e107, we'd say the wife likes it, but we'd be lying
Welcome
Username:

Password:


Remember me

[ ]
[ ]
[ ]
e107 Project Tracker
e107 on IRC
freenode.net
For real-time help and friendly chat please join #e107 on the Freenode Network

It's a friendly channel so please drop in and say hello regardless of your e107 or IRC experience

If you're new to IRC please click [here] for an explanantion of what to do.

Web Hosting

Security and Bug Fixes Release 0.7.2

Heres your chance to grab the latest bug fixes currently in the cvs with this new release. 0.7.2 includes a major security update addressing potential xss exploits in the bbcodes system so you should download and install this update immediately. You will notice theres a couple of new features amidst the fixes in the full changelog which can be found here: click to open link in new window

Once again, If you are upgrading from 0.7.0 or 0.7.1, make sure to grab the relevant package and its simply a case of uploading the new files over the existing files on your server. If you are upgrading from 0.6175 however you must read the upgrade guide and please also read the official 0.7 release news item here.

Links to the downloads can be found on this page

Please click here for the 0.6175 to 0.7 upgrade guide.

posted by Jim Currie on Friday 10 February 2006 - 12:36:30


Comments

[SpooK] on 10 Feb : 12:40 Member Of The e107 Support Team

Fantastic! Once again, great work guys
[ edited 10 Feb : 14:45 ]

Genbushi on 10 Feb : 13:24

Thanks!!

whoisrich on 10 Feb : 13:25 Member Of The e107 Support Team

Nice Job

nsno on 10 Feb : 14:51

thanks for this

the hide code works a treat!

whoisrich on 10 Feb : 17:55 Member Of The e107 Support Team

This is a really good version, so have now upgraded my site from 0.617 to 0.7.2

streaky on 11 Feb : 05:59

Oh, BTW, the perms should be fine for linux - i checked and re-checked and they are fine

Took forever
[ edited 11 Feb : 05:59 ]

skinnali on 11 Feb : 12:24

Getting this message in the admin panel. any suggestion?
Parse error: parse error, unexpected '}' in /home/hskinn13/public_html/e107_handlers/shortcode_handler.php(128) : eval()'d code on line 40

aomtealfox on 11 Feb : 12:30

Make that two.

I think there's something fishy in that particular file!

maaijre1 on 11 Feb : 14:20

after the upgrade to 0.7.2 is our stats log verrrrrrrrry slow.
It takes for 2 minutes to load the webpage.

stormofdragons on 12 Feb : 07:58

Yeah, somethings going on guys, I've got half my site down with "Fatal error: Maximum execution time of 30 seconds exceeded in sitename/e107_plugins/log/logs/logi_41.2006.php on line 102" and like errors.

I'm rolling BACK to .7.1 to fix it, hopefully.

stinkomatic on 12 Feb : 16:02

Yay, fix three bugs, introduce 200 more. While I understand and am very appreciative of you wonderful guys giving your free time to make a kickass free cms, this bug has cost me about 6 hours in various site fkups.
Im not wanting to blame anyone or get in a cheesfight, but maybe some more rigourous quality testing before releasing the next 'update'.

Advised to ALL, until this is fixed, do not update 7.1 to 7.2

streaky on 12 Feb : 17:59

Hey yeah, next time we'll sit on security updates for 3 months so they get 'tested' a la microsoft.. or maybe you could use a system that doesn't patch such issues like.. I dunno.. Joomla?

Not being pervasive here, but seriously, 4 people does not constitute a major problem, sorry.

stinkomatic on 12 Feb : 20:33

Okayyy.. maybe I should have said :

It is advised to upgrade to this new 0.7.2 version using the 0.7.1 upgrade script at your own risk. People have had major problems. Use at your own discretion. But I guess we all already knew that, right ?

Penbrock on 12 Feb : 20:41

My Stats loads fine, but I lost the fill color on the bars is all.

DvilleStoner on 12 Feb : 22:40

man, i lost 2 subforums, including threads due to this upgrade. . .

Youpi on 13 Feb : 02:27

yes there are some problems with this upgrade, perhaps it maybe more interesting to install a full version and not an upgrade from 7.1 to 7.2

dpuett on 13 Feb : 03:11

I couldn't do a clean install with .7.2. Kept getting errors. Eventually, I did a clean install using v7 build 1. I'll try another clean install of .7.2 in the next couple of days and post the error messages.

