stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Safari Newsflash: PHP-Nuke Cookie Bug Fixed







Safari Newsflash: PHP-Nuke Cookie Bug
Fixed

Safari Newsflash: PHP-Nuke Cookie Bug
Fixed
03/19/2003 10:28 PM

Maciej fixed the infamous cookie bug last night, so PHP-Nuke sites will now work properly. Quoting Maciej:

I have a fix for the infamous PHP-Nuke login bug. It should be in the next release. Here's the short version: the Netscape cookie spec says when a cookie comes from a URL like "http://www.foo.com/user.php" and no path is explicitly specified, then the path should default to "/user.php". However, it actually needs to default to "/", because that's what all real browsers do. Don't you love the web?

Another bug bites the dust! :)




This is a GrokNews Entry: (what is grok?)





Similar Items

Safari Newsflash: PHP-Nuke Cookie Bug Fixed

Grok Headline matches for Safari Newsflash: PHP-Nuke Cookie Bug Fixed

Safari Newsflash: WebCore Update


Safari Newsflash: WebCore Update 03/11/2003 09:44 AM

Some more issues I fixed tonight:

  1. Added support for attr to the content property.
  2. Fixed dotted/dashed border drawing to draw the correct type of border (and in the right position).
  3. Implemented the CSS3 :target selector.

Safari Newsflash: CSS Parser Integrated


Safari Newsflash: CSS Parser Integrated 03/11/2003 09:44 AM

I have integrated the CSS parser from the KHTML trunk into Safari. It uses the CSS2.1 grammar. Mark will no doubt be disappointed that it closes most of the sheet-content-related hacks. In particular, Safari is no longer vulnerable to the Safari Spacer hack, the Simplified Box Model Hack, the Star HTML bug, or the Inline High Pass filter. It is, however, still vulnerable (interestingly) to Fabrice's Inversion.

Note that some of these hacks really couldn't easily be left in, since using a correct grammar will just naturally close these hacks off. There's no way to easily pollute the grammar to support constructs like the Safari Spacer hack (nor should we).


Safari's cookie bug fixed


Safari's cookie bug fixed 03/19/2003 10:25 PM
Dave Hyatt reports: Maciej fixed the infamous cookie bug last night, so PHP-Nuke sites will now work properly. Quoting Maciej... I have a fix for the infamous PHP-Nuke login bug. It should be in the next release. Here's the short version: the Netscape cookie spec says when a cookie comes from a URL like "http://www.foo.com/user.php" and no path is explicitly specified, then the path should default to "/user.php". However, it actually needs to default to "/", because that's what all real browsers do. Don't you love the web? (from Surfin' Safari)

Safari 1.1 Cookie Theft


Safari 1.1 Cookie Theft 11/19/2003 06:53 PM
(MacInTouch via MyAppleMenu)

Multiple vulnerabilities PHP-Nuke Video
Gallery Module for PHP-Nuke


Multiple vulnerabilities PHP-Nuke Video
Gallery Module for PHP-Nuke
04/27/2004 12:59 PM
k1LL3r B0y (Apr 26 2004)

Photoshop Newsflash


Photoshop Newsflash 08/27/2004 01:33 PM

The Onion | America's Finest News Source: Pretty funny sidebar headline on The Onion:

Photoshop Actually Bought

Now that would be news. I thinking Photoshop is the most pirated app in the world.

Click here to comment on this entry


Newsflash: Mini Better Than Budget-Box
PC!


Newsflash: Mini Better Than Budget-Box
PC!
03/17/2005 04:12 AM

Newsflash: Longhorn, Blackcomb Plans in
Flux


Newsflash: Longhorn, Blackcomb Plans in
Flux
03/20/2003 11:56 AM

Newsflash: Gourmet Coffees Have Lots Of
Caffeine


Newsflash: Gourmet Coffees Have Lots Of
Caffeine
05/19/2004 06:03 PM

Safari Magic 1.0 adds numerous tools to
Safari


Safari Magic 1.0 adds numerous tools to
Safari
07/20/2004 02:43 AM
Stephen Becker has announced the release of Safari Magic 1.0, a utility which adds several tools to Safari...

