<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.m2osw.com"  xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Made to Order Software Corporation - security</title>
 <link>http://www.m2osw.com/taxonomy/term/44/all</link>
 <description></description>
 <language>en</language>
<item>
 <title>Fax Now Online</title>
 <link>http://www.m2osw.com/fax-now-online-30-day-free-trial</link>
 <description>&lt;div class=&quot;product-info product display&quot;&gt;&lt;span class=&quot;uc-price-product uc-price-display uc-price&quot;&gt;$0.00&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;product-body&quot;&gt;&lt;p&gt;&lt;img width=&quot;209&quot; height=&quot;84&quot; border=&quot;0&quot; align=&quot;left&quot; src=&quot;/sites/default/files/images/logo-fax-now-online-on-black.png&quot; alt=&quot;Fax Now Online logo&quot; title=&quot;Fax Now Online for all your facsimile needs.&quot; style=&quot;margin-right: 10px; margin-bottom: 10px;&quot; /&gt;Yes! With &lt;a title=&quot;Visit our Fax Now Online dedicated website.&quot; href=&quot;http://faxnowonline.com/&quot;&gt;&lt;em&gt;Fax Now Online&lt;/em&gt;&lt;/a&gt;,  you can send a fax from your browser or your server (using our MO&amp;nbsp;Fax  &lt;abbr class=&quot;mo-glossary mo-glossary-abbr&quot;  title=&quot;Application Program Interface&quot; lang=&quot;en&quot;&gt;API&lt;/abbr&gt;) to any fax machine in the US. Easy, flexible and cheap, &lt;em&gt;Fax Now Online&lt;/em&gt; is your remote facsimile solution.&lt;/p&gt;

&lt;/div&gt;&lt;div class=&quot;product-info product sell&quot;&gt;&lt;span class=&quot;uc-price-product uc-price-sell uc-price&quot;&gt;$0.00&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;add-to-cart&quot;&gt;&lt;form action=&quot;/taxonomy/term/44/all/feed&quot;  accept-charset=&quot;UTF-8&quot; method=&quot;post&quot; id=&quot;uc-product-add-to-cart-form-672&quot;&gt;
&lt;div&gt;&lt;input type=&quot;hidden&quot; name=&quot;qty&quot; id=&quot;edit-qty&quot; value=&quot;1&quot;  /&gt;
&lt;input type=&quot;submit&quot; name=&quot;op&quot; id=&quot;edit-submit-672&quot; value=&quot;Add to cart&quot;  class=&quot;form-submit node-add-to-cart&quot; /&gt;
&lt;input type=&quot;hidden&quot; name=&quot;form_build_id&quot; id=&quot;form-a13de7e04f24626c258d8201afbab92a&quot; value=&quot;form-a13de7e04f24626c258d8201afbab92a&quot;  /&gt;
&lt;input type=&quot;hidden&quot; name=&quot;form_id&quot; id=&quot;edit-uc-product-add-to-cart-form-672&quot; value=&quot;uc_product_add_to_cart_form_672&quot;  /&gt;

&lt;/div&gt;&lt;/form&gt;
&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://www.m2osw.com/fax-now-online-30-day-free-trial&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.m2osw.com/fax-now-online-30-day-free-trial#comments</comments>
 <pubDate>Fri, 30 Sep 2011 17:02:59 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">672 at http://www.m2osw.com</guid>
</item>
<item>
 <title>Snap! Website ($19.99/mo, first month is free!)</title>
 <link>http://www.m2osw.com/snap-website</link>
 <description>&lt;div class=&quot;product-info product display&quot;&gt;&lt;span class=&quot;uc-price-product uc-price-display uc-price&quot;&gt;$0.00&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;product-body&quot;&gt;&lt;p&gt;&lt;strong&gt;&lt;img align=&quot;left&quot; alt=&quot;Snap! The most advanced web hosting service available.&quot; height=&quot;119&quot; src=&quot;/sites/default/files/images/snap-logo.png&quot; style=&quot;margin-right: 10px; margin-bottom: 5px;&quot; title=&quot;Snap! The most advanced we hosting service available.&quot; width=&quot;150&quot; /&gt;&lt;/strong&gt; &lt;img align=&quot;bottom&quot; alt=&quot;(Small Snap! Logo)&quot; src=&quot;http://www.m2osw.com/sites/default/files/images/round_button_logo_snap.gif&quot; /&gt; &lt;strong&gt;Snap!&lt;/strong&gt; is the most advanced, business quality Web 2.0 hosting service available. &lt;img align=&quot;bottom&quot; alt=&quot;(Small Snap! Logo)&quot; src=&quot;http://www.m2osw.com/sites/default/files/images/round_button_logo_snap.gif&quot; /&gt; &lt;strong&gt;Snap!&lt;/strong&gt;, powerful &lt;em&gt;Content Management System&lt;/em&gt; (&lt;abbr class=&quot;mo-glossary mo-glossary-abbr&quot;  title=&quot;Content Management System&quot;&gt;CMS&lt;/abbr&gt;), is easy to use and gives you peace of mind.&lt;/p&gt;
&lt;p&gt;More and more, web hosting companies offer CMS systems to their customers. The US, French and German governments and many large businesses chose the same CMS as us. It gives you the ability to build a complete website in minutes and gives you full control of your content right from the start.&lt;/p&gt;