DvilleStoner on 13 Feb : 04:05

i wouldn't have cared if it didn't say 'security fix - upgrade now'. maybe next time they'll release 'bug-fixes' and security fixes SEPERATELY

Johan Söderström on 13 Feb : 04:36

DvilleStoner: Read the anouncement before complaining... you are not making sence...

skinnali on 13 Feb : 05:15

Well, I did read the anouncements and nothing was mentioned about the bug I found although I did exactly what was said, step by step......But no worries, I've just had it with e107... back to Xoops

judy323 on 13 Feb : 05:32 Member Of The e107 Support Team

? upgrade to 0.7.2 works like a charme- 3 sites updated

AndyDev on 13 Feb : 06:27 Member Of The e107 Support Team

Works fine for me! Thanks Guys... People with problems Either go back to 0.7.1 or Just wait for 0.7.3

skinnali on 13 Feb : 06:38

Good solution

JimboJ on 13 Feb : 08:02

my site has slowed down big time also...

VR6Pete on 13 Feb : 12:47

0.7.2 killed my site im afraid!

fox on 13 Feb : 16:00

anyone have an idea, why there is a long time before returning output to browser?

Render time: 63.5008 second(s); 0.0625 of that for queries.

I am sure, the server is ok. Other projects hosted there are working without problems.

In the README included in upgrade should be more information about the security fix - I mean - what was the problem and some description... just to be able to check the site if somebody did not use the security issue to do something bad......

thanks


[ edited 13 Feb : 16:44 ]

VR6Pete on 13 Feb : 16:02

If you have logging enabled, try to disable it, my website has been loading 50mb + files into memory and having a knock on effect!

Pete

fox on 13 Feb : 16:22

do you mean the stats logging? I already switched it off, but still the same problem. The problem first came today few hours ago, before the upgrade to .7.2 (so it was on .7.1) and I didn't makae any changes ;(

Oz on 13 Feb : 18:12 Member Of The e107 Support Team

the logging system messed up e107hacks.org, needed to delete a log file and restart the whole server to fix.

1. restarted server
2. logged in via ftp and deleted the bad file.

XCalPro on 13 Feb : 20:37

It seems there is an issue with the logging.. I also have been experiencing problems with the log. Since installing 7.1 to 7.2 I have been getting SUSPENDED pages from my ISP for exceeding CPU Quota and also 500 Server Error pages when trying to access the stats log.

TheMadMonk on 14 Feb : 02:57

I replaced the 0.72 patch for the log back to the 0.71 files and its stop this issue for now

Neutron on 14 Feb : 03:36

Works fine for me. I have not activated the stats. Any error.

aidee on 14 Feb : 08:27

The stats logging must have some kind of error. I had a logfile of >50MB in just 8 hours, filled with 0x20. The second day it was > 30MB. It caused the website to hang until deletion of the file. I turned it off.
[ edited 14 Feb : 08:28 ]

streaky on 14 Feb : 08:55

Yeah yeah, I'm working on it, calm down..

fox on 14 Feb : 11:13

Streaky we are calmed down but a little bit anxious )) as people usually are ))

good luck to your bug investigation....

streaky on 14 Feb : 18:16

If anybody needs a stats fix and cant wait try click to open link in new window - tough you may have to delete really big files if you have them, the fix wont sort huge files out but it will stop any more becoming huge, just extract the files into your e107_plugins/log/ dir, and please point people at this if you happen to see a forum thread with people having issues, thanks

AndyDev on 15 Feb : 04:13 Member Of The e107 Support Team

I got this after 2 days of the update working fine...

Fatal error: Maximum execution time of 30 seconds exceeded in ----e107_plugins\log\logs\logi_44.2006.php on line 5

fox on 15 Feb : 05:22

acynet.com -- read previous comments, especially focus on streakys' notes....;-)

Jim Currie on 15 Feb : 08:20

as you see streaky sorted out the stats problem and you can download it from the link he pasted above. we want to release 0.7.3 asap with this fix - the only thing preventing that right now is that we want to fix the parse error some people are getting. None of the devs get this error and the error message doesnt tell us enough about what that the error is. If someone who is having this problem could please give me complete access to their server I could most likely track down whats wrong. I will need ftp access and admin access to e107 - database access is probably not needeed in this case but if possible to sort that out too it might prove useful. Please send the details to click to send email . we're all sorry that some people had problems with this update. we try our best. thanks.

streaky on 15 Feb : 08:21

It'd be nice if people could confirm if the fix works

stinkomatic on 15 Feb : 09:06

Nah, Ive gone back to 0.7.1 and wont go up till next version prolly.. I dont use RSS anyway.

