News
- [20101101] – Core – XSS Vulnerabilities
- [20101001] – Core – XSS Vulnerabilities
- [20100701] – Core – SQL Injection / Internal Path Exposure
- [20100702] – Core – XSS Vulnerabillitis in Back End
- [20100703] – Core – XSS Vulnerabilities in Back End
- [20100704] – Core – XSS Vulnerabilities in Back End
- [20100501] – Core – XSS Vulnerabilities in Back End
- [20100423] – Core – Negative Values for Limit and Offset
- [20100423] – Core – Installer Migration Script
| [20101101] – Core – XSS Vulnerabilities
Posted: 04 Nov 2010 09:04 AM PDT § Project: Joomla! § SubProject: All § Severity: Low § Versions: 1.5.21 and all previous 1.5 releases § Exploit type: SQL Injection – Information Disclosure § Reported Date: 2010-October-05 § Fixed Date: 2010-November-04 DescriptionInadequate filtering of request variables causes database errors. Affected InstallsAll 1.5.x installs prior to and including 1.5.21 are affected. SolutionUpgrade to the latest Joomla! version (1.5.22 or later) Reported by YGN Ethical Hacker Group ContactThe JSST at the Joomla! Security Center. |
| [20101001] – Core – XSS Vulnerabilities
Posted: 08 Oct 2010 09:04 AM PDT § Project: Joomla! § SubProject: All § Severity: Medium § Versions: 1.5.20 and all previous 1.5 releases § Exploit type: XSS Injection § Reported Date: 2010-October-05 § Fixed Date: 2010-October-08 DescriptionInadequate filtering of multiple encoded entities permits XSS attacks in some circumstances. Affected InstallsAll 1.5.x installs prior to and including 1.5.20 are affected. SolutionUpgrade to the latest Joomla! version (1.5.21 or later) Reported by YGN Ethical Hacker Group ContactThe JSST at the Joomla! Security Center. |
| [20100701] – Core – SQL Injection / Internal Path Exposure
Posted: 15 Jul 2010 09:04 AM PDT § Project: Joomla! § SubProject: All § Severity: Low § Versions: 1.5.19 and all previous 1.5 releases § Exploit type: Internal Path Exposure § Reported Date: 2010-June-10 § Fixed Date: 2010-July-15 DescriptionBack-end user can create MySQL error which shows internal path information in the error message. Affected InstallsAll 1.5.x installs prior to and including 1.5.19 are affected. SolutionUpgrade to the latest Joomla! version (1.5.20 or later) Reported by Andy Gorges ContactThe JSST at the Joomla! Security Center. |
| [20100702] – Core – XSS Vulnerabillitis in Back End
Posted: 15 Jul 2010 09:04 AM PDT § Project: Joomla! § SubProject: All § Severity: Medium § Versions: 1.5.19 and all previous 1.5 releases § Exploit type: XSS Injection § Reported Date: 2010-June-8 § Fixed Date: 2010-July-15 DescriptionBack-end user can inject Javascript in various administrator screens. Affected InstallsAll 1.5.x installs prior to and including 1.5.19 are affected. SolutionUpgrade to the latest Joomla! version (1.5.20 or later) Reported by José Antonio Vázquez González ContactThe JSST at the Joomla! Security Center. |
| [20100703] – Core – XSS Vulnerabilities in Back End
Posted: 15 Jul 2010 09:04 AM PDT § Project: Joomla! § SubProject: All § Severity: Medium § Versions: 1.5.19 and all previous 1.5 releases § Exploit type: XSS Injection § Reported Date: 2010-June-8 § Fixed Date: 2010-July-15 DescriptionBack-end user can inject Javascript in various administrator screens. Affected InstallsAll 1.5.x installs prior to and including 1.5.19 are affected. SolutionUpgrade to the latest Joomla! version (1.5.20 or later) Reported by José Antonio Vázquez González ContactThe JSST at the Joomla! Security Center. |
| [20100704] – Core – XSS Vulnerabilities in Back End
Posted: 15 Jul 2010 09:04 AM PDT § Project: Joomla! § SubProject: All § Severity: Medium § Versions: 1.5.19 and all previous 1.5 releases § Exploit type: XSS Injection § Reported Date: 2010-June-1 § Fixed Date: 2010-July-15 DescriptionBack-end user can inject Javascript in various administrator screens. Affected InstallsAll 1.5.x installs prior to and including 1.5.19 are affected. SolutionUpgrade to the latest Joomla! version (1.5.20 or later) Reported by Mesut Timur. ContactThe JSST at the Joomla! Security Center. |
