<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Support for OpenX Source ad server by independent OpenX Source Specialist Erik Geurts &#187; security fix</title>
	<atom:link href="http://www.openxconsultant.com/blog/tag/security-fix/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.openxconsultant.com</link>
	<description>Support, Consulting, and Training for OpenX Source ad server</description>
	<lastBuildDate>Wed, 01 Feb 2012 14:41:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>OpenX Source v2.8.8 released for download</title>
		<link>http://www.openxconsultant.com/blog/2011/11/openx-source-v2-8-8-released-for-download/</link>
		<comments>http://www.openxconsultant.com/blog/2011/11/openx-source-v2-8-8-released-for-download/#comments</comments>
		<pubDate>Sat, 05 Nov 2011 10:12:58 +0000</pubDate>
		<dc:creator>Erik Geurts</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Upgrading]]></category>
		<category><![CDATA[downloads]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[upgrade]]></category>
		<category><![CDATA[v2.8]]></category>

		<guid isPermaLink="false">http://www.openxconsultant.com/?p=1072</guid>
		<description><![CDATA[Users of OpenX Source started receiving notifications about the release of a new version of the software earlier today, when they log in as a system administrator. It is the generic message that&#8217;s always used to announce new versions, but the message says specifically: It is highly recommended to install this update as soon as [...]]]></description>
			<content:encoded><![CDATA[<p>Users of OpenX Source started receiving notifications about the release of a new version of the software earlier today, when they log in as a system administrator. It is the generic message that&#8217;s always used to announce new versions, but the message says specifically:</p>
<blockquote><p>It is highly recommended to install this update as soon as possible, because it contains a number of security fixes.</p></blockquote>
<p>There is no news about this new release on the OpenX community forums or blog, as of yet. The readme file that comes with the downloaded file does not contain any specific information as to the nature of the security issues that have been fixed. However, a quick comparison of the source code of version 2.8.7 and version 2.8.8 reveals that there are multiple changes in the API, which seems to match reports about the origins of many hacking incidents that occurred these past few months.</p>
<p>You can <a href="http://www.openx.com/publisher/open-source-ad-server" target="_blank">download OpenX Source version 2.8.8</a> from the OpenX website.</p>
<p><em>Update November 8, 2011</em>: Since many people are asking me for tips on how to upgrade their OpenX Source software, I&#8217;d like to point to an blog post I published in November, 2010: <a title="How to: Upgrade OpenX Ad Server" href="http://www.openxconsultant.com/blog/2010/11/how-to-upgrade-openx-ad-server/">How to upgrade OpenX Source Ad Server software</a>.</p>
<p><em>Update December 2nd, 2011</em>: Yesterday, a post has been added to the OpenX official company blog, officially announcing this security fix release. It also specifically mentions that the security fixes relate to issues found in OpenX Source version 2.8.7, which indicates that versions 2.8.6 and earlier are not affected. However, it is always a good idea to upgrade to the most recent version available. Read the post &#8220;<a href="http://blog.openx.org/12/security-matters-3/" target="_blank">Security matters</a>&#8221; on the OpenX blog for more information.</p>
Share this on:<a rel="nofollow" target="_blank"  href="http://twitter.com/home?status=OpenX%20Source%20v2.8.8%20released%20for%20download%20-%20http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2011%2F11%2Fopenx-source-v2-8-8-released-for-download%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/twitter.png" class="sociable-img sociable-hovers" title="Twitter" alt="Twitter" /></a><a rel="nofollow" target="_blank"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2011%2F11%2Fopenx-source-v2-8-8-released-for-download%2F&amp;title=OpenX%20Source%20v2.8.8%20released%20for%20download&amp;source=Support+for+OpenX+Source+ad+server+by+independent+OpenX+Source+Specialist+Erik+Geurts+Support%2C+Consulting%2C+and+Training+for+OpenX+Source+ad+server&amp;summary=Users%20of%20OpenX%20Source%20started%20receiving%20notifications%20about%20the%20release%20of%20a%20new%20version%20of%20the%20software%20earlier%20today%2C%20when%20they%20log%20in%20as%20a%20system%20administrator.