openupload-devel Mailing List for Open Upload
Status: Beta
Brought to you by:
tsdogs
You can subscribe to this list here.
2008 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
(11) |
Dec
(11) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2009 |
Jan
(11) |
Feb
(9) |
Mar
(1) |
Apr
(32) |
May
(31) |
Jun
(6) |
Jul
(9) |
Aug
(108) |
Sep
(27) |
Oct
|
Nov
(9) |
Dec
(9) |
2010 |
Jan
(16) |
Feb
(38) |
Mar
(24) |
Apr
(2) |
May
(15) |
Jun
(2) |
Jul
(3) |
Aug
(4) |
Sep
(12) |
Oct
(21) |
Nov
(4) |
Dec
(17) |
2011 |
Jan
(7) |
Feb
(6) |
Mar
(26) |
Apr
(35) |
May
(6) |
Jun
(7) |
Jul
(1) |
Aug
(12) |
Sep
(5) |
Oct
(17) |
Nov
(6) |
Dec
(7) |
2012 |
Jan
(28) |
Feb
(17) |
Mar
(18) |
Apr
(2) |
May
(6) |
Jun
(15) |
Jul
(3) |
Aug
(3) |
Sep
(13) |
Oct
|
Nov
(6) |
Dec
(6) |
2013 |
Jan
(13) |
Feb
(2) |
Mar
|
Apr
(2) |
May
|
Jun
|
Jul
(3) |
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
|
2014 |
Jan
(2) |
Feb
|
Mar
(2) |
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(2) |
2015 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(2) |
Nov
|
Dec
|
2016 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(4) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2019 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(1) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2020 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: jenaye <je...@pr...> - 2020-04-12 19:32:25
|
Hi there, i found vulnerability ( stored XSS )To make this POC, i just install Openupload 0.4.3 from http://openupload.sourceforge.net and configure it using nginx/php-fpm. I created a file called "<input autofocus onfocus=alert(1)>.png" then i uploaded it, and there is 2 ways to exploit it : 1 ) send link to your uploaded file to admin by email for exemple2 ) let admin navigate himself into`http://localhost/index.php?action=adminfiles` could you correct it? if you have any questions, do not hesitate good evening to you Mike - Pentester for @OrangeCyberdef & and CTF player for @Inshallhack Sent with ProtonMail Secure Email. |
From: Alessandro B. <al...@br...> - 2019-06-01 13:41:22
|
Hi all, if anybody is still interested I just released openupload-0.4.3 which supports php 7.x Migrated from mysql to mysqli and added pdo_mysql support. It has not been fully tested so if you find bugs, please report. Also in GIT (I migrated some time ago) there's an updated version of the 0.5 beta. Enjoy, Alessandro |
From: Alessandro B. <ts...@br...> - 2016-06-04 17:09:32
|
Il 2016-06-03 15:55 Johannes Schröter ha scritto: > It is possible to inject javascript code through the filename of the > uploaded file. > > The vulnerability exists in the default installation and affects all > administrator or user accounts which can see the names of uploaded > files. > > For testing upload a file named "><img src=x > onerror=alert(document.cookie)>.png > > The javascript is stored and also affects the file list at the > Administration Panel. > ok, thanks for the info. Alessandro |
From: Johannes S. <j.s...@de...> - 2016-06-03 13:55:45
|
It is possible to inject javascript code through the filename of the uploaded file. The vulnerability exists in the default installation and affects all administrator or user accounts which can see the names of uploaded files. For testing upload a file named "><img src=x onerror=alert(document.cookie)>.png The javascript is stored and also affects the file list at the Administration Panel. Greets, Johannes Am 03.06.16 um 10:42 schrieb Alessandro Briosi: > Well, > not really... but please send me details about it. > > Alessandro > > Il 01/06/2016 16:34, Johannes Schröter ha scritto: >> Hi, >> >> will this project still maintained? >> >> There exists a potential XSS vulnerability. > > > ------------------------------------------------------------------------------ > What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic > patterns at an interface-level. Reveals which users, apps, and protocols are > consuming the most bandwidth. Provides multi-vendor support for NetFlow, > J-Flow, sFlow and other flows. Make informed decisions using capacity > planning reports. https://ad.doubleclick.net/ddm/clk/305295220;132659582;e > _______________________________________________ > Openupload-devel mailing list > Ope...@li... > https://lists.sourceforge.net/lists/listinfo/openupload-devel > -- devWerks IT-Security and Development Johannes Schröter Gartenstrasse 2 36129 Gersfeld Fon: +49 (0)171 / 4832242 E-Mail: j.s...@de... http://www.devwerks.net |
From: Alessandro B. <al...@br...> - 2016-06-03 09:02:03
|
Well, not really... but please send me details about it. Alessandro Il 01/06/2016 16:34, Johannes Schröter ha scritto: > Hi, > > will this project still maintained? > > There exists a potential XSS vulnerability. |