Cookie Jar


Cookie Jar 12/11/2002 08:09 AM
This class should be used to handle cookies (storing cookies from HTTP response messages, and sending out cookies in HTTP request messages). This class is mainly based on Cookies.pm from the libwww-perl collection . Unlike Cookies.pm, this class only supports the Netscape cookie spec , not RFC 2965.

A Fortune For This Cookie


A Fortune For This Cookie 04/30/2004 04:23 PM
P.F. Chang's has one delectable menu, but is its stock price as palatable?

Why is there a part of a cookie here?


Why is there a part of a cookie here? 01/16/2004 01:00 PM
Made one mitten, mitten too small...damn it. Back to the drawing board for that one. Wendy's scarf has been...completed! (said...

I Don't Want a Cookie, Mom, Can I Just
See the Box? (Reuters)


I Don't Want a Cookie, Mom, Can I Just
See the Box? (Reuters)
04/16/2004 08:53 AM
Reuters - It looks like an ordinary old-fashioned cookie tin, but the hidden drawing of two dogs having sex in the grass makes it an instant collectors' item.

Bad Provider. No Cookie.


Bad Provider. No Cookie. 04/26/2004 10:25 AM

Netcraft reports that a hosting provider in San Diego got busted for sniffing for the Google spider and feeding it phony links to their own web site whenever it indexed any of the sites they hosted.

Aplus.Net admitted Friday that it had manipulated customer web sites to try and improve its ranking in the Google search engine, inserting "hidden links" that made it appear that more than 17,000 sites were linking to Aplus.net's home page. The technique may have helped Aplus.net achieve a first-place Google ranking for the term "dedicated servers."

While it's a low-down dirty trick, you have to marvel at the ingenuity.

Click here to comment on this entry


Update: Cookie Dog 2.0


Update: Cookie Dog 2.0 01/23/2004 02:21 PM
Cookie Dog is a cookie manager for Internet Explorer, Safari, Mozilla/Netscape, Camino, and Omniweb.

Brownie - Beyond Cookie


Brownie - Beyond Cookie 08/06/2004 03:07 PM
The Brownie Project has started!

Cookie Path Best Practice


Cookie Path Best Practice 07/01/2004 06:56 AM

Mac Gems: Cookie Cutter


Mac Gems: Cookie Cutter 03/31/2005 09:40 AM
Manage Safari's cookies with Cookies Eater

Gizmodo Fortune Cookie


Gizmodo Fortune Cookie 08/02/2004 02:08 PM

All car stereos should have 1/4-inch stereo miniJack inputs.


Only four EU countries enacted cookie
directive


Only four EU countries enacted cookie
directive
11/03/2003 06:33 AM
Computer Weekly Nov 3 2003 6:11AM ET

CNN.com - Has Cookie Monster given up
sweets? - Apr 7, 2005


CNN.com - Has Cookie Monster given up
sweets? - Apr 7, 2005
04/08/2005 08:11 PM

Notes and Tips: MSN Cookie Problem


Notes and Tips: MSN Cookie Problem 06/07/2004 10:24 AM
MSN's cookie tricks can keep you from signing out successfully in Safari.

Top UK sites 'do not comply' with
anti-cookie law


Top UK sites 'do not comply' with
anti-cookie law
12/15/2003 09:24 AM
ZDNet UK Dec 15 2003 8:47AM ET

Judge: Cookie Gesture Wasn't Campaigning
(AP)


Judge: Cookie Gesture Wasn't Campaigning
(AP)
01/22/2004 02:10 AM
AP - Carson's cookie case crumbled.