%20It%20is%20the%20generic%20message%20that%27s%20always%20used%20to%20announce%20new%20versions%2C%20but%20the%20message" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/linkedin.png" class="sociable-img sociable-hovers" title="LinkedIn" alt="LinkedIn" /></a><a rel="nofollow" target="_blank"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2011%2F11%2Fopenx-source-v2-8-8-released-for-download%2F&amp;t=OpenX%20Source%20v2.8.8%20released%20for%20download" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/facebook.png" class="sociable-img sociable-hovers" title="Facebook" alt="Facebook" /></a><a rel="nofollow" target="_blank"  href="mailto:?subject=OpenX%20Source%20v2.8.8%20released%20for%20download&amp;body=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2011%2F11%2Fopenx-source-v2-8-8-released-for-download%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/email_link.png" class="sociable-img sociable-hovers" title="email" alt="email" /></a><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.openxconsultant.com/blog/2011/11/openx-source-v2-8-8-released-for-download/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update about security of OpenX software</title>
		<link>http://www.openxconsultant.com/blog/2010/09/update-about-security-of-openx-software/</link>
		<comments>http://www.openxconsultant.com/blog/2010/09/update-about-security-of-openx-software/#comments</comments>
		<pubDate>Wed, 22 Sep 2010 04:45:36 +0000</pubDate>
		<dc:creator>Erik Geurts</dc:creator>
				<category><![CDATA[Installation]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[OpenX plugins]]></category>
		<category><![CDATA[Upgrading]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[v2.8]]></category>

		<guid isPermaLink="false">http://www.openxconsultant.com/?p=633</guid>
		<description><![CDATA[In recent weeks, many stories have been published about security issues regarding the OpenX Ad Server software. Please find below some additional information on the current situation regarding the security of the OpenX software. The most recent and most severe issues all resulted from a security problem in a third party open source component named [...]]]></description>
			<content:encoded><![CDATA[<p>In recent weeks, many stories have been published about security issues regarding the OpenX Ad Server software. Please find below some additional information on the current situation regarding the security of the OpenX software.</p>
<p>The most recent and most severe issues all resulted from a security problem in a third party open source component named &#8220;Open Flash Charts 2&#8243;. This component is used in the Video Ads plugin that comes with OpenX v2.8.4 and higher. The problem has been corrected with the release of OpenX v2.8.7. Instead of performing a full upgrade, a much simpler task is to just upgrade the Video Ads plugin. If you run OpenX version 2.8.3, which doesn&#8217;t have the Video ads plugin, you will not be affected by this particular issue.</p>
<p>There is also a smaller but still significant issue in the OpenX core software. It affects all version of the OpenX v2.8 software, up to v2.8.5 and it is relatively easy to fix.  The way to do that is outlined in an <a href="http://forum.openx.org/index.php?showtopic=503483831" target="_blank">OpenX forum post</a>. Applying this patch is not complicated, but it does require some skill in editing php software files.</p>
<p>You can find out which version of OpenX you have by looking at the  source code of any page of your OpenX system, including the login page. The version number is displayed in line 4 of that source code.</p>
<p>To summarize the above:</p>
<ul>
<li>if you run OpenX v2.8.2 or older, an upgrade to version 2.8.3 would be recommended, including a patch for the security issue that was discovered in August.</li>
<li>if you run OpenX v2.8.3, applying the security patch that was published in August should be sufficient.</li>
<li>if you run OpenX v2.8.4 or higher, it would be smart to upgrade the Video Ads plugin, and apply the patch for the security issue, or to upgrade to OpenX v2.8.7.</li>
</ul>