&lt;/div&gt;&lt;div class=&quot;product-info product sell&quot;&gt;&lt;span class=&quot;uc-price-product uc-price-sell uc-price&quot;&gt;$0.00&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;add-to-cart&quot;&gt;&lt;form action=&quot;/taxonomy/term/44/all/feed&quot;  accept-charset=&quot;UTF-8&quot; method=&quot;post&quot; id=&quot;uc-product-add-to-cart-form-667&quot;&gt;
&lt;div&gt;&lt;input type=&quot;hidden&quot; name=&quot;qty&quot; id=&quot;edit-qty-1&quot; value=&quot;1&quot;  /&gt;
&lt;input type=&quot;submit&quot; name=&quot;op&quot; id=&quot;edit-submit-667&quot; value=&quot;Add to cart&quot;  class=&quot;form-submit node-add-to-cart&quot; /&gt;
&lt;input type=&quot;hidden&quot; name=&quot;form_build_id&quot; id=&quot;form-f5253ed4914521edaa0de81d83a8b53a&quot; value=&quot;form-f5253ed4914521edaa0de81d83a8b53a&quot;  /&gt;
&lt;input type=&quot;hidden&quot; name=&quot;form_id&quot; id=&quot;edit-uc-product-add-to-cart-form-667&quot; value=&quot;uc_product_add_to_cart_form_667&quot;  /&gt;

&lt;/div&gt;&lt;/form&gt;
&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://www.m2osw.com/snap-website&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.m2osw.com/snap-website#comments</comments>
 <pubDate>Sat, 20 Aug 2011 22:40:50 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">667 at http://www.m2osw.com</guid>
</item>
<item>
 <title>Security Issue in many mail systems</title>
 <link>http://www.m2osw.com/security-issue-postfix</link>
 <description>&lt;p&gt;It always amazes me when one finds a security issue that looks like something that should never have happened in the first place.&lt;/p&gt;
&lt;p&gt;This one was found earlier this year by&amp;nbsp;Wietse Venema who first discovered the issue in Postfix.&lt;/p&gt;
&lt;p&gt;He fixed the Postfix server quickly, however, he went further. He actually tested many other servers sending commands that bypass that very security measure and to his surprised he found out that Postfix wasn&#039;t the only system affected by the problem.&lt;/p&gt;
&lt;p&gt;For those interested, all the details of the problem can be found on the Postfix website as &lt;a href=&quot;http://www.postfix.org/CVE-2011-0411.html&quot; target=&quot;_blank&quot;&gt;CVE-2011-411&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;A&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://www.m2osw.com/security-issue-postfix&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.m2osw.com/security-issue-postfix#comments</comments>
 <pubDate>Wed, 06 Jul 2011 20:04:42 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">666 at http://www.m2osw.com</guid>
</item>
<item>
 <title>Upgrade to PHP 5.3.3 or older because of security issue</title>
 <link>http://www.m2osw.com/php-security-issue-upgrade-needed</link>
 <description>&lt;p&gt;If you are responsible for a Debian or Ubuntu server and run PHP on it, make sure to run the following command to fix several security issues found in PHP:&lt;/p&gt;
&lt;pre class=&quot;rteindent1&quot;&gt;
sudo apt-get install php5-suhosin
&lt;/pre&gt;
&lt;p&gt;This will make the necessary and your PHP&amp;nbsp;version (security wise) will look like you have PHP 5.3.3.&lt;/p&gt;
&lt;p&gt;What I found quite annoying in regard to this issue is the fact that it was very difficult to find a mention of this upgrade. All I could find in large number were people saying that you&#039;d have to get an upgrade using the source code of PHP. Somehow, I did not feel like upgrading PHP from source!

