<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Wikka Developer Blog</title>
	
	<link>http://blog.wikkawiki.org</link>
	<description>Fresh news from the Wikka Developer Team</description>
	<lastBuildDate>Thu, 11 Apr 2013 05:27:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/WikkaDeveloperBlog" /><feedburner:info uri="wikkadeveloperblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>WikkaWiki is alive and well!</title>
		<link>http://feedproxy.google.com/~r/WikkaDeveloperBlog/~3/0lzrT_iMDPg/</link>
		<comments>http://blog.wikkawiki.org/2013/04/11/wikkawiki-is-alive-and-well/#comments</comments>
		<pubDate>Thu, 11 Apr 2013 05:27:03 +0000</pubDate>
		<dc:creator>Brian</dc:creator>
				<category><![CDATA[Announcements]]></category>

		<guid isPermaLink="false">http://blog.wikkawiki.org/?p=214</guid>
		<description><![CDATA[I wanted to apologize to those who have discovered several of our sites, including the main site and docs site, have been down the past few days. Our hosting provider of 6+ years unexpectedly and without justification pulled the plug on us, so we are scrambling to migrate everything to a new hosting provider. Please [...]]]></description>
			<content:encoded><![CDATA[<p>I wanted to apologize to those who have discovered several of our sites, including the main site and docs site, have been down the past few days.  Our hosting provider of 6+ years unexpectedly and without justification pulled the plug on us, so we are scrambling to migrate everything to a new hosting provider.  Please be assured WikkaWiki is alive and well, and we have no plans of closing shop.  We appreciate each and every one of you who use WikkaWiki to make your lives easier or more fun, and hope you&#8217;ll stick with us during this transition.  As always, your comments are appreciated!</p>
<img src="http://feeds.feedburner.com/~r/WikkaDeveloperBlog/~4/0lzrT_iMDPg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.wikkawiki.org/2013/04/11/wikkawiki-is-alive-and-well/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.wikkawiki.org/2013/04/11/wikkawiki-is-alive-and-well/</feedburner:origLink></item>
		<item>
		<title>Wikka 1.3.4 release announcement</title>
		<link>http://feedproxy.google.com/~r/WikkaDeveloperBlog/~3/x8hK_j7Q3jU/</link>
		<comments>http://blog.wikkawiki.org/2013/02/10/wikka-1-3-4-release-announcement/#comments</comments>
		<pubDate>Sun, 10 Feb 2013 18:27:58 +0000</pubDate>
		<dc:creator>Brian</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://blog.wikkawiki.org/?p=210</guid>
		<description><![CDATA[WikkaWiki 1.3.4 has been released. There is no pressing need to upgrade from 1.3.3; most changes are minor bug fixes, one enhancement (usergroup ACLs) and no security fixes. However, if you are still running a version prior to 1.2p7, you really, really need to upgrade. As always, comments are appreciated!]]></description>
			<content:encoded><![CDATA[<p><a href="http://docs.wikkawiki.org/WhatsNew134">WikkaWiki 1.3.4</a> has been released.  There is no pressing need to upgrade from 1.3.3; most changes are minor bug fixes, one enhancement (usergroup ACLs) and no security fixes.  However, if you are still running a version prior to 1.2p7, <strong>you <em>really, really</em> need to upgrade</strong>.  As always, comments are appreciated!</p>
<img src="http://feeds.feedburner.com/~r/WikkaDeveloperBlog/~4/x8hK_j7Q3jU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.wikkawiki.org/2013/02/10/wikka-1-3-4-release-announcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.wikkawiki.org/2013/02/10/wikka-1-3-4-release-announcement/</feedburner:origLink></item>
		<item>
		<title>Wikka 1.3.3 released</title>
		<link>http://feedproxy.google.com/~r/WikkaDeveloperBlog/~3/CpSEEl1waek/</link>
		<comments>http://blog.wikkawiki.org/2013/02/03/wikka-1-3-3-released/#comments</comments>
		<pubDate>Sun, 03 Feb 2013 23:49:45 +0000</pubDate>
		<dc:creator>Brian</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://blog.wikkawiki.org/?p=204</guid>
		<description><![CDATA[Apparently I was remiss in announcing the release of 1.3.3; I apologize for the oversight. You can download the latest version here. This is considered a minor upgrade, so 1.3.2 users really have no compelling need to upgrade. However, if you are running any version prior to 1.3.2p7, please be aware that there are some [...]]]></description>
			<content:encoded><![CDATA[<p>Apparently I was remiss in announcing the release of 1.3.3; I apologize for the oversight.  You can download the latest version <a href="http://docs.wikkawiki.org/WhatsNew133">here</a>.  This is considered a minor upgrade, so 1.3.2 users really have no compelling need to upgrade.  However, if you are running any version prior to 1.3.2p7, please be aware that there are some <a href="http://blog.wikkawiki.org/2011/12/04/security-updates-for-1-3-11-3-2/">serious security issues</a> with these versions that can permit hackers to access your database and change/destroy data, <strong>so upgrading to 1.3.3 from any version prior to 1.2p7 is imperative!</strong></p>
<p>As always, your comments and suggestions are always welcome!</p>