Share this on:<a rel="nofollow" target="_blank"  href="http://twitter.com/home?status=Update%20about%20security%20of%20OpenX%20software%20-%20http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fupdate-about-security-of-openx-software%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/twitter.png" class="sociable-img sociable-hovers" title="Twitter" alt="Twitter" /></a><a rel="nofollow" target="_blank"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fupdate-about-security-of-openx-software%2F&amp;title=Update%20about%20security%20of%20OpenX%20software&amp;source=Support+for+OpenX+Source+ad+server+by+independent+OpenX+Source+Specialist+Erik+Geurts+Support%2C+Consulting%2C+and+Training+for+OpenX+Source+ad+server&amp;summary=In%20recent%20weeks%2C%20many%20stories%20have%20been%20published%20about%20security%20issues%20regarding%20the%20OpenX%20Ad%20Server%20software.%20Please%20find%20below%20some%20additional%20information%20on%20the%20current%20situation%20regarding%20the%20security%20of%20the%20OpenX%20software.%0D%0A%0D%0AThe%20most%20recent%20an" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/linkedin.png" class="sociable-img sociable-hovers" title="LinkedIn" alt="LinkedIn" /></a><a rel="nofollow" target="_blank"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fupdate-about-security-of-openx-software%2F&amp;t=Update%20about%20security%20of%20OpenX%20software" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/facebook.png" class="sociable-img sociable-hovers" title="Facebook" alt="Facebook" /></a><a rel="nofollow" target="_blank"  href="mailto:?subject=Update%20about%20security%20of%20OpenX%20software&amp;body=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fupdate-about-security-of-openx-software%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/email_link.png" class="sociable-img sociable-hovers" title="email" alt="email" /></a><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.openxconsultant.com/blog/2010/09/update-about-security-of-openx-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenX Ad Server v2.8.7 released</title>
		<link>http://www.openxconsultant.com/blog/2010/09/openx-ad-server-v2-8-7-released/</link>
		<comments>http://www.openxconsultant.com/blog/2010/09/openx-ad-server-v2-8-7-released/#comments</comments>
		<pubDate>Thu, 16 Sep 2010 16:02:10 +0000</pubDate>
		<dc:creator>Erik Geurts</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Upgrading]]></category>
		<category><![CDATA[bug fix]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[upgrade]]></category>
		<category><![CDATA[v2.8]]></category>

		<guid isPermaLink="false">http://www.openxconsultant.com/?p=622</guid>
		<description><![CDATA[A new version of the OpenX Ad Server software has been released. This version 2.8.7 fixes a very serious security issue. According to the announcement on the OpenX blog: there is a vulnerability in the 2.8 downloadable version of OpenX that can result in a server running the downloaded version of OpenX being compromised. The [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_129" class="wp-caption alignright" style="width: 280px"><img class="size-full wp-image-129" title="OpenX Ad Server logo" src="http://www.openxconsultant.com/images/logo-adserver.png" alt="" width="270" height="32" /><p class="wp-caption-text">OpenX Ad Server v2.8.7 released for download</p></div>
<p>A new version of the OpenX Ad Server software has been released. This version 2.8.7 fixes a very serious security issue. According to the announcement on the OpenX blog:</p>
<blockquote><p>there is a vulnerability in the 2.8 downloadable version of OpenX that can  result in a server running the downloaded version of OpenX being compromised.</p></blockquote>
<p>The issue stems from the Video Ads plugin for OpenX, which in turn uses an open source third party component called Open Flash Charts (OFC) to display graphs about video ad performance. There was a security issue with OFC which has now been fixed.</p>
<p>In addition, the upgrade notification inside the OpenX management pages has this information:</p>
<blockquote><p>If you recently upgraded to version 2.8.6, you can simply install an  upgraded video ad plug-in available [here] or remove the following file: <em>admin/plugins/videoReport/lib/ofc2/ofc_upload_image.php</em> from your installation.</p></blockquote>
<p>This is the second update in less than 1 week, which might sound alarming. On the other hand, there will always be bugs and security vulnerabilities in software, and it&#8217;s better to have those fixed.</p>