From: Johannes S. <j.s...@de...> - 2016-06-01 14:50:21
|
Hi, will this project still maintained? There exists a potential XSS vulnerability. -- devWerks IT-Security and Development Johannes Schröter Gartenstrasse 2 36129 Gersfeld Fon: +49 (0)171 / 4832242 E-Mail: j.s...@de... http://www.devwerks.net |
From: Alessandro B. <al...@br...> - 2015-10-22 07:55:22
|
Il 21/10/2015 11:56, Kaju Kaju ha scritto: > Hey > > I'm wondering how much security is that script. > I see that on ftp files are somehow encrypted. > Is there any simple way that some hacker can stole this files and open it? > Unless there is some plugin doing the encryption the files are simply renamed, no encryption involved. If the file is opened with the right application (Windows bases this on the file extension, but other OS like linux looks at the real file type) it can be opened. Ciao, Alessandro |
From: Kaju K. <ka...@gm...> - 2015-10-21 09:56:14
|
Hey I'm wondering how much security is that script. I see that on ftp files are somehow encrypted. Is there any simple way that some hacker can stole this files and open it? |
From: Alessandro B. <ts...@br...> - 2014-12-08 12:45:53
|
Il 2014-12-08 11:44 David VANTYGHEM ha scritto: > Hello, > > Unison logo and Open Upload logo > (http://www.cis.upenn.edu/~bcpierce/unison/) are very similar. Which > one > is the original ? > o:) > As I wrote on the bug report: As OpenUpload is from 2008 and Unison seems to be from 2005 I'd say that Unison has percedence. When I drew it just came out of my mind and my bad skills into graphic design (and didn't notice the logo was similar to Unison till now) Anyway OpenUpload development has stalled, and I have no plans on changing the logo, unless some developer from Unison steps up asking it to be changed. Though I don't see exactly what the problem is. Ciao, Alessandro |
From: David V. <dav...@fr...> - 2014-12-08 10:44:47
|
Hello, Unison logo and Open Upload logo (http://www.cis.upenn.edu/~bcpierce/unison/) are very similar. Which one is the original ? o:) -- David VANTYGHEM Mél. : dav...@fr... XMPP : dav...@ja... http://www.education.free.fr http://www.goall.fr http://www.cnll.fr .--. |o_o | ||_/ | // \\ Envoyé de mon GNU/Linux (| |) / \_ _/ \ \___)=(___/ |
From: Olivier T. <oli...@se...> - 2014-04-15 12:11:38
|
Hi, Looking for a free sharing files solution for an association, I've installled openupload on our server and it's exactly what I needed, thanks for this work. I would like to tweak one thing for our usage : email notifications. When a user upload a file, he has to specify the mail adresses of the recipients and I would like to systematically send a notification to 2 other mail adresses when a file is uploaded by an user ? How could I make this possible ? Sorry for my very bad english, I hope you can understand what I mean... |
From: Alessandro B. <ts...@br...> - 2014-03-21 08:15:04
|
Il 2014-03-20 18:15 Steve Goodrich ha scritto: > I am currently working on getting openupload to work with postfix. I > have > been able to upload a file and have it send an e-mail to the registered > user > from the drop down dialog box. I am however, unable to send a > confirmation > e-mail with the "Send me an e-mail" check box clicked and an e-mail > address > entered into "You're e-mail address". I can't seem to find any error > messages in the logs anywhere. Hoping someone can point me in the right > direction to get this working. > > > Hi Steve, what version are we talking about? 0.4.x or svn. The have different mail configurations. 0.4 uses the php mail command, so you should look at how php is configured. svn uses swiftmailer which has different options. Have you looked at the mail.log if there's something there which clues why the mail is not sent? Maybe is simply an access problem. When you register, confirmation email sender is the openupload email which is set in the config. When you upload a file, email is sent from the user which uploaded the file. Now that I'm talking about it, I have no idea on what happens when who uploads a file is not registered (thus has no email address associated) ... Let me know. Alessandro |
From: Steve G. <stv...@gm...> - 2014-03-20 17:16:00
|
I am currently working on getting openupload to work with postfix. I have been able to upload a file and have it send an e-mail to the registered user from the drop down dialog box. I am however, unable to send a confirmation e-mail with the "Send me an e-mail" check box clicked and an e-mail address entered into "You're e-mail address". I can't seem to find any error messages in the logs anywhere. Hoping someone can point me in the right direction to get this working. Thanks, -Steve |
