Posts

Showing posts with the label Security

Email sending issues

Email sending limited A client has accidentally sent spam messages via our shared hosting server and as a result, sending mail is now limited. A computer infected with a virus or malware can send thousands of spam messages undetected.  Mail internal to our server is being delivered and external mail is being delivered to the mailboxes on our server. However email from our server is not currently arriving at external mailboxes and we are working with our hosting service provider to resolve this. We cannot guarantee delivery of recent messages because they may be delayed or blocked by external servers beyond our control. Make sure to follow safe internet usage. Use virus and malware scanning software. Only use trusted software and trusted internet links even if the source appears to from someone you know. To ensure that our server does not send spam, we are limiting the number of emails that can be sent per hour.

Malware incident

A customer's WordPress website was recently infected with malware. The infection was detected by our service provider and blocked from preventing further damage. We suspect this was due to a security vulnerability in an old WordPress version, so this is a reminder to keep software up to date. Customers managing their own installation of WordPress hosted on our servers or on their own server should update using their WordPress Dashboard or contact us for assistance. Please contact us , if you want help with your WordPress blog or website.

Some sites upgraded to the latest TYPO3 versions

We have recently updated the TYPO3 core software of the websites we host for some of our customers from TYPO3 CMS 8.7.27 to TYPO3 CMS 8.7.30 and TYPO3 CMS 9.5.9 to TYPO3 CMS 9.5.13 . These versions are security and bug fix releases. For more details about the releases, please visit https://typo3.org/article/typo3-1022-9512-and-8730-security-releases-published/ . Older versions of TYPO3 are no longer supported and will not receive security updates or bug fixes. Customers who are still using TYPO3 CMS 4.5, TYPO3 CMS 4.7 or TYPO3 CMS 6.2 versions are especially encouraged to upgrade to the latest version of TYPO3 CMS 6.2 (LTS) as soon as possible, and then to the latest version of TYPO3 CMS 7 (LTS) and then onto TYPO3 CMS 8 (LTS). If you want to upgrade your TYPO3 website to the latest version or add new features, please contact us .

Some sites upgraded to the latest versions of TYPO3

We have recently updated the TYPO3 core software of the websites we host for some of our customers from TYPO3 CMS 8.7.22 to  TYPO3 CMS 8.7.24 . This is a bug and security fix release. Older versions of TYPO3 are no longer supported and will not receive security updates or bug fixes. Customers who are still using TYPO3 CMS 4.5, TYPO3 CMS 4.7 or TYPO3 CMS 6.2 versions are especially encouraged to upgrade to the latest version of TYPO3 CMS 6.2 (LTS) as soon as possible, and then to the latest version of TYPO3 CMS 7 (LTS) and then onto TYPO3 CMS 8 (LTS). If you want to upgrade your TYPO3 website to the latest version or add new features, please  contact us .

Scheduled server restart in the next two weeks

Due to a security vulnerability identified within Intel's CPUs, our service providers will apply a patch to the servers used by most of our customers and the servers will be restarted as part of this process. The timeframe for this is during the next two weeks. You will not need to do anything. You are likely to experience a short interruption of no more than 5 minutes at the end of the patching process when the servers are restarted. See https://meltdownattack.com/ for more information about the Meltdown/Spectre Vulnerability. We will post an update here when we know more about the timing of the server restart.

Security update for TYPO3 third party extension on some sites

We have updated customers' sites using the TYPO3  "News System" (news)   extension to the latest version to prevent potential information disclosure. More information on this issue is available on the  TYPO3 Security Bulletin .  If you want to upgrade your TYPO3 website to the latest version or add new features, please  contact us .

WordPress Updated

We have updated WordPress for customers where we manage their websites to the latest version:  WordPress 4.7.3 . This is a security and bug fix update. Customers managing their own installation of WordPress hosted on our servers or on their own server should update using their WordPress Dashboard or contact us for assistance. Please  contact us , if you want help with your WordPress blog or website.

Some sites updated to latest TYPO3 CMS (LTS) versions

We have recently updated the TYPO3 core software of the websites we host for some of our customers from TYPO3 CMS 6.2.25 (LTS) to  TYPO3 CMS 6.2.26 (LTS) . This is a security release. We have also recently updated the TYPO3 core software of the websites we host for some of our customers from TYPO3 CMS 7.6.9 (LTS) to  TYPO3 CMS 7.6.10 (LTS) .  This is a security release. Older versions of TYPO3 are no longer supported and will not receive security updates or bug fixes. Customers who are still using TYPO3 CMS 4.5, TYPO3 CMS 4.7 or TYPO3 CMS 6.1 versions are especially encouraged to upgrade to the latest version of TYPO3 CMS 6.2 (LTS) as soon as possible, and then to the latest version of TYPO3 CMS 7 (LTS) or TYPO3 CMS 8 (LTS). If you want to upgrade your TYPO3 website to the latest version or add new features, please  contact us .

TYPO3 Updated

Recently a critical security issue was discovered in all versions of TYPO3 core software. We have updated the TYPO3 core software of the websites we host for some of our customers from TYPO3 CMS 6.2.22 (LTS) to  TYPO3 CMS 6.2.25 (LTS) . This is a security release. We have also updated the TYPO3 core software of the websites we host for some of our customers from TYPO3 CMS 7.6.6 (LTS) to  TYPO3 CMS 7.6.9 (LTS) . This is a security release. We also applied patches to the TYPO3 Core software of the websites we host for some of our customers who are still using TYPO3 CMS 4.5, TYPO3 CMS 4.7 and TYPO3 CMS 6.1. These older versions are no longer supported and usually will not receive security updates or bug fixes, however the security fix in case was critical and patches were made available. Customers who are still using TYPO3 CMS 4.5, TYPO3 CMS 4.7 or TYPO3 CMS 6.1 versions are especially encouraged to upgrade to the latest version of TYPO3 CMS 6.2 (LTS) as soon as possible...

