肥兔 发布的文章

Wordpress 是全球最棒的免费个人内容(Blog)发布平台之一,它用经典的PHP+MySQL搭建而成,简单的说,Wordpress是一个BLOG程序,用它你可以架设完全属于你自己的BLOG。而Wordpress现在的应用又不仅仅只是在BLOG方面,因为其强大的扩展性,部分网站甚至已经开始使用Wordpress来架设,或者说这些BLOG你甚至都看不出它们只是BLOG而已了。

更新内容如下:
加强媒体文件上传的安全性
性能改进
增加对 IIS6 的支持
修正分类和 PATHINFO(/index.php/)的固定链接问题
修正了在某些极端情况下,数据库查询和分类法相关内容可能导致插件不兼容的问题

View: 官方网站|中文网站
Screenshot: 界面预览
Download: WordPress v3.1.1(ZIP)
Download: WordPress v3.1.1(TAR.GZ)

 

源头在于wiki.php.net的漏洞导致wiki账号被盗,而wiki的账号和php代码源的SVN提交权限相关联。

原文:

The wiki.php.net boxwas compromised and the attackers were able to collect wiki account credentials. No other machines in the php.net infrastructure appear to have been affected. Our biggest concern is, of course, the integrity of our source code. We did an extensive code audit and looked at every commit since 5.3.5 to make sure that no stolen accounts were used to inject anything malicious. Nothing was found. The compromised machine has been wiped and we are forcing a password change for all svn accounts.
We are still investigating the details of the attack which combined a vulnerability in the Wiki software with a Linux root exploit.

- 阅读剩余部分 -

Pure-FTPd 是一个自由的(BSD) FTP 服务器. 它能够在许多的类Unix系统上编译和运行,包括 Linux, OpenBSD, NetBSD, FreeBSD, DragonFly BSD, Solaris, Tru64, Darwin, Irix and HP-UX 等.
Pure-FTPd 基于 Troll-FTPd,当前由Frank Denis 领导的团队开发维护.
pureftpd 今早紧急发布了1.0.30版本,主要就是修复了一个STARTTLS加密方面的漏洞(CVE-2011-0411),如果你的ftp正在使用TLS的话,请立即升级。

官方原文如下:

Pure-FTPd 1.0.30 has been released.
pure-quotacheck can now work with a large number of files.
OPTS UTF-8 is now an alias to OPTS UTF8.
Fix a STARTTLS flaw similar to Postfix’s CVE-2011-0411. If you’re using TLS, upgrading is recommended.

下载源码:
http://download.pureftpd.org/pure-ftpd/releases/pure-ftpd-1.0.30.tar.bz2
MD5 (pure-ftpd-1.0.30.tar.bz2) = 865a9020dbe48d30913c796ac3ec1f32
http://download.pureftpd.org/pub/pure-ftpd/releases/pure-ftpd-1.0.30.tar.gz
MD5 (pure-ftpd-1.0.30.tar.gz) = 29e2a68e756d09f4aff8f4f76435b020