How to: Upgrade OpenX Ad Server

A few years ago, I published an article on this blog, describing the procedure I was using at the time for upgrading an existing OpenX installation. Over time, I’ve made small changes to this process based on experience. The article below describes how I currently do these upgrades.

[Read more...]

Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email

Move banner image storage location in OpenX Source

A new place to store all your banner image files

When you do a standard installation of OpenX Source ad server, the installation procedure will result in a situation where the banner images will be stored in a folder that’s deep down in the OpenX Source folder tree. This makes it hard to perform future upgrades or effective backups. Luckily, it’s rather simple to move the banner storage folder. In this article, I will explain how to make that change.
[Read more...]

Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email

Update about security of OpenX software

In recent weeks, many stories have been published about security issues regarding the OpenX Ad Server software. Please find below some additional information on the current situation regarding the security of the OpenX software.

The most recent and most severe issues all resulted from a security problem in a third party open source component named “Open Flash Charts 2″. This component is used in the Video Ads plugin that comes with OpenX v2.8.4 and higher. The problem has been corrected with the release of OpenX v2.8.7. Instead of performing a full upgrade, a much simpler task is to just upgrade the Video Ads plugin. If you run OpenX version 2.8.3, which doesn’t have the Video ads plugin, you will not be affected by this particular issue.

There is also a smaller but still significant issue in the OpenX core software. It affects all version of the OpenX v2.8 software, up to v2.8.5 and it is relatively easy to fix. The way to do that is outlined in an OpenX forum post. Applying this patch is not complicated, but it does require some skill in editing php software files.

You can find out which version of OpenX you have by looking at the source code of any page of your OpenX system, including the login page. The version number is displayed in line 4 of that source code.

To summarize the above:

  • if you run OpenX v2.8.2 or older, an upgrade to version 2.8.3 would be recommended, including a patch for the security issue that was discovered in August.
  • if you run OpenX v2.8.3, applying the security patch that was published in August should be sufficient.
  • if you run OpenX v2.8.4 or higher, it would be smart to upgrade the Video Ads plugin, and apply the patch for the security issue, or to upgrade to OpenX v2.8.7.
Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email

OpenX Ad Server v2.8.7 released

OpenX Ad Server v2.8.7 released for download

A new version of the OpenX Ad Server software has been released. This version 2.8.7 fixes a very serious security issue. According to the announcement on the OpenX blog:

there is a vulnerability in the 2.8 downloadable version of OpenX that can result in a server running the downloaded version of OpenX being compromised.

The issue stems from the Video Ads plugin for OpenX, which in turn uses an open source third party component called Open Flash Charts (OFC) to display graphs about video ad performance. There was a security issue with OFC which has now been fixed.

In addition, the upgrade notification inside the OpenX management pages has this information:

If you recently upgraded to version 2.8.6, you can simply install an upgraded video ad plug-in available [here] or remove the following file: admin/plugins/videoReport/lib/ofc2/ofc_upload_image.php from your installation.

This is the second update in less than 1 week, which might sound alarming. On the other hand, there will always be bugs and security vulnerabilities in software, and it’s better to have those fixed.

Besides this fix for the security issue that was uncovered, there is also a seemingly small functional change in this new version:

For users in the UK, all market interfaces now reflect your participation in Orange Ad Market, and all Orange Ad Market market monetary values are in GBP.

Since both the OpenX main website and the OpenX blog appear to be down at the time I’m writing this, I can’t give you any more information than what I included above.

What does still seem to work at the moment is the download link at http://download.openx.org/openx-2.8.7.zip.

Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email

OpenX Statistics as Graphs plugin updated (v1.0.3)

The team at AdserverPlugins.com is releasing an update of the free Statistics as Graphs plugin for the OpenX Ad Server. This version 1.0.3 is available for download right now.