WordPress Updated

We have updated WordPress for customers where we manage their websites to the latest version: WordPress 4.5.2 . This is a security release. Customers managing their own installation of WordPress hosted on our servers or on their own server should update using the WordPress Dashboard or contact us for assistance. Please contact us, if you want help with your WordPress blog or website.

Security update for TYPO3 third party extension on some sites

We have updated customers' sites using the TYPO3  "Static Methods since 2007" (div2007)   extension to the latest version to prevent potential information disclosure. More information on this issue is available on the  TYPO3 Security Bulletin .  If you want to upgrade your TYPO3 website to the latest version or add new features, please  contact us .

Vulnerability protection for TYPO3 websites using ImageMagick

The latest TYPO3 security bulletin identified a vulnerability with the third-party ImageMagick software that TYPO3 uses for image processing. We have reconfigured all TYPO3 websites of our customers to use the safer GraphicsMagick (most sites were already using GraphicsMagick). If you experience any problems which may or may not be related to this maintenance, please contact us .

Server maintenance

A patch was applied today to a server hosting many of customers to protect against vulnerability (CVE-2016-0800) in the SSLv2 protocol, which could allow an attacker to compromise the security of encrypted connections to or from our server. This required a server restart and as a result one of our database servers did not restart automatically. This has been resolved and everything on the server should be working normally now. We apologize for any inconvenience. If you experience any problems which may or may not be related to this maintenance, please contact us .

Some sites updated to latest TYPO3 CMS (LTS) version

We have updated the TYPO3 core software of the websites we host for some of our customers from TYPO3 CMS 6.2.17 (LTS) to TYPO3 CMS 6.2.18 (LTS) . This is a maintenance release containing bug and security fixes.  TYPO3 CMS 6.2.18 (LTS) is now the latest long term support version of TYPO3 for existing projects and we recommend that customers contact us to upgrade to this version for long term security and new features.  Customers who are still using TYPO3 CMS 4.5, TYPO3 CMS 4.7 or TYPO3 CMS 6.1 versions are especially encouraged to upgrade to TYPO3 CMS 6.2.18 (LTS) as soon as possible. These old versions are no longer supported and will not receive security updates or bug fixes. Customers looking for new TYPO3 features should upgrade to TYPO3 7.6.3 LTS . This requires an upgrade to TYPO3 6.2.17 LTS first. If you want to upgrade your TYPO3 website to the latest version or add new features, please contact us .

Third party extension removed from some TYPO3 sites

To prevent Cross-Site Request Forgery, we have removed the third party TYPO3 t3_quixplorer extension from the websites of customers who had this installed. This extension was only available for users with administration rights and is not required for maintaining or operating the websites. More information on this issue is available on the TYPO3 Security Bulletin . If you want to upgrade your TYPO3 website to the latest version or add new features, please contact us .

WordPress updated

We have updated customers using WordPress to the latest security release version: WordPress 4.3.1 . Please contact us , if you want help with your WordPress blog or website.

Some sites updated to latest TYPO3 CMS (LTS) version

We have updated the TYPO3 core software of the websites we host for some of our customers from TYPO3 CMS 6.2.14 (LTS) to TYPO3 CMS 6.2.15 (LTS) . This is a update contains security and bug fixes. TYPO3 CMS 6.2.15 (LTS) is now the latest long term support version of TYPO3 and we recommend that customers contact us to upgrade to this version for long term security and new features. Customers who are using TYPO3 CMS 4.5, TYPO3 CMS 4.7 or TYPO3 CMS 6.1 versions are especially encouraged to upgrade to TYPO3 CMS 6.2.15 (LTS) as soon as possible. If you want to upgrade your TYPO3 website to the latest version or add new features, please contact us .

WordPress updated

We have updated customers using WordPress to the latest  WordPress 4.2.4 Security and Maintenance Release . Please  contact us , if you want help with your WordPress blog or website.

WordPress updated

We have updated customers using WordPress to the latest WordPress 4.2.3 Security and Maintenance Release . Please contact us , if you want help with your WordPress blog or website.

Security update for some TYPO3 websites

To apply security fixes, we have updated the TYPO3 CMS core software on our customers' websites that are using TYPO3 CMS 6.2.x (LTS) to the latest version. More information about these security updates is available at: http://typo3.org/teams/ security/security-bulletins/ typo3-core/typo3-core-sa-2015- 002/ http://typo3.org/teams/ security/security-bulletins/ typo3-core/typo3-core-sa-2015- 003/ http://typo3.org/teams/ security/security-bulletins/ typo3-core/typo3-core-sa-2015- 004/ http://typo3.org/teams/ security/security-bulletins/ typo3-core/typo3-core-sa-2015- 005/ http://typo3.org/teams/ security/security-bulletins/ typo3-core/typo3-core-sa-2015- 006/ http://typo3.org/teams/ security/security-bulletins/ typo3-core/typo3-core-sa-2015- 007/ TYPO3 CMS 6.2.13 LTS is now the latest long term support version of TYPO3 and we recommend that customers contact us to upgrade to this version for long term security and new features. Customers who are using TYPO3 CMS 4.5, TYPO3 CMS ...