From: Alessandro B. <ts...@br...> - 2014-01-05 14:49:16
|
Il 04/01/2014 10:36, Robert Hale ha scritto: > Hi > > I have managed to get open upload working and contains much of what we > have been looking for, so thank you very much for making this software > available. I use php 5.2.9 and have upload progress working – I’ll > share my feedback and have some questions > > I downloaded the latest version from the SF page and found the web pages > & images were not loading correctly (as others have experienced) so I > then downloaded the latest version from svn and it was much better. I > had the following issues that I have resolved (but these may have been > as I installed the svn version over the older version?) > > 1. I use mysql, some tables were added OK, others I had to manually add > from the sql/mysql/1_structure.sql file Yeah, svn installation procedure is only manual. > 2. Adding a ‘ to the sites name caused a php hard string error, I had > to manually edit the config file ( from \\' to \’ ) Could be, haven't checked. > 3. Manually set up the permissions for ‘registered’ and ‘unregistered’ > groups. Permissions from 0.4 to svn have changed, as in 1 installation should be manual. > > My questions are: > > Are the access/ permissions detailed anywhere? I have worked out that > to allow an unregistered person access to download without having to > register, you can set the upload module action ‘d’ to allow. > Hmm, not from SVN (but they should be simple to understand, and basically similar to the 0.4) > Also is there a way to see if a file has been downloaded or not? E.g. > If I want to sent a file to 3 email addresses (at the same time or by > later sending an already uploaded file to someone else), can I see which > has downloaded it? > Not really, there's a log but would not know how to distinguish them. Only way would be to have different ids for the same file and send one to each user. Probably it could be implemented with a plugin. Alessandro |
From: Robert H. <rh...@ch...> - 2014-01-04 09:51:30
|
Hi I have managed to get open upload working and contains much of what we have been looking for, so thank you very much for making this software available. I use php 5.2.9 and have upload progress working - I'll share my feedback and have some questions I downloaded the latest version from the SF page and found the web pages & images were not loading correctly (as others have experienced) so I then downloaded the latest version from svn and it was much better. I had the following issues that I have resolved (but these may have been as I installed the svn version over the older version?) 1. I use mysql, some tables were added OK, others I had to manually add from the sql/mysql/1_structure.sql file 2. Adding a ' to the sites name caused a php hard string error, I had to manually edit the config file ( from \\' to \' ) 3. Manually set up the permissions for 'registered' and 'unregistered' groups. My questions are: Are the access/ permissions detailed anywhere? I have worked out that to allow an unregistered person access to download without having to register, you can set the upload module action 'd' to allow. Also is there a way to see if a file has been downloaded or not? E.g. If I want to sent a file to 3 email addresses (at the same time or by later sending an already uploaded file to someone else), can I see which has downloaded it? Thanks Robert |
From: VAN D. J. <jv...@ac...> - 2013-11-12 16:01:34
|
Dear Alessandro, First, i would like to thank you for this great software ! I installed version 0.4.2 (last official stable release) in our company and configure it with AD authentication. I had to sniff network packets with tcpdump, look inside your php code, and inspect our AD with LDAPExplorer to understand the parameters needed for AD integration (I'm not really familiar with AD parameters). But finally, it works perfectly ! I added a patch "chained.inc.php" to allow external users to connect - also works greatly (would be nice to add it into svn release). There was a little bug when user modifies its password (it is recorded into DB not encrypted and user can't log in anymore). So I changed the code to: function useredit($user, $pwd = false) { // check if $user is internal as we do not edit // users in ldap directory. // the check is not very useful because the form calling this function // display the new values even if they are not applied here $users=$this->users(); // retrieve internal users foreach ($users as $u) { if (strcmp($u['login'],$user['login'])==0) { $this->authD->useredit($user, $pwd); break; } } } That's all for "official release" ;-) Then