b2evolution b2evolution

  • Sign in
  • Sign up
  • About
  • Downloads
  • Hosting
  • Docs
  • Support
  • Sign in
  • Sign up
  • About
  • News
 
  • « b2evo 1.8.6 AND 1.9.1 released!
  • b2evolution 1.9.0-beta "Casino Royale" released »

Security Alert: import-mt.php

Posted by fplanque on Nov 30, 2006 in Security info

Well, it's been a long time since the last security alert, but every now and then someone finds a security hole and it gets exploited...

This one doesn't affect b2evolution in itself but the Movable Type Importer as shipped with b2evolution since version 1.6. So, in effect, this security issue affects all versions of b2evolution since 1.6. With the latest tests, versions 0.9.x have appeared to be safe.

The good news is that it is very easy to secure your b2evolution installation before it gets hit by an attack: just delete the Movable Type Importer (you don't need it. It is only used *during* the import if you have migrated from MT to b2evo).

In b2evo versions 1.x, delete this file from your server:
/blogs/inc/CONTROL/imports/import-mt.php

In b2evo versions 0.9.x, you don't need to do anything, you're not affected by this issue. Your version is aging though, and you should consider upgrading as soon as we release 1.8.6.

Older versions: you are not affected by this issue, however your version is so old that you may be affected by other issues. It is strongly advised to upgrade.

We'll release a fixed version of b2evo later tonight.

6 comments

Comment from: Ben borges

Ben borges

Thanks ! :)

2006-11-30 @ 15:53

Comment from: fplanque

Latest developments:

- Versions 0.9.x are NOT affected. :)

- If your PHP (php.ini) is properly configured with register_globals = Off, you are NOT affected. :)

- If your PHP (php.ini) is conservatively configured with allow_url_fopen = Off, you are NOT affected either. :)

- We will release a fixed update of 1.x (version 1.8.6) later tonight.

In the meantime, if you are unsure, please delete the import-mt.php file.

2006-11-30 @ 16:03

Comment from: fplanque

Fixed releases (1.8.6 and 1.9.1) are ready (and downloadable from SourceForge if you’re in a hurry) but we’ll double check them tomorrow.

2006-12-01 @ 02:00

Comment from: edbennett

EdB

Thanks for the super-quick corrective actions!

2006-12-01 @ 05:54

Comment from: beano

beano

Does this mean that you don’t need to delete the import-mt.php file in versions 1.9.2 onwards?

2007-02-25 @ 17:43

Comment from: fplanque

Yes versions 1.9.2 and above are perfectly safe. No need to touch mt-import in these.

2007-02-25 @ 18:19

b2evolution News

  • Home
  • Latest comments

Search

Categories

  • All
  • New releases
    • Press releases
  • Community
  • b2evolution.net
  • Development
    • New features
    • Technology
    • Security info
    • Translations
  • The Webmaster's Blog

Archives

  • July 2024 (1)
  • March 2022 (1)
  • September 2020 (1)
  • January 2020 (1)
  • May 2019 (1)
  • March 2019 (2)
  • September 2018 (1)
  • May 2018 (1)
  • September 2017 (1)
  • March 2017 (1)
  • September 2016 (1)
  • March 2016 (1)
  • More...

XML Feeds

  • RSS 2.0: Posts
  • Atom: Posts
What is RSS?

About b2evolution

  • What is it?
  • Features
  • Getting Started
  • Screenshots
  • Online demo
  • Testimonials
  • Design philosophy
  • Free & open source
  • Terms of service

Downloads

  • Latest releases
  • Skins
  • Plugins
  • Language packs

About us

  • About us
  • Contact

Webhosting Guide

  • Web hosting blog
  • Best web hosting
  • Cheap web hosting
  • Green web hosting
  • Hosting with SSH
  • VPS hosting
  • Dedicated servers
  • Reseller hosting
  • Int'l: UK / France

Docs & Support

  • Online manual
  • Forums
  • Hire a pro !

Other

  • Adsense
  • Press room
  • Privacy policy

Stay in touch

  • GitHub
  • Twitter
  • Facebook
  • LinkedIn
  • News blog
  • RSS feed
  • Atom feed

Founded & Maintained by François Planque