'I wrote it in bed with my computer on a
cookie sheet'


'I wrote it in bed with my computer on a
cookie sheet'
05/15/2004 08:44 AM
National Post May 15 2004 1:27PM GMT

Word of mouth and how the cookie
crumbles


Word of mouth and how the cookie
crumbles
09/09/2004 11:10 AM
From The Center for Media Research.... BuzzMetrics, a company specializing in word of mouth research and planning, released a new report revealing how word of mouth and online discussion forums shaped a food-industry crises. When a leading consumer advocacy group filed a lawsuit against food giant Kraft over its use of partially-hydrogenated oils in Oreo cookies, a frenzy erupted across thousands of consumer online discussion platforms. According to BuzzMetrics' analysis of over 2.6 million comments from over 120,000 consumers, the Ban Trans Fats legal assault on Oreo caused the total volume of online discussions on trans fats to increase more...

Cookie fans chip away at spyware bill


Cookie fans chip away at spyware bill 02/05/2005 09:08 PM
Lawmakers consider bowing to Web marketers' pressure not to designate cookies as unlawful technology under an anti-spyware bill.

Cookie Delivery Sparks $900 Medical
Bill (AP)


Cookie Delivery Sparks $900 Medical
Bill (AP)
02/05/2005 09:23 PM
AP - Two teenage girls who surprised their neighbors with homemade cookies late one night were ordered to pay nearly $900 in medical bills for a woman who says she was so startled that she had to go to the hospital.

Avoid a cookie bug in Safari's reset
feature


Avoid a cookie bug in Safari's reset
feature
05/20/2004 11:45 AM
Here's a bug in Safari -- it doesn't actually reset your cookies unless you open the Preferences -> Show Cookies window. Here's a proof ... open Safari and navigate to a few sites that you know stores a cookie (Google, Mac OS...

"Teens' cookie deliveries crumble into
$900 lawsuit"


"Teens' cookie deliveries crumble into
$900 lawsuit"
02/07/2005 02:02 AM

Intel caught with hand in 4U Opteron
cookie jar


Intel caught with hand in 4U Opteron
cookie jar
12/15/2003 09:20 AM

Meet the new, dietetically correct
Cookie Monster


Meet the new, dietetically correct
Cookie Monster
04/08/2005 12:54 AM
Xeni Jardin: Geez, talk about sucking all the fun out of life. Cookie Monster will be cutting back on sweets as part of a new healthy eating program on Sesame Street. The googly-eyed, blue fuzzball will learn that "A Cookie Is a Sometimes Food." What next, a song called "C is for Celery?"
Link (Thanks, jodyh)

Sexy Cookie Tin Snapped Up at Auction
(Reuters)


Sexy Cookie Tin Snapped Up at Auction
(Reuters)
04/26/2004 09:02 AM
Reuters - An otherwise ordinary cookie tin featuring hidden drawings of two dogs mating and a pair of naked lovers fetched 423 pounds ($752) at an English auction Friday -- proving that sex sells.

seattlepi.com Buzzworthy: Cookie Monster
caves


seattlepi.com Buzzworthy: Cookie Monster
caves
04/11/2005 03:49 AM
We should respond with a massive cookie binge fest! .. Cookie Monster caves .. change his name

blog.seattlepi.nwsource.com/buzz/archives/004630.html
track this site | 4 links


Fortune Cookie Fulfills Lottery Destiny
(AP)


Fortune Cookie Fulfills Lottery Destiny
(AP)
03/31/2005 07:46 PM
AP - Dozens of people recently got an extra-special dessert with their Chinese food: a winning lottery number.

Member Forum Spotlight:Cookie Monster's
Den


Member Forum Spotlight:Cookie Monster's
Den
03/31/2005 12:25 PM
geehumshriber's Member Forum, Cookie Monster's Den, is a place to "have fun, enjoy your time, meet new friends, get free cookies." Check it out!

Data center firms settle cookie suit


Data center firms settle cookie suit 09/16/2004 08:36 PM
F5 Networks and Radware have come to terms in a patent dispute over "cookie persistence" technology.