This is a security fix release that takes care of one issue:

  • A vulnerability has been discovered in the third-party open source graphing component Open Flash Charts that is used by this plugin to draw the graphs.

As always with security fix releases, it is crucial to upgrade to the newest version as soon as possible.

Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email

OpenX Ad Server v2.8.6 released (or not?)

Note: this is a cross-post from my contribution at OpenXtips.com yesterday.

OpenX Ad Server v2.8.6 released for download

OpenX Ad Server v2.8.6 released for download

Just like in March 2010, a new version of the OpenX software has been released recently, but not a single byte of publicity has been devoted to it. No mention on the OpenX blog or on Twitter, nothing. Judging from the dates on the files in the download archive, the new release was completed on September 2nd of 2010, so almost a week ago.

This new version 2.8.6 seems to be mostly about the security issue that was found and fixed a few weeks ago. Back then, on August 12, a somewhat cryptic announcement was posted on the OpenX forums, informing people how to fix the security problem. That post also hinted at a new release that would be out soon.

The release notes file in the 2.8.6 archive points to the OpenX Developer site for more details, but the issue tracker for version 2.8.6 is still open and most issues in it are still marked as unresolved. And the version check inside the OpenX software doesn’t give any notifications about upgrade availability.

Altogether, this is a pretty strange situation. Obviously, it’s smart to upgrade to a new version as soon as it’s released, especially if the upgrade is about fixing security issues. On the other hand, what should we think about a release that is not announced in any way, shape or form?

Download the OpenX Community edition v2.8.6.

Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email

OpenX Master Class: October 7, 2010 in Amsterdam (Netherlands)

OpenX Master Class: October 7, 2010 in Amsterdam (Netherlands)

OpenX Master Class: October 7, 2010 in Amsterdam (Netherlands)

On Thursday October 7, 2010, I’m hosting an OpenX Master Class in Amsterdam, The Netherlands. During this unique event, a small group of experienced OpenX users will gather to discuss advanced features and use cases of the OpenX Ad Server software. As an OpenX consultant with over 7 years of experience supporting OpenX users from around the world, I will be facilitating this event to make sure it will be an intense training course and a memorable experience.

Read more and sign up for the OpenX Master Class.

Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email

OpenX Master Class: October 7, 2010 in Amsterdam (Netherlands)

OpenX Master Class: October 7, 2010 in Amsterdam (Netherlands)

OpenX Master Class: October 7, 2010 in Amsterdam (Netherlands)

On Thursday October 7, 2010, I’m hosting an OpenX Master Class in Amsterdam, The Netherlands. During this unique event, a small group of experienced OpenX users will gather to discuss advanced features and use cases of the OpenX Ad Server software. As an OpenX consultant with over 7 years of experience supporting OpenX users from around the world, I will be facilitating this event to make sure it will be an intense training course and a memorable experience.

Read more and sign up for the OpenX Master Class.

Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email

OpenX Statistics as Graphs plugin updated (v1.0.2)

OpenX Statistics as Graphs plugin

OpenX Statistics as Graphs plugin

The team at AdserverPlugins.com have released an update of the free Statistics as Graphs plugin for the OpenX Ad Server. This version 1.0.2 is available for download right now.

They’re also reporting that this plugin has been downloaded over 1,000 times to date.

Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email

New version of OpenX Reference Guide

I have updated the OpenX Reference Guide that I created a few years ago. It’s completely up to date again, so that it matches the current release of the OpenX Ad Server software.

This 32 page guide provides a comprehensive description of the OpenX Ad Server, an explanation of all important concepts and terminology, and a detailed description of the process of creating advertisers, campaigns, banners, websites and zones. Next there is a section on more advanced subjects, including the algorithm for the calculation of ‘probabilities’ and targeting of banners.

download Download: OpenX Reference Guide

Version: 1.0
Updated: August 7, 2010
Size: 312.56 KB
Share this on:
  • Twitter
  • LinkedIn
  • Facebook
  • email