hi,
my webhoster closed my website because spam mails were
sent over my mailserver. they say i should update the
exponent scripts.
i use exponent 0.93 origin.
i've read that 26.9.2006 there was a security patch
announced. here are my questions:
- will this patch close the spam mail door?
- is it possible to be informed by mail about security
patches (or must i read the news)?
- which patches do i have to install to get a secure
exponent version when using the "0.96.3 origin" tarball
from download area?
- i've read that 0.96.4 fixed some security problems
but the official productive version is 0.96.3 - were
the problems solved by patches for 0.96.3 or how do i
get the secure code?
i really love exponent but i'm really confused about
security patches and release management. please help me ...
kind regards,
pierre
Logged In: YES
user_id=1231619
- The patch will not close the spam mail door. Please take a
look at the release notes.
- You can monitor new file releases in your personal account
page. http://sourceforge.net/my/monitor.php
- I recommend users to upgrade to the new beta version since
a lot of the security holes are fixed.
- Caused by poor release management, the 0.96.4 release has
been removed from the files section on sourceforge. 0.96.4
contained more bugs then 96.3. Our new target is 0.96.5.
0.96.5 is almost stable and should be released soon.
We made some significant improvements concerning our release
management. As soon as the developers completed a new
version, our quality and assurance teams picks it up and
test the new version. As soon as the bugs, coming forward
when testing are fixed, a new version will be released in
public. For example 96.5rc1, 96.5rc2, 96.5beta. Then the
community test our new releases and with the given feedback
we label a release stable or not.
Please have a little more patience, we are close the release
of a whole new stable version with a lot of improvements.
We’ll take your problem into discussion. Please provide us
as much information as possible. Which script has been used?
There is no spam door as far as I know. The only possibility
is a script that continuously sends forms from the
formbuilder. I think the best solution is to implement an
captcha test in the formbuilder. I’ll post your problem in
the new bugtracker on projects.oicgroup.net.