&lt;p&gt;&lt;a href=&quot;http://www.m2osw.com/php-security-issue-upgrade-needed&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.m2osw.com/php-security-issue-upgrade-needed#comments</comments>
 <pubDate>Fri, 10 Jun 2011 00:26:19 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">662 at http://www.m2osw.com</guid>
</item>
<item>
 <title>Protected Node Global Settings</title>
 <link>http://www.m2osw.com/doc-protected-node-settings</link>
 <description>&lt;p&gt;The protected node module has global settings found under:&lt;/p&gt;
&lt;p class=&quot;rteindent1&quot;&gt;&lt;span style=&quot;color: rgb(128, 0, 0);&quot;&gt;Administer &amp;raquo; Site configuration &amp;raquo; Protected node&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;Protected node Statistics&lt;/h2&gt;
&lt;p&gt;The page starts with statistics to let you know how pages are protected on your website. All the counts include published and unpublished content.&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Total nodes &amp;mdash; the total number of nodes on your website&lt;/li&gt;
    &lt;li&gt;Unprotected nodes &amp;mdash; number of nodes that do not have a password&lt;/li&gt;
    &lt;li&gt;Protected nodes &amp;mdash; number of nodes that are current protected by a password
    &lt;ul&gt;
        &lt;li&gt;Showing title &amp;mdash; number of nodes showing their title&lt;/li&gt;
 ...&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;

&lt;p&gt;&lt;a href=&quot;http://www.m2osw.com/doc-protected-node-settings&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.m2osw.com/doc-protected-node-settings#comments</comments>
 <category domain="http://www.m2osw.com/taxonomy/term/607">Protect</category>
 <pubDate>Thu, 28 Apr 2011 00:49:24 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">650 at http://www.m2osw.com</guid>
</item>
<item>
 <title>To Do Tokens</title>
 <link>http://www.m2osw.com/doc-to-do-tokens</link>
 <description>&lt;p&gt;The To Do module supports tokens that can be retrieved using the Token module.&lt;/p&gt;
&lt;p&gt;The available tokens will generally appear in the list of tokens as found under a text area.&lt;/p&gt;
&lt;p&gt;The raw tokens are no representing any security risk. They simply return the raw value instead of a more human representation of the value. For example, when the priority is &amp;quot;High&amp;quot;, the raw value is 2.&lt;/p&gt;

</description>
 <comments>http://www.m2osw.com/doc-to-do-tokens#comments</comments>
 <pubDate>Tue, 26 Apr 2011 10:02:03 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">646 at http://www.m2osw.com</guid>
</item>
<item>
 <title>Insert Node Parameter: override (6-1.3) [special]</title>
 <link>http://www.m2osw.com/doc-insert-node-parameter-override</link>
 <description>&lt;blockquote&gt;
&lt;p class=&quot;rtecenter&quot;&gt;&lt;span style=&quot;color: rgb(255, 0, 0);&quot;&gt;WARNING&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style=&quot;font-size: small;&quot;&gt;&lt;em&gt;This parameter is considered a security hazard. There is an option in your format definition that you have to turn on in order for the feature to work. When not selected, override is ignored. Only allow this feature in an input filter where you can trust users 100%.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;One can use the override parameter to replace the expected data with their own data. Although one would think using the data directly would work as well, there are cases when this is useful.&lt;/p&gt;
&lt;p&gt;By default the InsertNode module gets data from the $node object as defined by the system. At times, the data available in the