Netegrity SiteMinder Affiliate Agent
Cookie Overflow


Netegrity SiteMinder Affiliate Agent
Cookie Overflow
04/23/2004 04:10 PM
advisories_at_atstake.com (Apr 22 2004)
Grok Description matches for Safari Newsflash: PHP-Nuke Cookie Bug Fixed
GrokA matches for Safari Newsflash: PHP-Nuke Cookie Bug Fixed

Use Safari with Novell Groupwise
WebAccess


Use Safari with Novell Groupwise
WebAccess
02/11/2004 11:04 AM
There is a known issue with using Novell Groupwise WebAccess with Safari. There is a toolbar that is supposed to appear on the left hand side of the screen that fails to appear when using Safari. I've found that if you click ...

Create Safari cookies that expire after
each session


Create Safari cookies that expire after
each session
10/30/2003 12:37 AM
In Mozilla and variants, and many other browsers, you can set Cookies to expire at the end of the session. This means that Cookies will be kept for your use, until you close your browser and they are then wiped out. I like t...

ID Backup to Cookies Will Also Restore
Erased Cookies


ID Backup to Cookies Will Also Restore
Erased Cookies
04/03/2005 10:42 AM
Technology News Daily Apr 3 2005 1:33PM GMT

HTTP-Cookies-Safari-1.06


HTTP-Cookies-Safari-1.06 09/21/2004 12:54 AM

Safari cookies may fail with future
dates


Safari cookies may fail with future
dates
03/08/2004 11:18 PM
This is more of a solution, than a hint. A few days ago I encountered a problem with Safari, specifically, many sites that requires stored cookie to log in refuses to log in. I tried to reset Safari's settings. No effect. No...

Security Update Offers Safari Cookies
Fix


Security Update Offers Safari Cookies
Fix
12/05/2003 07:51 PM
By Peter Cohen (MacCentral via MyAppleMenu)

Security update offers Safari cookies
fix


Security update offers Safari cookies
fix
12/05/2003 03:12 PM
Apple on Friday released Security Update 2003-12-05. The new update is available for download through the Software Update system preferences pane.

Eolas Patent Invalid


Eolas Patent Invalid 03/06/2004 02:01 AM
A federal patent examiner's initial review has found the Web browser patent at the center of a major verdict against Microsoft Corp. to be invalid.

AdSense - Worrying About Invalid Clicks


AdSense - Worrying About Invalid Clicks 07/18/2004 07:15 AM
The hot topic for AdSense for the summer has be ClickBots, Invalid Clicks, and competitors getting you booted out of the program. This is but one of dozens of threads on the topic.

Use JavaScript to implement multiple
session ID cookies


Use JavaScript to implement multiple
session ID cookies
08/10/2002 10:53 PM
CNET Aug 10 2002 10:14PM ET

Uzbek Internet provider tender invalid


Uzbek Internet provider tender invalid 05/27/2004 03:23 AM
Interfax Information Agency May 27 2004 7:05AM GMT

Rambus Patent Ruled Invalid In Europe


Rambus Patent Ruled Invalid In Europe 02/13/2004 04:03 PM
Rambus' legal action against memory maker Micron appears to have had the rug pulled from under its feet this week when the European Patent Office said it will revoke one of the company's patents.

"news of a little girl who had her first
Communion declared invalid"


"news of a little girl who had her first
Communion declared invalid"
08/18/2004 08:34 PM

Invalid Windows CE Setup Files During
Installation


Invalid Windows CE Setup Files During
Installation
05/25/2004 08:42 AM

Invalid Page Fault in module THUMBVW.DLL
or KERNEL32.DLL


Invalid Page Fault in module THUMBVW.DLL
or KERNEL32.DLL
12/31/2004 12:32 PM
Tech-Recipes Dec 31 2004 4:56PM GMT

Xerox Patent Ruled Invalid, palmOne
Exonerated


Xerox Patent Ruled Invalid, palmOne
Exonerated
05/22/2004 10:01 AM

Judge rules Lindows-backed refund site
invalid


Judge rules Lindows-backed refund site
invalid
01/16/2004 01:00 PM
A judge has now ruled that the administrator in the settlement deal must ignore claims filed through MSfreePC.com. In a move of typical legal efficiency, the rejections are really only half-rejections.