I tried last SVN release (build 398). The functionality that generates a "one shot upload" invitation is very interesting for our support team. I thought I just have to copy my "config.inc.php" into the new folder, but it does not work. I identified the problem : the user group. In version 0.4.2, (LDAP) group is only used for right assignment/check when you access to web pages. In SVN version (b398), the group is also inserted into DB when you upload files or generate invitation. So the group is checked when you try to download or delete a file. This group is not correctly initialized when you use AD authentication. In the User class, "$user[group]" contains an array of all the AD groups of the user. When you upload a file or create an invitation, the new file (or invitation) is inserted into DB, but not the "openupload" AD group (=array). You can list your files, but if you click on one of them you'll get an error message : "Wrong file id" Access to your uploaded files or invitations is not allowed. If you take a look into the database, you'll see empty values in the group column of the uploaded files / invitation. One possible solution: Extract the groups from the group table (=DB group). Extract the AD groups of logged user. Compare them and if one match is found (DB group = AD group) stop the search - only one group by user. This will be the user group. If the user is not member of any of the DB group, default group (see config file) is applied. What do you think about it ? Where should it be done ? Jean |
From: kun a. <ham...@gm...> - 2013-07-16 03:25:05
|
Not working. here's the error report: PHP Warning: ldap_search(): Search: No such object in /var/www/openupload042/lib/modules/auth/ldap.inc.php on line 47 On 7/10/13, Alessandro Briosi <ts...@br...> wrote: > Il 05/07/2013 08:15, didi supriyadi ha scritto: >> I installed successfully openupload with openldap, except when i need >> other groups in other subtree i can't login. I found this thread >> https://sourceforge.net/mailarchive/message.php?msg_id=27459301 but i >> don't know where to put the script. Can anybody help me? > > I'd say it's to use in the ldap.inc.php where the user is used to > authenticate against openldap. > > line 45 in the file. (the code you found should substitute the actual > code that follows) > > $uid = $this->ufield.'='.$login.','.$this->config['userdn']; > > with > > // The following code looks for the user DN, in case our users are not > stored in a flat tree but in various subtrees. > // If all users are under config['userdn'], then the returned dn is the > same as the previously determined uid. > > $tmp_result=ldap_search($this->ds,$this->config['userdn'],"uid=$login"); > $infos=ldap_get_entries($this->ds,$tmp_result); > $dn=$infos[0]["dn"]; > $uid = $dn; > > But personally never tested this. > > Alessandro > > ------------------------------------------------------------------------------ > See everything from the browser to the database with AppDynamics > Get end-to-end visibility with application monitoring from AppDynamics > Isolate bottlenecks and diagnose root cause in seconds. > Start your free trial of AppDynamics Pro today! > http://pubads.g.doubleclick.net/gampad/clk?id=48808831&iu=/4140/ostg.clktrk > _______________________________________________ > Openupload-devel mailing list > Ope...@li... > https://lists.sourceforge.net/lists/listinfo/openupload-devel > |
From: Alessandro B. <ts...@br...> - 2013-07-10 15:25:33
|
Il 05/07/2013 08:15, didi supriyadi ha scritto: > I installed successfully openupload with openldap, except when i need > other groups in other subtree i can't login. I found this thread > https://sourceforge.net/mailarchive/message.php?msg_id=27459301 but i > don't know where to put the script. Can anybody help me? I'd say it's to use in the ldap.inc.php where the user is used to authenticate against openldap. line 45 in the file. (the code you found should substitute the actual code that follows) $uid = $this->ufield.'='.$login.','.$this->config['userdn']; with // The following code looks for the user DN, in case our users are not stored in a flat tree but in various subtrees. // If all users are under config['userdn'], then the returned dn is the same as the previously determined uid. $tmp_result=ldap_search($this->ds,$this->config['userdn'],"uid=$login"); $infos=ldap_get_entries($this->ds,$tmp_result); $dn=$infos[0]["dn"]; $uid = $dn; But personally never tested this. Alessandro |
From: didi s. <ham...@gm...> - 2013-07-05 06:16:06
|
I installed successfully openupload with openldap, except when i need other groups in other subtree i can't login. I found this thread https://sourceforge.net/mailarchive/message.php?msg_id=27459301 but i don't know where to put the script. Can anybody help me? |