| [20100501] – Core – XSS Vulnerabilities in Back End
Posted: 27 May 2010 05:00 PM PDT § Project: Joomla! § SubProject: All § Severity: High § Versions: 1.5.17 and all previous 1.5 releases § Exploit type: XSS Injection § Reported Date: 2010-May-13 § Fixed Date: 2010-May-28 DescriptionBack-end user can inject javascript in various administrator screens. Affected InstallsAll 1.5.x installs prior to and including 1.5.17 are affected. SolutionUpgrade to the latest Joomla! version (1.5.18 or later) Reported by Riyaz Ahemed ContactThe JSST at the Joomla! Security Center. |
| [20100423] – Core – Negative Values for Limit and Offset
Posted: 23 Apr 2010 10:31 AM PDT § Project: Joomla! § SubProject: All § Severity: Moderate § Versions: 1.5.15 and all previous 1.5 releases § Exploit type: information Disclosure § Reported Date: 2010-Feb-21 § Fixed Date: 2010-Apr-23 DescriptionIf a user entered a URL with a negative query limit or offset, a PHP notice would display revealing information about the system. Affected InstallsAll 1.5.x installs prior to and including 1.5.15 are affected. SolutionUpgrade to the latest Joomla! version (1.5.16 or later) Reported by Security List ContactThe JSST at the Joomla! Security Center. |
| [20100423] – Core – Installer Migration Script
Posted: 23 Apr 2010 10:27 AM PDT § Project: Joomla! § SubProject: All § Severity: Low § Versions: 1.5.15 and all previous 1.5 releases § Exploit type: Code upload § Reported Date: 2009-Dec-30 § Fixed Date: 2010-Apr-23 DescriptionThe migration script in the Joomla! installer does not check the file type being uploaded. If the installation application is present, an attacker could use it to upload malicious files to a server. Affected InstallsAll 1.5.x installs prior to and including 1.5.15 are affected. SolutionUpgrade to the latest Joomla! version (1.5.16 or later) Reported by Nicola Bettini ContactThe JSST at the Joomla! Security Center. |
How to Fix Dreamweaver ASP.NET htm Error – Translators Not Loading
Are you getting a Dreamweaver error telling you translators are not loading? Asp.net, htm, error message jargon got you down?
Relax, there’s a (really simple) fix!
We use a few different HTML editors here at LAWolfe including the two biggies Frontpage and Dreamweaver. Recently, one of our older versions of Dreamweaver (Dreamweaver 3 in the Adobe Create Suite 3 Design Premium bundle, to be exact) began rendering Javascript errors. It went something like this: Try to load Dreamweaver, or a file in Dreamweaver, or save a file (basically do anything) and get error message:
- Translators not loading.
- Click OK (as in who cares, just work, darn-it)
- Yell at computer when error does a lather, rinse, repeat with every attempt to do anything in DW.
- Ask if IT guy is back from lunch yet.
What is this confounded Dreamweaver 3 error about Translators, asp and htm (oh, my!) you ask?
Error Explanation For Techies: Something blah blah translators not loading, asp htm error, blah, blah… (we figure you already understand the error and just came here looking for the solution.)
For Laypeople: Dreamweaver is not working. U mad.
You Can Fix This Without an IT Guy of Your Own
I put our newest IT guy, fresh out of college and in-the-know to the task. He did all the right things – repair, deinstall, reinstall – checked forums and found other IT guys talking about the exact same problem. Tried other solutions offered by other people. Nothing was working – including my IT guy who spent a couple hours trying to resolve the problem.
Now, I am not CompTIA certified. I could not network anything that involved cables. I have never held an iPad in my hands nor long to, and have never had lengthy discussions about the ethics of hackintosh. I am “old” school and in some ways, still think “old school.” But in this case, that was exactly all that was needed: Someone who knew enough to recognize that there was a problem, but not enough to over think the solution.