You guys didnt make the BF2 1.2 patch as well did you ?

Jim Currie on 15 Feb : 09:11

stinkomatic : heres an idea - rather than say youve introduced shitloads of bugs and stomp your feet about and criticise why not help everyone by reporting what those bugs are in the bugtracker and helping us fix them for everybody else?

2dopey on 15 Feb : 11:16

streaky - I've uploaded the patch and re-enabled stat logging on 2 sites and so far things seem to be OK - will let you know if it's not

streaky on 15 Feb : 13:26

Cool, thanks

Make sure you keep and eye on it though, just in case
[ edited 15 Feb : 13:27 ]

w1n78 on 15 Feb : 14:41

i still get those backslashes when i use apostrophes and quotes

i'll be patient. can't complain much when it's free and we have great devs. i am glad about the rss fix :clap:

thanks devs, keep up the good work, it's much appreciated

pss0ft on 15 Feb : 15:17

Hi,

Had the same problems with logfiles becoming very huge. My ISP complained about it. I had a logfile in a few hours of 50Mb. We submitted it into the bugtracker and before that we discussed it in the forum.

I applied the patch. We will see what it does. I will keep the communtiy informed.

Grtz. Henk [pss0ft]

2dopey on 15 Feb : 16:50

streaky I found that click to open link in new window was running very slow tonight (22.30 GMT) with the following: Render time: 60.2086 second(s); 58.2479 of that for queries.

That's with stat logging enabled and all the latest CVS files and no large stat logs when I updated

It might just be a coincidence with a server problem but it's on Hostingplex and has been OK in the past so will look again in the morning and post back if no change

2dopey on 16 Feb : 02:48

Streaky - I can confirm it was a server issue as everything is fine this morning (I thought it was as 2 sites are on the same server)

The revised log files you released have been up for over 12 hours now and the largest log file created is 1k so far

Florian on 16 Feb : 09:42

.


[ edited 20 Feb : 13:38 ]

shit4brains on 16 Feb : 11:05

I've been using the patch now since it was released and my logs are stable, largest is 5K. However, even though I've enabled stat logging via admin I get a "stat logging is disabled" msg in my Online 4 menu andd when I click to activate it I get an error msg for "/e107_admin/log.php" which is weird as it should point to "/e107_plugins/log/logs/" shouldn't it.
Anyway, at least the log files aren't massive and my sites up

2dopey on 16 Feb : 11:38

That's a wrong link in onlineinfo4 Andy which you will need to manually correct

buddhu on 16 Feb : 14:29

Thanks for the updates, guys.

Sheesh, I remember the old days when e107 users weren't a bunch of ungrateful w*nkers.

Streaky's right: microsoft gets a lot of you losers to pay through the nose to beta test their bloated heap of crap. e107 is given to you for free. Fine, point out bugs, but show a little class in the way you do it.

e107 rox. Always did, always will.

djw2 on 17 Feb : 09:34

Yeah, Buddhu’s right.

Never mind that you downloaded an official patch that crashed your website. It’s just a stupid website, not like it’s important or anything.

Never mind that there are millions of websites just like yours, all competing for the same audience on a daily basis. I’m sure your users will happily wait for Streaky to get around to fixing it. Just explain the problem to them; I’m sure they’ll understand.

Never mind that you’ve collected money from advertisers who are expecting to see their ads prominently displayed on your website.

Seriously, I remember the old days when Microsoft was laughable precisely because they were so far below the standard. Hell, now that Microsoft has become the standard, we don’t need to worry about any of this shit anymore.

Programmers used to actually sit around and freakin test their stuff before it was released. OMG! Can you even imagine how much time that wasted?

~ Back to Reality ~

If your operational standard is Microsoft you seriously need to raise your bar.