<p>Besides this fix for the security issue that was uncovered, there is also a seemingly small functional change in this new version:</p>
<blockquote><p>For users in the UK, all market interfaces now reflect your  participation in Orange Ad Market, and all Orange Ad Market market  monetary values are in GBP.</p></blockquote>
<p>Since both the OpenX main website and the OpenX blog appear to be down at the time I&#8217;m writing this, I can&#8217;t give you any more information than what I included above.</p>
<p>What does still seem to work at the moment is the download link at <a href="http://download.openx.org/openx-2.8.7.zip" target="_blank">http://download.openx.org/openx-2.8.7.zip</a>.</p>
Share this on:<a rel="nofollow" target="_blank"  href="http://twitter.com/home?status=OpenX%20Ad%20Server%20v2.8.7%20released%20-%20http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-ad-server-v2-8-7-released%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/twitter.png" class="sociable-img sociable-hovers" title="Twitter" alt="Twitter" /></a><a rel="nofollow" target="_blank"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-ad-server-v2-8-7-released%2F&amp;title=OpenX%20Ad%20Server%20v2.8.7%20released&amp;source=Support+for+OpenX+Source+ad+server+by+independent+OpenX+Source+Specialist+Erik+Geurts+Support%2C+Consulting%2C+and+Training+for+OpenX+Source+ad+server&amp;summary=%0D%0A%0D%0AA%20new%20version%20of%20the%20OpenX%20Ad%20Server%20software%20has%20been%20released.%20This%20version%202.8.7%20fixes%20a%20very%20serious%20security%20issue.%20According%20to%20the%20announcement%20on%20the%20OpenX%20blog%3A%0D%0Athere%20is%20a%20vulnerability%20in%20the%202.8%20downloadable%20version%20of%20OpenX%20that%20can%20" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/linkedin.png" class="sociable-img sociable-hovers" title="LinkedIn" alt="LinkedIn" /></a><a rel="nofollow" target="_blank"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-ad-server-v2-8-7-released%2F&amp;t=OpenX%20Ad%20Server%20v2.8.7%20released" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/facebook.png" class="sociable-img sociable-hovers" title="Facebook" alt="Facebook" /></a><a rel="nofollow" target="_blank"  href="mailto:?subject=OpenX%20Ad%20Server%20v2.8.7%20released&amp;body=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-ad-server-v2-8-7-released%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/email_link.png" class="sociable-img sociable-hovers" title="email" alt="email" /></a><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.openxconsultant.com/blog/2010/09/openx-ad-server-v2-8-7-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenX Statistics as Graphs plugin updated (v1.0.3)</title>
		<link>http://www.openxconsultant.com/blog/2010/09/openx-statistics-as-graphs-plugin-updated-v1-0-3/</link>
		<comments>http://www.openxconsultant.com/blog/2010/09/openx-statistics-as-graphs-plugin-updated-v1-0-3/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 15:40:59 +0000</pubDate>
		<dc:creator>Erik Geurts</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[OpenX plugins]]></category>
		<category><![CDATA[plugins]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[upgrade]]></category>

		<guid isPermaLink="false">http://www.openxconsultant.com/?p=617</guid>
		<description><![CDATA[The team at AdserverPlugins.com is releasing an update of the free Statistics as Graphs plugin for the OpenX Ad Server. This version 1.0.3 is available for download right now. This is a security fix release that takes care of one issue: A vulnerability has been discovered in the third-party open source graphing component Open Flash [...]]]></description>
			<content:encoded><![CDATA[<p>The team at AdserverPlugins.com is releasing an update of the free <a href="http://www.adserverplugins.com/openx/free-plugins-for-openx-ad-server/statistics-as-graphs/" target="_blank">Statistics as Graphs plugin for the OpenX Ad Server</a>. This version 1.0.3 is <a href="http://www.adserverplugins.com/openx/free-plugins-for-openx-ad-server/statistics-as-graphs/" target="_blank">available for download right now</a>.</p>
<p>This is a security fix release that takes care of one issue:</p>
<ul>
<li>A vulnerability has been discovered in the third-party open source graphing component Open Flash Charts that is used by this plugin to draw the graphs.</li>
</ul>