From: Alessandro B. <ts...@br...> - 2013-04-27 07:32:14
|
Il 25/04/2013 14:19, nag...@ac... ha scritto: > Hi, > > I wanted to enquire regarding opensource that can use opensource project > and published on net by creating website(.com). > I'm not sure I fully understand the question. But openupload is released under the GPL2 so you can use it as far as you respect the license terms. Alessandro |
From: <nag...@ac...> - 2013-04-25 12:20:57
|
Hi, I wanted to enquire regarding opensource that can use opensource project and published on net by creating website(.com). reply reg, palwencha ________________________________ This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security and assessment of internal compliance with Accenture policy. ______________________________________________________________________________________ www.accenture.com |
From: Alexandre C. <ale...@op...> - 2013-02-14 19:25:38
|
Hello, What is the extension of the e-mail address? Personally, I've already seen problems with. 'Pro'. Sincerely, Alexander Chaussier ----- Mail original ----- De: "Alastair Cook" <ma...@as...> À: ope...@li... Envoyé: Jeudi 14 Février 2013 17:46:14 Objet: [openupload-devel] “e-mail is not a valid address!” message Hi, I was wondering if anyone could assist me. I’ve set up OpenUpload however if I try and add a new user, or do anything that involves entering an email address, like uploading a file, I get the following message once I proceed: “e-mail is not a valid address!” The email is valid and I’ve checked the plugin options but it still persists. Any ideas? Thanks, Alastair ------------------------------------------------------------------------------ Free Next-Gen Firewall Hardware Offer Buy your Sophos next-gen firewall before the end March 2013 and get the hardware for free! Learn more. http://p.sf.net/sfu/sophos-d2d-feb _______________________________________________ Openupload-devel mailing list Ope...@li... https://lists.sourceforge.net/lists/listinfo/openupload-devel |
From: Alastair C. <ma...@as...> - 2013-02-14 17:01:37
|
Hi, I was wondering if anyone could assist me. I’ve set up OpenUpload however if I try and add a new user, or do anything that involves entering an email address, like uploading a file, I get the following message once I proceed: “e-mail is not a valid address!” The email is valid and I’ve checked the plugin options but it still persists. Any ideas? Thanks, Alastair |
From: gmartin <gm...@gm...> - 2013-01-21 03:46:27
|
I verified that on a machine running 64bit OS & php compiled as x86-64 I was able to set the max_upload to 10,000M. this solves the php integer setting. I wasn't able to run a test however. More here: http://stackoverflow.com/questions/864058/how-to-have-64-bit-integer-on-php \\Greg On Sat, Jan 19, 2013 at 11:36 AM, Alessandro Briosi <ts...@br...>wrote: > Il 2013-01-19 15:42 gmartin ha scritto: > > Alessandro, > > Can php support larger files if you are running on a 64bit OS? I was > > under > > the opinion that the limit was due to the php integer size which > > would be > > larger when compiled for 64bit > > > > That said, the problem here seems one of configuration > > > > I have seen some talk about 64bit, but I'm not sure it would work. > > There's a patch applied on march 2012 which should overcome this (even > on 32bit), but I have no idea on what version this applies to. > > https://bugs.php.net/bug.php?id=44522 > > Alessandro > > > ------------------------------------------------------------------------------ > Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS, > MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current > with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft > MVPs and experts. SALE $99.99 this month only -- learn more at: > http://p.sf.net/sfu/learnmore_122912 > _______________________________________________ > Openupload-devel mailing list > Ope...@li... > https://lists.sourceforge.net/lists/listinfo/openupload-devel > |
From: Alessandro B. <ts...@br...> - 2013-01-19 16:37:03
|
Il 2013-01-19 15:42 gmartin ha scritto: > Alessandro, > Can php support larger files if you are running on a 64bit OS? I was > under > the opinion that the limit was due to the php integer size which > would be > larger when compiled for 64bit > > That said, the problem here seems one of configuration > I have seen some talk about 64bit, but I'm not sure it would work. There's a patch applied on march 2012 which should overcome this (even on 32bit), but I have no idea on what version this applies to. https://bugs.php.net/bug.php?id=44522 Alessandro |