Listen, I fully realize that the dev team is here voluntarily, but so are the users. Microsoft has one MAJOR advantage over a team like e107; it’s called limited competition. There are dozens of content management systems out there and the market share for each and every one directly correlates to quality of product and support. You see, every computer in the world is sold with Microsoft’s operating system on it, people will use it simply by default, whether Microsoft supports it or not. e107 does not have this cushion.

Developers may in fact choose to be here, but again so do the users. So, if the developers choose to release corrupted updates, and untested scripts… than perhaps the users will choose to go somewhere else. At which point I have to ask… what’s the point. By then, I suppose you could just post on the website that users should go ahead and use somebody else’s script because we don’t give a fuck. That will work wonders.

Peace

Jim Currie on 17 Feb : 10:48

in repsonse specifically to djw2: there are two bugs that i think are what everyone is talking about. The stats bug and the parse error.

the stats bug didnt occur for the dev team.
the parse error doesnt occur for the dev team and we still as of yet dont know what causes it.

on this basis i dont know how you think we should allow for bugs that for us dont exist?

2dopey on 17 Feb : 11:01

And the stats bug has already been addressed and appears to be working fine - the largest file created since applying the fix is 5K

I don't get the parse error and nor do I assume do a lot of other people so as it's not happening to everyone how can the dev team be expected to track it down?

judy323 on 17 Feb : 11:18 Member Of The e107 Support Team

I just want to submit, that streakys log fix seams to fix the probs from my users. I contact them all today and everythings seams to be ok. The bigsized logi files are gone for now. Will report more if there is something to report. One thing as commited in bugtracker--the search string stats arent utf8 correct and dont show german characters. I am not sure if it is new or exists before the latest fix

kermit1986 on 22 Feb : 12:13

I can't get on my site anymore because of the log error.

I uploaded those 2 new files, and I moved the big 50mb file I had to another folder (logi_51.2006.php), but now my site won't even load.



So I think that if I delete that file, my site won't load anymore....

I made a topic about it in the forum, if anyone can help me a.s.a.p. I'll be greatly thankful.

kermit1986 on 22 Feb : 12:19

phew...thankfully I had the link to my admin area cookied.

I got in and was able to turn off stat logging. Finally my site works again.

Hooray!

Leet Mentality on 23 Feb : 00:30

As far as the stats go, you can go in the stats folder from your ftp and delete the logs, thats where teh problem is, After i started gettin too many hits on my site my stats log would jam up

Shadowfire on 25 Feb : 16:05

Has the streaky log/stats fix been added to the main e107_6175 upgrade to 0.7.2 download, or is this a seperate manual fix for the time being?

streaky on 26 Feb : 13:01

It wont be added to the .7.2 packages, but will be part of .7.3

doa on 14 Apr : 10:12

Wow, this thread died.

I run a hositng company and many users are getting this error.

I think this is ridiculous to go into each account daily and delete those files.

Streaky, I went to the link you had provided for a temp fix (http://blog.streakyland.co.uk/stuff/stats_fix.zip) and link doesnt exist. I will continue to search this site for a more stable fix.

Thanks.
e107 rocks and I thank all those that put time and effort into it, but I think for critical patches- they should be released sooner. This is coming from an Engineer/Software support person myself. Hang in there.

doa on 14 Apr : 10:13

Btw- all of these sites are on v7.2

doa on 14 Apr : 10:20

I found a link in the chatbox from dopey.

click to open link in new window

Thanks. I understand I use these CVS files at my own risk. Hence why I am only using the log one.

Thanks.

2dopey on 14 Apr : 10:44

DOA All the files will be in v7.3 - (although they may still change as evelopment is continuing) I only put the risk warning in in case a change has a 'knock on' effect elsewhere that the Developer overlooked - saying that quite a few of the 'Support Team' are running CVS - including me on 3 live sites and a local test one in order to try and spot any glaring ones a.s.a.p.

doa on 14 Apr : 14:20

Glad to hear some of the DEVL team are using the latest CVS.

I may or may not give it a try. Glad the Team is around though. Myself and many other community members do as well. TY


You must be logged in to make comments on this site - please log in, or if you are not registered click here to signup




All product names mentioned herein are the trademarks of their respective owners. In addition, images, logos, pictures or other material may be trademarks or registered trademarks of their respective owners. Emote images by seb, released under the GPL licence.
e107 recommends Mozilla Firefox
Render time: 1.2562 sec, 1.0486 of that for queries. Memory Usage: 3,108kB