&lt;p&gt;&lt;a href=&quot;http://www.m2osw.com/doc-insert-node-parameter-override&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.m2osw.com/doc-insert-node-parameter-override#comments</comments>
 <pubDate>Sat, 26 Feb 2011 21:49:05 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">637 at http://www.m2osw.com</guid>
</item>
<item>
 <title>How to bypass Drupal strong security?</title>
 <link>http://www.m2osw.com/drupal-security-dodgy-patch</link>
 <description>&lt;p&gt;Interestingly enough, today I received a Security Advisory from Drupal saying that users received an email from a hacker asking them to install a Trojan &lt;em&gt;module&lt;/em&gt; on their Drupal system.&lt;/p&gt;
&lt;p&gt;I find it quite interesting since, if Drupal wasn&#039;t secure, the hackers would not have to ask you to make it unsecure, would they?&lt;/p&gt;
&lt;p&gt;However, this shows how many &lt;abbr class=&quot;mo-glossary mo-glossary-abbr&quot;  title=&quot;Content Management System&quot;&gt;CMS&lt;/abbr&gt; systems introduce a security issue problem to your web server installation since it is required to let your web server execute any one PHP file...&lt;/p&gt;
&lt;p&gt;All the files installed on your web server and that are directly accessible from the outside (i.e. ...&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.m2osw.com/drupal-security-dodgy-patch&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.m2osw.com/drupal-security-dodgy-patch#comments</comments>
 <pubDate>Fri, 18 Feb 2011 00:45:31 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">633 at http://www.m2osw.com</guid>
</item>
<item>
 <title>Fax Now Online</title>
 <link>http://www.m2osw.com/fax-now-online</link>
 <description>&lt;div class=&quot;product-info product display&quot;&gt;&lt;span class=&quot;uc-price-product uc-price-display uc-price&quot;&gt;$9.99&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;product-body&quot;&gt;&lt;p&gt;&lt;img width=&quot;209&quot; height=&quot;84&quot; border=&quot;0&quot; align=&quot;left&quot; style=&quot;margin-right: 10px; margin-bottom: 10px;&quot; title=&quot;Fax Now Online for all your facsimile needs.&quot; alt=&quot;Fax Now Online logo&quot; src=&quot;/sites/default/files/images/logo-fax-now-online-on-black.png&quot; /&gt;Yes! With &lt;a href=&quot;http://faxnowonline.com/&quot; title=&quot;Visit our Fax Now Online dedicated website.&quot;&gt;&lt;em&gt;Fax Now Online&lt;/em&gt;&lt;/a&gt;, you can send a fax from your browser or your server (using our MO&amp;nbsp;Fax &lt;abbr class=&quot;mo-glossary mo-glossary-abbr&quot;  title=&quot;Application Program Interface&quot; lang=&quot;en&quot;&gt;API&lt;/abbr&gt;) to any fax machine in the US. Easy, flexible and cheap, &lt;em&gt;Fax Now Online&lt;/em&gt; is your remote facsimile solution.&lt;/p&gt;

&lt;/div&gt;&lt;div class=&quot;product-info product sell&quot;&gt;&lt;span class=&quot;uc-price-product uc-price-sell uc-price&quot;&gt;$9.99&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;add-to-cart&quot;&gt;&lt;form action=&quot;/taxonomy/term/44/all/feed&quot;  accept-charset=&quot;UTF-8&quot; method=&quot;post&quot; id=&quot;uc-product-add-to-cart-form-618&quot;&gt;
&lt;div&gt;&lt;input type=&quot;hidden&quot; name=&quot;qty&quot; id=&quot;edit-qty-2&quot; value=&quot;1&quot;  /&gt;
&lt;input type=&quot;submit&quot; name=&quot;op&quot; id=&quot;edit-submit-618&quot; value=&quot;Add to cart&quot;  class=&quot;form-submit node-add-to-cart&quot; /&gt;
&lt;input type=&quot;hidden&quot; name=&quot;form_build_id&quot; id=&quot;form-4d13d2999be380fad436f3d870d5a45b&quot; value=&quot;form-4d13d2999be380fad436f3d870d5a45b&quot;  /&gt;
&lt;input type=&quot;hidden&quot; name=&quot;form_id&quot; id=&quot;edit-uc-product-add-to-cart-form-618&quot; value=&quot;uc_product_add_to_cart_form_618&quot;  /&gt;

&lt;/div&gt;&lt;/form&gt;
&lt;/div&gt;&lt;p&gt;&lt;a href=&quot;http://www.m2osw.com/fax-now-online&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.m2osw.com/fax-now-online#comments</comments>
 <pubDate>Mon, 15 Nov 2010 08:53:28 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">618 at http://www.m2osw.com</guid>
</item>
<item>
 <title>jsMath Security Issue</title>
 <link>http://www.m2osw.com/doc_jsmath_security</link>
 <description>&lt;h2&gt;Security Issue&lt;/h2&gt;
&lt;p&gt;A security issue was found in all versions of jsMath before 2.x-dev for Drupal 6.x of Jul 29, 2010.&lt;/p&gt;
&lt;p&gt;You may still securely use older versions of jsMath on private websites and websites were you are the only user (as in, the only one who can log in.)&lt;/p&gt;
&lt;p&gt;The Drupal Security Advisory issue is here: &lt;a href=&quot;http://drupal.org/node/854402&quot; title=&quot;http://drupal.org/node/854402&quot;&gt;http://drupal.org/node/854402&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.m2osw.com/doc_jsmath_security&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.m2osw.com/doc_jsmath_security#comments</comments>
 <pubDate>Sun, 18 Jul 2010 08:18:28 +0000</pubDate>
 <dc:creator>Alexis Wilke</dc:creator>
 <guid isPermaLink="false">561 at http://www.m2osw.com</guid>
</item>
</channel>
</rss>