<p>As always with security fix releases, it is crucial to upgrade to the newest version as soon as possible.</p>
Share this on:<a rel="nofollow" target="_blank"  href="http://twitter.com/home?status=OpenX%20Statistics%20as%20Graphs%20plugin%20updated%20%28v1.0.3%29%20-%20http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-statistics-as-graphs-plugin-updated-v1-0-3%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/twitter.png" class="sociable-img sociable-hovers" title="Twitter" alt="Twitter" /></a><a rel="nofollow" target="_blank"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-statistics-as-graphs-plugin-updated-v1-0-3%2F&amp;title=OpenX%20Statistics%20as%20Graphs%20plugin%20updated%20%28v1.0.3%29&amp;source=Support+for+OpenX+Source+ad+server+by+independent+OpenX+Source+Specialist+Erik+Geurts+Support%2C+Consulting%2C+and+Training+for+OpenX+Source+ad+server&amp;summary=The%20team%20at%20AdserverPlugins.com%20is%20releasing%20an%20update%20of%20the%20free%20Statistics%20as%20Graphs%20plugin%20for%20the%20OpenX%20Ad%20Server.%20This%20version%201.0.3%20is%20available%20for%20download%20right%20now.%0D%0A%0D%0AThis%20is%20a%20security%20fix%20release%20that%20takes%20care%20of%20one%20issue%3A%0D%0A%0D%0A%09A%20vuln" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/linkedin.png" class="sociable-img sociable-hovers" title="LinkedIn" alt="LinkedIn" /></a><a rel="nofollow" target="_blank"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-statistics-as-graphs-plugin-updated-v1-0-3%2F&amp;t=OpenX%20Statistics%20as%20Graphs%20plugin%20updated%20%28v1.0.3%29" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/facebook.png" class="sociable-img sociable-hovers" title="Facebook" alt="Facebook" /></a><a rel="nofollow" target="_blank"  href="mailto:?subject=OpenX%20Statistics%20as%20Graphs%20plugin%20updated%20%28v1.0.3%29&amp;body=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-statistics-as-graphs-plugin-updated-v1-0-3%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/email_link.png" class="sociable-img sociable-hovers" title="email" alt="email" /></a><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.openxconsultant.com/blog/2010/09/openx-statistics-as-graphs-plugin-updated-v1-0-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenX Ad Server v2.8.6 released (or not?)</title>
		<link>http://www.openxconsultant.com/blog/2010/09/openx-ad-server-v2-8-6-released-or-not/</link>
		<comments>http://www.openxconsultant.com/blog/2010/09/openx-ad-server-v2-8-6-released-or-not/#comments</comments>
		<pubDate>Thu, 09 Sep 2010 09:03:57 +0000</pubDate>
		<dc:creator>Erik Geurts</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[upgrade]]></category>
		<category><![CDATA[v2.8]]></category>

		<guid isPermaLink="false">http://www.openxconsultant.com/?p=605</guid>
		<description><![CDATA[Note: this is a cross-post from my contribution at OpenXtips.com yesterday. Just like in March 2010, a new version of the OpenX software has been released recently, but not a single byte of publicity has been devoted to it. No mention on the OpenX blog or on Twitter, nothing. Judging from the dates on the [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: this is a cross-post from my contribution at <a href="http://www.openxtips.com/2010/09/news-openx-2-8-6-released-or-not/" target="_blank">OpenXtips.com</a> yesterday.</em></p>
<div id="attachment_82" class="wp-caption alignright" style="width: 241px"><img class="size-full wp-image-82 " title="OpenX Ad Server v2.8.6 released for download" src="http://www.openxconsultant.com/images/openx_adserver_logo.gif" alt="OpenX Ad Server v2.8.6 released for download" width="231" height="82" /><p class="wp-caption-text">OpenX Ad Server v2.8.6 released for download</p></div>
<p>Just like in <a href="http://www.openxconsultant.com/blog/2010/03/openx-ad-server-v2-8-5-released-for-download/" target="_self">March 2010</a>, a new version of the OpenX software has been released recently, but not a single byte of publicity has been devoted to it. No mention on the <a href="http://blog.openx.org/" target="_blank">OpenX blog</a> or on <a href="http://twitter.com/openx" target="_blank">Twitter</a>, nothing. Judging from the dates on the files in the download archive, the new release was completed on September 2nd of 2010, so almost a week ago.</p>
