Protection against a critical Joomla < 3.6.5 security bug

The authors of the Joomla software announced that Joomla versions 1.6.0 through 3.6.4 have a critical security bug that allows “hackers” to take over a site (CVE-2016-9838).

The best solution for Joomla users is to update to version 3.6.5 immediately. However, we also added a security rule to our servers this evening to block this attack, based on an initial analysis.

The rule works by blocking attempts to register new Joomla users that contain certain kinds of invalid data; it allows only “expected” data. This could mean that if you’ve modified your Joomla user registration page in some unusual way, it might be incorrectly blocked. We’ll keep an eye out for this potential problem; don’t hesitate to contact us if you have any trouble.

PHP 5.6.29

The PHP developers recently released version 5.6.29 that fixes several bugs. We’ve upgraded the PHP 5.6 series on our servers as a result.

This change should not be noticeable, but in the unlikely event you experience any trouble, don’t hesitate to contact us.

PHP 7.0.14

The PHP developers recently released version 7.0.14 that fixes several bugs. We’ve upgraded the PHP 7.0 series on our servers as a result.

This change should not be noticeable, but in the unlikely event you experience any trouble, don’t hesitate to contact us.

WordPress 4.7

WordPress 4.7 was recently released, and as always, we’ve updated our WordPress one-click installer to automatically install the latest version for new WordPress sites.

If you’ve previously installed an older version of WordPress, you should update it from within your WordPress Dashboard.

Read the rest of this entry »

PHP 7.0.13 and 5.6.28

The PHP developers recently released versions 7.0.13 and 5.6.28 that fix several bugs. We’ve upgraded the PHP 7.0 and 5.6 series on our servers as a result.

Read the rest of this entry »

PHP 7.0.12 and 5.6.27

The PHP developers recently released versions 7.0.12 and 5.6.27 that fix several bugs. We’ve upgraded the PHP 7.0 and 5.6 series on our servers as a result.

For the PHP 5.6 and 7.0 series, we’ve also updated ionCube Loader to the current version 6.0.6, and SourceGuardian Loader to the current version 11.

These changes should not be noticeable, but in the unlikely event you experience any trouble, don’t hesitate to contact us.

Protection against a critical Joomla < 3.6.4 security bug

The authors of the Joomla software announced that Joomla versions 3.4.4 through 3.6.3 have a critical security bug that allows “hackers” to take over a site by adding new administrative users (CVE-2016-8869).

The best solution for Joomla users is to update to version 3.6.4 immediately. However, we also added a rule to our servers this morning to block this attack. The rule should ensure that if you use our hosting service, hackers won’t be able to take advantage of this bug.

(And a tip o’ the hat to security researcher Melvin Lammerts, who published detailed technical information of the bug that allowed us to do this more quickly than usual.)

PHP 7.0.11 and 5.6.26

The PHP developers recently released versions 7.0.11 and 5.6.26 that fix several bugs. We’ve upgraded the PHP 7.0 and 5.6 series on our servers as a result.

These changes should not be noticeable, but in the unlikely event you experience any trouble, don’t hesitate to contact us.

In addition, the ionCube Loader software is now compatible with PHP 7, so we’ve enabled that option in the “PHP Settings” section of our My Account control panel.

Mailman mailing list software upgraded to version 2.1.23

The authors of the Mailman mailing list software we provide for customers have recently released version 2.1.23 to fix several bugs.

We’ve upgraded the Mailman software on our servers as a result.

Users of Mailman lists shouldn’t notice any changes, but as always, don’t hesitate to contact us if you have any questions or see any problems.

PHP 7.0.10 and 5.6.25

The PHP developers recently released versions 7.0.10 and 5.6.25 that fix several bugs. We’ve upgraded the PHP 7.0 and 5.6 series on our servers as a result.

These changes should not be noticeable, but in the unlikely event you experience any trouble, don’t hesitate to contact us.