When I found the Dreamweaver blah blah translator blah blah asp.net htm error was still appearing this morning I did what someone who is not certified in IT stuff would do: I went to the Dreamweaver site and searched for patches. Not only did I find one addressing my exact problem, I clicked “download” all by myself and fixed the problem in less than a minute. (My IT guy will be so impressed!)
The moral here is simple: sometimes to solve a problem you have to look outside the box. But sometimes, the solution is right there in front of you and not as complicated as one might think.
Why is that lesson important to attorneys with websites?
Trust your gut when a marketing company is trying to oversell you on services to get your website to rank. The bottom line is think simple solutions and old school first – is the site well structured? The content sound and meaningful (or boiler plate junk written for search engines)? Is the SEO up to Google’s high standards? Adding video, books, and fancy features will not get your site ranked higher.
Before looking for new marketing strategies to increase traffic – make sure Google already digs your site first. I will repeat: adding more stuff to a poorly done website will not make it a good website.
Dreamweaver 3 Patches to Fix blah blah Translator not Loading, blah blah asp.net htm errors
(In case you want to know exactly where the following info came from: Adobe’s Website.)
Dreamweaver 3
Dreamweaver 3.01 Updaters
This small updater file fixes several minor issues with Dreamweaver 3. Customers who want to take advantage of Dreamweaver extensions from the Macromedia Exchange and the Aria Objects for Dreamweaver should download this updater.
Download the Dreamweaver 3.01 Updater for Windows (1.1 MB)
Download the Dreamweaver 3.01 Updater for Macintosh (6.5 MB)
Extension Fixes
Dreamweaver MX extension fix for .NET framework version 1.1
For Windows only, this patch fixes an issue with the rendering of built-in ASP.NET controls that arises after installing version 1.1 (or greater) of the ASP.NET Framework. The default MM.ASPNetDesignerMgr.dll file is replaced with an updated version that has been tested with Dreamweaver MX 6.1.
Download the extension patch (8 KB) for Windows. <—This one is the magic bullet if you are getting translator not loading blah blah asp,net htm error messages.
For more information, read the TechNote.
Dreamweaver MX extension fix for source code formatting issue
Dreamweaver MX 6.1 fails to format code correctly if the preference for indentation has been turned off. This extension installs a command that runs invisibly each time you start Dreamweaver. If the Dreamweaver version is 6.1 and you have disabled indentation then a special registry key is set to revert to an older version of Dreamweaver’s code reformatter. This works around the aforementioned bug.
Download the extension patch (2 KB) for Windows and Macintosh.
For more information, read the TechNote.
Related Forums Discussions with other solutions: Developer Forums – Dreamweaver Error Thread
Algorithm Change – Google Place Search Will Affect Business Owners in Local Listings
2010 has been a big year for algorithm changes made by Google. In April, there was Google Caffeine, followed immediately by Google Mayday in May. Then, another round of of algorithm changes in September Google kicked off Google Instant sending many webmasters into a panic. And now, in late October 2010, Google has launched yet another huge change in its Place Search product.
First, the way Google displays business listings has changed. In the past, business listings taken from the Google Places directory (which used to be called “Google Business”) would appear at, or very close to the top of search query results next to a small Google map. Up to seven businesses were shown when a local listing could be matched with a search query. Business owners that did not have websites could still have a business listing on Google and show up in search results.
But that has changed.
Three great places to get information about the changes are:
- Showing Up in Local Searches on Google – Google Place Search Algorithm Change
- Google Blog Post About Place Search; and
- Expand2Web – a great video explanation as well as tips on how to deal with the new changes.
Search Case Law For Free Using Google Scholar
If you need to research case law where do you turn? If you are an attorney, you probably already subscribe to an (expensive) legal database, but consumers are more likely to turn to Google’s Advanced Scholar Search.
Google’s United States Federal case law database includes:
- United States Supreme Court opinions since 1 US 1 (pre – 1776);
- Federal Appeals opinions since 1 F 2d 1 (1924+); and
- Many Federal District Court opinions from F Supp.
- Opinions from all 50 states are included since 1950.
Other perks:
- Cases are hyperlinked to other cases within each case
- Internal page numbers
- Hyperlinked citations
- List of all cases citing the observed case