<p>This new version 2.8.6 seems to be mostly about the security issue that was found and fixed a few weeks ago. Back then, on August 12, a somewhat cryptic <a href="http://forum.openx.org/index.php?showtopic=503483831" target="_blank">announcement was posted on the OpenX forums</a>, informing people how to fix the security problem. That post also hinted at a new release that would be out soon.</p>
<p>The release notes file in the 2.8.6 archive points to the <a href="https://developer.openx.org/" target="_blank">OpenX Developer site</a> for more details, but the <a href="https://developer.openx.org/jira/browse/OX/fixforversion/11201" target="_blank">issue tracker for version 2.8.6</a> is still open and most issues in it are still marked as unresolved. And the version check inside the OpenX software doesn&#8217;t give any notifications about upgrade availability.</p>
<p>Altogether, this is a pretty strange situation. Obviously, it&#8217;s smart to upgrade to a new version as soon as it&#8217;s released, especially if the upgrade is about fixing security issues. On the other hand, what should we think about a release that is not announced in any way, shape or form?</p>
<p><a href="http://www.openx.org/ad-server/download" target="_blank">Download the OpenX Community edition v2.8.6</a>.</p>
Share this on:<a rel="nofollow" target="_blank"  href="http://twitter.com/home?status=OpenX%20Ad%20Server%20v2.8.6%20released%20%28or%20not%3F%29%20-%20http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-ad-server-v2-8-6-released-or-not%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/twitter.png" class="sociable-img sociable-hovers" title="Twitter" alt="Twitter" /></a><a rel="nofollow" target="_blank"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-ad-server-v2-8-6-released-or-not%2F&amp;title=OpenX%20Ad%20Server%20v2.8.6%20released%20%28or%20not%3F%29&amp;source=Support+for+OpenX+Source+ad+server+by+independent+OpenX+Source+Specialist+Erik+Geurts+Support%2C+Consulting%2C+and+Training+for+OpenX+Source+ad+server&amp;summary=Note%3A%20this%20is%20a%20cross-post%20from%20my%20contribution%20at%20OpenXtips.com%20yesterday.%0D%0A%0D%0A%0D%0A%0D%0AJust%20like%20in%20March%202010%2C%20a%20new%20version%20of%20the%20OpenX%20software%20has%20been%20released%20recently%2C%20but%20not%20a%20single%20byte%20of%20publicity%20has%20been%20devoted%20to%20it.%20No%20mention%20on%20the%20O" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/linkedin.png" class="sociable-img sociable-hovers" title="LinkedIn" alt="LinkedIn" /></a><a rel="nofollow" target="_blank"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-ad-server-v2-8-6-released-or-not%2F&amp;t=OpenX%20Ad%20Server%20v2.8.6%20released%20%28or%20not%3F%29" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/facebook.png" class="sociable-img sociable-hovers" title="Facebook" alt="Facebook" /></a><a rel="nofollow" target="_blank"  href="mailto:?subject=OpenX%20Ad%20Server%20v2.8.6%20released%20%28or%20not%3F%29&amp;body=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F09%2Fopenx-ad-server-v2-8-6-released-or-not%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/email_link.png" class="sociable-img sociable-hovers" title="email" alt="email" /></a><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.openxconsultant.com/blog/2010/09/openx-ad-server-v2-8-6-released-or-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Attacks on OpenX v2.8.2 installations reported</title>
		<link>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/</link>
		<comments>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 09:00:04 +0000</pubDate>
		<dc:creator>Erik Geurts</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[v2.8]]></category>

		<guid isPermaLink="false">http://www.openxconsultant.com/?p=445</guid>
		<description><![CDATA[Starting Saturday, April 10, 2010, users of OpenX v2.8.2 have begun to experience problems with their ad servers that have now been traced back to the security vulnerability that I wrote about back in December of 2009. First symptoms: statistics disappeared The first symptoms is that the statistics in OpenX disappear. I&#8217;ve seen reports of [...]]]></description>
			<content:encoded><![CDATA[<p>Starting Saturday, April 10, 2010, users of OpenX v2.8.2 have begun to experience problems with their ad servers that have now been traced back to the <a href="http://www.openxconsultant.com/blog/2009/12/openx-ad-server-v283-released/" target="_self">security vulnerability</a> that I wrote about back in December of 2009.</p>
