Archive for August, 2009

Libpurple Users: Update ASAP!

Friday, August 21st, 2009

Pidgin Vulnerability
For users of the awesome instant messaging client Pidgin, you should have a look at this and update your libpurple library when possible.

Just download and install the latest version of Pidgin. It will automatically upgrade your current version.

US-CERT Emailed today:

Pidgin has released a security advisory to address a vulnerability affecting libpurple. This vulnerability is a buffer overflow that may allow an attacker to execute arbitrary code. Libpurple is used by multiple instant messenger (IM) programs including Adium and Pidgin.

IM applications that use libpurple may distribute it as a part of their security updates. Users are encouraged to update affected IM software as soon as possible. A partial listing of IM programs that implement libpurple can be found in the “What is libpurple?” webpage on the Pidgin website. Additional information may be found in the US-CERT Vulnerability Notes Database.

Invision Power Board 3.0.2 Out Now!

Tuesday, August 11th, 2009

Invision Power Board 3.0.2For our clients who run Invision Software, Invision has released Power Board 3.0.2 today!

Excerpted from their email blast earlier today, new features include:

* Improved search and member list performance
* Date filter options for Active Content page
* Many improvements for Sphinx searching (i.e. ability to filter by forum, ability to search titles only, ability to group posts as topics, plugin functionality for modifying the query, and misc bug fixes)
* Ability to hide an application’s tab on the front end, while still allowing it to be publicly accessible
* Improved IP address lookup tool can now support add-on applications
* Portal option to not pin pinned topics for articles
* Added link to user profile when editing a member in ACP
* Added display of time remaining for suspended members when editing a member in ACP
* Spam Monitoring Service support
* Ability to control image quality for Gallery images (jpg/png only)
* PHP version 5.3 is now supported in IP.Board except for OpenID login method. We are awaiting updates from OpenID vendors.

These features look promising, and I recommend if you can, upgrade to it! The improvements to the search are worth it alone, in my opinion.

Also from their email:

You can download IP.Board 3.0.2 and any applications you have an active license for in the client area. As always, make a backup of your community before proceeding.

If you need a hand with this, let us know! We’re here for you, day and night.

Happy foruming! Thanks for hosting with PhireFast!

Twitter Being DDOSed

Thursday, August 6th, 2009

Twitter "Fail Whale"It happened to us a couple of weeks ago, and now Twitter is experiencing the pain of a DDOS attack.

Twitter.com is being DDOSed right now, and the event is reminding us that even Twitter, with their bottomless funding and technical contacts, has been unusable most of the day.

This is a grim reminder that the internet is just like the wild west. Everyone server administrator is responsible for their own “e-land,” and when the bigger boys come in to town and start wreaking havoc, you better watch out.

The winner of most DDOS attacks is the contestant with the most bandwidth. DDOS attacks often come from hundreds or thousands of IP addresses and locations which are constantly changing – A situation which is nearly impossible to block. The analogy I’ve always liked is “you’re trying to shoot several moving targets.” In this case, it’s obvious that Twitter is being overpowered, and for this, I wish them luck.

Promotion that makes no sense right now, seeing that they’re down:
Don’t forget to check out PhireFast on Twitter! twitter.com/phirefast

Regarding the DDOS attack against PhireFast two weeks ago:
Incoming DOS Attacks (Update: Federal Report Now Filed)

Wishing luck to Twitter today. Happy hosting!