<img src="http://feeds.feedburner.com/~r/WikkaDeveloperBlog/~4/CpSEEl1waek" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.wikkawiki.org/2013/02/03/wikka-1-3-3-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blog.wikkawiki.org/2013/02/03/wikka-1-3-3-released/</feedburner:origLink></item>
		<item>
		<title>Security updates for 1.3.1/1.3.2</title>
		<link>http://feedproxy.google.com/~r/WikkaDeveloperBlog/~3/4Ne8zjid0Nc/</link>
		<comments>http://blog.wikkawiki.org/2011/12/04/security-updates-for-1-3-11-3-2/#comments</comments>
		<pubDate>Sun, 04 Dec 2011 18:18:44 +0000</pubDate>
		<dc:creator>Brian</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://blog.wikkawiki.org/?p=194</guid>
		<description><![CDATA[On 30Nov an individual posted several WikkaWiki exploits that affect 1.3.1 and 1.3.2 (and possibly earlier versions). All users should immediately upgrade to 1.3.2-p7 or later. You can download the updates from the WikkaWiki homepage. Simply make a backup of your existing Wikka install, and unzip or untar the update directly over your existing installation. [...]]]></description>
			<content:encoded><![CDATA[<p>On 30Nov an individual posted <a href="http://packetstormsecurity.org/files/107405">several WikkaWiki exploits</a> that affect 1.3.1 and 1.3.2 (and possibly earlier versions).  <strong>All users should immediately upgrade to 1.3.2-p7</strong> or later.  You can download the updates from the <a href="http://wikkawiki.org/HomePage">WikkaWiki homepage</a>.  Simply make a backup of your existing Wikka install, and unzip or untar the update directly over your existing installation.  There are no other changes required.</p>
<p>For those looking for more details, please read on&#8230;</p>
<p><span id="more-194"></span></p>
<p>I&#8217;ll address each exploit and whether or not it might affect your WikkaWiki site.  You can choose to apply the patches you wish, or you can simply download the entire update and install over your existing installation.</p>
<p><em>SQL Injection in UPDATE statement (CVE-2011-4448)</em><br />
This one basically permits a user to carefully modify a UserSettings page, send it back to your server, and extract various fields from your DB or, under some conditions and depending upon which version of MySQL you are using, execute arbitrary SQL statements.  If you do not use the UserSettings action (for instance, you have a wiki closed to registrations), then this vulnerability does not apply to you.  You can find the patch <a href="https://wush.net/trac/wikka/changeset/1820">here</a>.</p>
<p><em>Unrestricted File Upload (CVE-2011-4449)</em><br />
This vulnerability is actually an <a href="http://httpd.apache.org/docs/2.2/mod/mod_mime.html#multipleext">Apache configuration issue</a> and how Apache handles files with multiple extensions, and not a Wikka issue.  A properly configured Apache instance should not be vulnerable.  To be on the safe side, I simply chose to disable all uploads of files with multiple extensions.  You must have INTRANET_MODE  or file uploading enabled for this vulnerability to have any effect.  If you do not use the files action, then this patch does not apply to you.  You can find the patch <a href="https://wush.net/trac/wikka/changeset/1822">here</a>.</p>
<p><em>Arbitrary File Download and Arbitrary File Deletion (CVE-2011-4450)</em><br />
As with the previous vulnerability, this one will affect you only if you are using the files action.  If so, then it is possible to display the contents of any file in your Wikka installation directory, including wikka.config.php.  It <em>might</em> be possible to delete arbitrary files as well, but this is dependent upon somehow gaining access as an administrator.  You can find the patch <a href="https://wush.net/trac/wikka/changeset/1821">here</a>.</p>
<p><em>Remote Code Execution (CVE-2011-4451)</em><br />
Successful execution of this vulnerability requires a very limited set of circumstances:  (1) Rewrite mode must be disabled, (2) spam logging must be enabled.  When both of these instances are true, it is possible to inject arbitrary PHP code into the spamlog, which is then executed by the Apache server upon access.  If you have spam logging disabled, OR rewrite mode enabled, this one does not apply to you.  You can find the patch <a href="https://wush.net/trac/wikka/changeset/1825">here</a>.</p>
<p><em>Cross-Site Request Forgery (CVE-2011-4452)</em><br />
This vulnerability affects any site which uses the AdminUsers action: It is possible, with carefully crafted Wikka markup, to arbitrarily delete a user (other than the admin).  You can find the patch <a href="https://wush.net/trac/wikka/changeset/1819">here</a>.</p>
<p>As always, the Wikka development team is committed to making WikkaWiki as secure as feasible, and we always welcome your input and bug reports.</p>
<img src="http://feeds.feedburner.com/~r/WikkaDeveloperBlog/~4/4Ne8zjid0Nc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://blog.wikkawiki.org/2011/12/04/security-updates-for-1-3-11-3-2/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		<feedburner:origLink>http://blog.wikkawiki.org/2011/12/04/security-updates-for-1-3-11-3-2/</feedburner:origLink></item>
	</channel>
</rss>