<p><span id="more-445"></span></p>
<h2>First symptoms: statistics disappeared</h2>
<p>The first symptoms is that the statistics in OpenX disappear. I&#8217;ve seen reports of people mentioning this on the OpenX forums, and some people have also contacted me directly. Luckily, the statistics aren&#8217;t really gone from the database, and ad delivery continues to function without problem. This was confirmed when inspecting the database and looking at the tables that store the statistics.</p>
<h2>Cause: hacks of old versions</h2>
<p>While investigating one of these problematic OpenX installations, fellow <a title="OpenX consultant Matteo Beccati" href="http://www.beccati.com/" target="_blank">OpenX consultant Matteo Beccati</a> discovered that it had been attacked, abusing a vulnerability in OpenX v2.8.2 that has been fixed a long time ago. Unfortunately, not everyone has taken the time to upgrade yet, leaving their systems vulnerable to attacks like this one.</p>
<p>It was found that the attacker uses this security vulnerability to insert an additional administrator account. Next he uses this login to upgrade the OpenX plugin that takes care of the available banner types. The plugin he injects contains malicious code that creates a backdoor into the server. As a side effect, the attack creates some entries in the database, leading to the disappearance of the on-screen statistics.</p>
<p>From the logs that have been found, this appears to be an automated attack. The attacks that have been investigated are all originating from the same IP address.</p>
<h2>Remedy: upgrade</h2>
<p>For someone running OpenX v2.8.2 or older who hasn&#8217;t been infected yet, the best course of action is to upgrade to a more recent version of OpenX as soon as possible. If it takes a while to prepare and plan for this, then meanwhile I would recommend removing the install.php and install-plugins.php files in the &#8216;www/admin&#8217; folder of your OpenX installation.</p>
<p>If a system has been attacked already, an upgrade is not going to fix this problem, since the modified plugin will be migrated to the new version, along with any changes in the database. This will have to be cleaned first.</p>
<h3>Update</h3>
<p>In later reports of the same kind of hack, the &#8216;missing statistics&#8217; issue no longer occurred. It appears that the hacker has changed this element. However, the malicious code is still getting injected. The first time people notice problems is when their site or the ad server is reported as as containing malware by Google&#8217;s Safe Browsing program.</p>
<p>Not only OpenX v2.8.2 is vulnerable to this problem, the same applies to v2.8.0 and v2.8.1.</p>
Share this on:<a rel="nofollow" target="_blank"  href="http://twitter.com/home?status=Attacks%20on%20OpenX%20v2.8.2%20installations%20reported%20-%20http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F04%2Fattacks-on-openx-v2-8-2-installations-reported%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/twitter.png" class="sociable-img sociable-hovers" title="Twitter" alt="Twitter" /></a><a rel="nofollow" target="_blank"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F04%2Fattacks-on-openx-v2-8-2-installations-reported%2F&amp;title=Attacks%20on%20OpenX%20v2.8.2%20installations%20reported&amp;source=Support+for+OpenX+Source+ad+server+by+independent+OpenX+Source+Specialist+Erik+Geurts+Support%2C+Consulting%2C+and+Training+for+OpenX+Source+ad+server&amp;summary=Starting%20Saturday%2C%20April%2010%2C%202010%2C%20users%20of%20OpenX%20v2.8.2%20have%20begun%20to%20experience%20problems%20with%20their%20ad%20servers%20that%20have%20now%20been%20traced%20back%20to%20the%20security%20vulnerability%20that%20I%20wrote%20about%20back%20in%20December%20of%202009.%0D%0A%0D%0A%0D%0AFirst%20symptoms%3A%20statistics" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/linkedin.png" class="sociable-img sociable-hovers" title="LinkedIn" alt="LinkedIn" /></a><a rel="nofollow" target="_blank"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F04%2Fattacks-on-openx-v2-8-2-installations-reported%2F&amp;t=Attacks%20on%20OpenX%20v2.8.2%20installations%20reported" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/facebook.png" class="sociable-img sociable-hovers" title="Facebook" alt="Facebook" /></a><a rel="nofollow" target="_blank"  href="mailto:?subject=Attacks%20on%20OpenX%20v2.8.2%20installations%20reported&amp;body=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2010%2F04%2Fattacks-on-openx-v2-8-2-installations-reported%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/email_link.png" class="sociable-img sociable-hovers" title="email" alt="email" /></a><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>OpenX Ad Server v2.8.3 released &#8211; Security Fix!</title>
