:: home
:: archive
:: donate
:: rss feed
:: about site
:: bend forums
:: bend blogs
:: sh.orty
:: welcome to bend |
|
|
|
|
UtterlyBoring.com is produced by Jake Ortman (e-mail, resume), a 30-year-old dad, percussionist, freelance Web designer, consultant and jack-of-all-trades computer geek, living in Bend, Oregon. He created this so that his expensive journalism and technology degree isn't getting totally wasted. In addition to editing this site in his free time, he is the IT Director and Ad Designer at both Sunray and Discover Sunriver. He has LinkedIn, MySpace, Facebook profiles if you're trying to stalk him.
Opinions and comments on this site are the opinions of the author, not the author's employer, family, friends or pets.
This site is powered by Movable Type and is hosted by orty.com. Internet connection provided by Bend BroadBand. Since December 1st, 2002, there have been 5112 entries. Visitors to this blog have posted 15565 comments.
If you're reading this, you have too much time on your hands. |
|
|
|
|
|
|
URGENT: Patch Your MovableType Install
Even if you're still running 2.6x, you need to get this patch installed. It fixes an ugly vulnerability that allows your MT installation to be used by spammers to send out mail (similar to a formmail script hole).
I actually noticed this about nine months ago but nobody seemed to notice or care. Glad to hear SixApart is finally listening to folks and has the right kinds of folks there to make sure this kind of crap doesn't ever happen again.
4 Comments
Dave M. said on 01/25/05 @ 11:02 AM:
I actually noticed this about nine months ago but nobody seemed to notice or care. Glad to hear SixApart is finally listening to folks and has the right kinds of folks there to make sure this kind of crap doesn't ever happen again.
Yea, it usually takes someone high up to complain before something ever gets done.
My wife's site is MT, so "a patching I will go, a patching I will go, hi go the dario, a patching I will go." :)
Jay Allen said on 01/26/05 @ 10:55 PM: "Yea, it usually takes someone high up to complain before something ever gets done."
For the record, that's totally untrue. A security flaw is a securrity flaw and as long as I'm Product Manager, I don't need God to point it out to me. :-)
"I actually noticed this about nine months ago but nobody seemed to notice or care."
I can't speak for what happened (because I was an outsider then too), but I can tell you that, most likely, they were so busy between the -- what? -- ten of them working there that your email probably got lost amongst all the others that never got read.
Sad, really, but now those days are mostly behind us. We're growing -- and in a good way. :-)
So please, if you ever find any other vulnerabilities, don't hesitate to write to contact at sixapart dot com or to me directly.
And thanks both for the compliment and for sticking with us.
Jake said on 01/27/05 @ 10:06 AM: Jay: This is why I'm sticking with MT, because of the smart and talented folks 6A is hiring (including you) that will make sure this kind of crap doesn't EVER happen again. Thanks again!
Jay Allen said on 01/27/05 @ 10:29 AM: Thanks for the vote of confidence. With every release going forward, you'll see that it's well placed. It's my job to make sure of that and, like you said, with the talent that we're adding all the time, it's hard NOT to make a great piece of software. :-)
Post a comment
|
What are you doing down here? Don't you have something better to do? Like Go Back To The Top of the page, or even see who created this site? This site is © 2001 - 2008 by the Utterly Boring folks at UtterlyBoring.com. Steal my content, as I probably did, too, just link to my site or the original site. Batteries not included. One size fits all. Not for off-road use. Not for internal use. Do not taunt Happy Fun Ball. Technorati Profile.
|
|