肥兔 发布的文章

-*- coding: utf-8 -*-
Changes with Apache 2.2.20

*) SECURITY: CVE-2011-3192 (cve.mitre.org)
core: Fix handling of byte-range requests to use less memory, to avoid
denial of service. If the sum of all ranges in a request is larger than
the original file, ignore the ranges and send the complete file.
PR 51714. [Stefan Fritsch, Jim Jagielski, Ruediger Pluem, Eric Covener]

*) mod_authnz_ldap: If the LDAP server returns constraint violation,
don't treat this as an error but as "auth denied". [Stefan Fritsch]

*) mod_filter: Fix FilterProvider conditions of type "resp=" (response
headers) for CGI. [Joe Orton, Rainer Jung]

*) mod_reqtimeout: Fix a timed out connection going into the keep-alive
state after a timeout when discarding a request body. PR 51103.
[Stefan Fritsch]

*) core: Do the hook sorting earlier so that the hooks are properly sorted
for the pre_config hook and during parsing the config. [Stefan Fritsch]

[Apache 2.1.0-dev includes those bug fixes and changes with the
Apache 2.0.xx tree as documented, and except as noted, below.]

Changes with Apache 2.0.x and later:

*) http://svn.apache.org/viewvc/httpd/httpd/branches/2.0.x/CHANGES?view=markup

 

download link http://httpd.apache.org/download.cgi

26 June 2011
IMAGEVUE 1.8.2
-----------------------------------------------------------------

1.8.2
[*] PHP5.3 Compatibility

1.8.1
[*] PHP5.3 Compatibility

1.8
[*] Fixed picture ghosting
[+] Files are being chmoded 666 after upload using admin

1.7.8
[*] Refixed passwords

1.7.7
[*] Disabled sendpic logging by default
(if you need to log all emails, check sendpic.php)
[*] Fixed password being converted to lowercase
[*] Changed short opening tags in all .php files

Download link : http://www.gokuai.com/f/U2S8BP02Jb1Y91XL

此版本为V1系列终结版,文件包含了整站程序,附带了部分文件源代码,允许二次开发,程序不需要授权,如果没有必要,请使用X2系列。

兔兔严重鄙视那些看文章不回复又想下载的人,再次提醒,需要下载请自觉回复。

  港交所网站被黑事件尚未平息,一个影响更为广泛的DedeCMS系统高危漏洞又被黑客捅了出来。公开数据显示,使用DedeCMS系统的国内互联网站接近40万家,覆盖企业、教育机构、数字传媒等各个领域。截至发稿前,DedeCMS仍未发布官方补丁修复漏洞,为此360网站安全检测平台(webscan.360.cn)已紧急提供了临时解决方案,提醒广大网站站长尽快参考方案修复漏洞。

DedeCMS是国内第一个开源的网站内容管理系统,在CMS市场受到大批网站站长的欢迎。不过最近有技术论坛发现,该系统的全局变量初始化存在漏洞,可能导致黑客利用漏洞侵入使用DedeCMS的网站服务器,造成网站用户数据泄露、页面被恶意篡改等严重后果。

据此前360安全中心发布的《互联网安全报告》显示:今年以来,黑客攻击网站服务器,窃取用户数据造成的危害已经超过盗号木马。很多网民即便电脑没有中木马,账号和密码也会由于网站漏洞而被黑客窃取。因此,DedeCMS漏洞不仅关系着数十万家网站的服务器安全,对网民的切身利益也造成了间接影响。

360网站安全检测平台提醒广大站长,该平台已经第一时间支持DedeCMS最新漏洞的检测,使用DedeCMS开发的网站站长可登录webscan.360.cn免费检测。一旦发现网站存在漏洞,在DedeCMS官方补丁发布之前,应尽快按照如下应急方案进行处理(以DedeCMS 5.6为例):

在DedeCMS系统的/include/common.inc.php中,找到注册变量的代码:

  foreach(Array('_GET','_POST','_COOKIE') as $_request)
  {
  foreach($$_request as $_k => $_v) ${$_k} = _RunMagicQuotes($_v);
  }

将其修改为:

  foreach(Array('_GET','_POST','_COOKIE') as $_request)
  {
  foreach($$_request as $_k => $_v) {
  if( strlen($_k)>0 && eregi('^(cfg_|GLOBALS)',$_k) ){
  exit('Request var not allow!');
  }
  ${$_k} = _RunMagicQuotes($_v);
  }
  }

Fixed Filemod bug
Added Google Analytics folder/files tracking
Fixed thumbnails with “globalpath” when loading from non-default gallery location.
When you open flash galllery custom language is reset to default one
After moving/copying files you stay in the current folder
Fixed an issue with minus sign in menu [icon.png]
Fixed missing messages in CSS editor in Imagevue
Better expanding textareas in Config editor
Stripped [icon] from page title in admin
Wider inputs in config editor
Trial expires not that quick now
Ctrl-A/Cmd-A Selection of files in admin doesn’t block selections in textfields
Fix for #/links replacement for HTML gallery
Clean theme delete
Orphaned thumbnail remover
Changed frontend HTML
Better handling of paths with non-latin characters (Not recommended)

Download link : http://www.gokuai.com/f/V0D74R50iN57A798

兔兔严重鄙视那些看文章不回复又想下载的人,再次提醒,需要下载请自觉回复。

QQ 2011全新体验 加强安全防护机制,QQ使用更安全.
内置QQ安全防护模块,可有效防护盗号木马侵扰,保障QQ使用安全!
有效拦截恶意程序注入,避免QQ异常.

针对恶意程序试图注入QQ进行拦截并弹出提示,同时允许选择不再弹窗提醒,当选择不再提醒后,QQ主界面底部的安全逻辑会生效,再有恶意注入时进行闪烁提醒。
可疑程序注入提醒,方便用户自由选择
针对可疑程序试图注入QQ进行提醒,方便用户自由选择;并且所做的选择可以在安全沟通页面进行一键恢复到默认值。
支持一键打开安全防护页面,查看详细记录
支持通过QQ主界面底部安全菜单进入安全防护页面,查看注入的历史记录;针对是否弹出提示的设置,支持一键恢复默认为初始设置。优化了QQ安全检查逻辑,降低QQ被破坏的风险。

下载地址:http://dl_dir.qq.com/qqfile/qq/QQ2011/QQ2011Beta3(QQProtect1.0).exe