		<link>http://www.openxconsultant.com/blog/2009/12/openx-ad-server-v283-released/</link>
		<comments>http://www.openxconsultant.com/blog/2009/12/openx-ad-server-v283-released/#comments</comments>
		<pubDate>Thu, 24 Dec 2009 10:47:53 +0000</pubDate>
		<dc:creator>Erik Geurts</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Upgrading]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[v2.8]]></category>

		<guid isPermaLink="false">http://www.openxconsultant.com/?p=287</guid>
		<description><![CDATA[A security problem has been discovered in OpenX Ad Server v2.8.2, enabling anyone to log in as an Administrator. This is obviously an very serious problem, because it renders any OpenX Ad Server vulnerable. An emergency fix has been developed and released as OpenX Ad Server v2.8.3. The new version is available for immediate download [...]]]></description>
			<content:encoded><![CDATA[<p>A security problem has been discovered in OpenX Ad Server v2.8.2, enabling anyone to log in as an Administrator. This is obviously an very serious problem, because it renders any OpenX Ad Server vulnerable.</p>
<p>An emergency fix has been developed and released as <strong>OpenX Ad Server v2.8.3</strong>. The new version is available for <a href="http://www.openx.org/ad-server/download" target="_blank">immediate download</a> at the OpenX website. The <a href="http://blog.openx.org/12/security-matters-2/" target="_blank">OpenX Blog provides background information</a> and tips for security precautions.</p>
<p><em>Update April 13, 2010: it appears that <a href="http://www.openxconsultant.com/blog/2010/04/attacks-on-openx-v2-8-2-installations-reported/">an exploit for the vulnerability in OpenX v2.8.2</a> is making the rounds on the internet, infection these old versions with a back door and breaking the display of the on-screen statistics.</em></p>
Share this on:<a rel="nofollow" target="_blank"  href="http://twitter.com/home?status=OpenX%20Ad%20Server%20v2.8.3%20released%20-%20Security%20Fix%21%20-%20http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2009%2F12%2Fopenx-ad-server-v283-released%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/twitter.png" class="sociable-img sociable-hovers" title="Twitter" alt="Twitter" /></a><a rel="nofollow" target="_blank"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2009%2F12%2Fopenx-ad-server-v283-released%2F&amp;title=OpenX%20Ad%20Server%20v2.8.3%20released%20-%20Security%20Fix%21&amp;source=Support+for+OpenX+Source+ad+server+by+independent+OpenX+Source+Specialist+Erik+Geurts+Support%2C+Consulting%2C+and+Training+for+OpenX+Source+ad+server&amp;summary=A%20security%20problem%20has%20been%20discovered%20in%20OpenX%20Ad%20Server%20v2.8.2%2C%20enabling%20anyone%20to%20log%20in%20as%20an%20Administrator.%20This%20is%20obviously%20an%20very%20serious%20problem%2C%20because%20it%20renders%20any%20OpenX%20Ad%20Server%20vulnerable.%0D%0A%0D%0AAn%20emergency%20fix%20has%20been%20developed%20and%20" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/linkedin.png" class="sociable-img sociable-hovers" title="LinkedIn" alt="LinkedIn" /></a><a rel="nofollow" target="_blank"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2009%2F12%2Fopenx-ad-server-v283-released%2F&amp;t=OpenX%20Ad%20Server%20v2.8.3%20released%20-%20Security%20Fix%21" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/facebook.png" class="sociable-img sociable-hovers" title="Facebook" alt="Facebook" /></a><a rel="nofollow" target="_blank"  href="mailto:?subject=OpenX%20Ad%20Server%20v2.8.3%20released%20-%20Security%20Fix%21&amp;body=http%3A%2F%2Fwww.openxconsultant.com%2Fblog%2F2009%2F12%2Fopenx-ad-server-v283-released%2F" ><img src="http://www.openxconsultant.com/wp-content/plugins/sociable-30/images/default/16/email_link.png" class="sociable-img sociable-hovers" title="email" alt="email" /></a><br/><br/>]]></content:encoded>
			<wfw:commentRss>http://www.openxconsultant.com/blog/2009/12/openx-ad-server-v283-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