ISA Server 2000 Hotfix for FTP Client
Invalid PORT Command


ISA Server 2000 Hotfix for FTP Client
Invalid PORT Command
12/12/2003 10:29 AM
This hotfix verifies that the IP address and port specified in an FTP client PORT command are appropriate to the current FTP session in both inbound and outbound FTP sessions.

PHP Blog: feof() doesn't return TRUE
when invalid file handle is passed to it


PHP Blog: feof() doesn't return TRUE
when invalid file handle is passed to it
05/17/2004 07:34 PM
When a fopen() is done on a file that has permissions that are set to not allow the current process user to read it or the file doesn\'t exist it returns false. This is expected. The problem is when feof() is fed the invalid handle it doesn\'t return TRUE() thus creating an infinite loop in the following code example. feof() would return TRUE to cancel the loop and the script would end. There would of course be warnings because of the invalid file handle, but that is expected. There should be better error handling on the developers part and catch the invalid file handle, but I would expect the file functions to handle this situation accordingly.

Samba nmbd Invalid Length Denial of
Service Vulnerability [iDEFENSE]


Samba nmbd Invalid Length Denial of
Service Vulnerability [iDEFENSE]
09/13/2004 04:31 PM
Jérôme (Sep 13 2004)

Vulns: Microsoft Exchange Server Invalid
MIME Header charset = '' DoS
Vulnerability


Vulns: Microsoft Exchange Server Invalid
MIME Header charset = '' DoS
Vulnerability
04/16/2004 11:40 PM
SecurityFocus Apr 17 2004 2:51AM GMT

A session folder without cookies, based
in
http://www.zope.org/Members/czimmet/Cook
ieLess by jmunoz on 2002/08/08


A session folder without cookies, based
in
http://www.zope.org/Members/czimmet/Cook
ieLess by jmunoz on 2002/08/08
08/08/2002 11:58 AM

Cookies in PHP


Cookies in PHP 01/28/2004 12:05 AM
For those new to web development and 'how things work', cookies can be a very confusing matter. In this tutorial, Timothy gives you an overview of cookies to help you understand how they work.

Watch Your Cookies...


Watch Your Cookies... 09/09/2004 11:51 PM

Bukkake Cookies


Bukkake Cookies 04/15/2005 11:59 AM
Xeni Jardin: Recipe here:
Link


FeedDemon, RSS and cookies


FeedDemon, RSS and cookies 08/18/2004 10:25 AM

I've recently had a a few people ask whether FeedDemon supports the use of cookies, and the answer is, "yes, it does."

The most obvious use of this is to require a login before returning any information, and I've seen this done by several feeds already. Unfortunately, some of them redirect to an HTML page when the login cookie isn't found, which obviously won't work since FeedDemon is trying to download RSS, not HTML. So, if you use cookie-based authentication, don't redirect to an HTML page - instead, dynamically create an RSS <item> which includes a link to the login page.


Are you deleting your cookies?


Are you deleting your cookies? 04/08/2005 06:36 PM

Apparently most people are pretty sick of cookies and 58% of people are deleting them almost as fast as websites try to force them on you. Seems Marketers have responded and are using other ways to track what people are doing through. Persistent Identification Element (PIE)that uses a technology that is tied to Macromedia's Flash MX, which is able to track your every move. Here is how to disable their dirty little trick. [Macromedia]

Kinda Ironic isn't it Cookies and now Pie (Geez)


New law on cookies takes the biscuit


New law on cookies takes the biscuit 12/12/2003 10:26 AM
Personal Computer World Dec 12 2003 9:16AM ET

Protecting Cookies from Deletion


Protecting Cookies from Deletion 03/31/2005 12:24 AM

3g Buy Of Scout's Fortune Cookies


3g Buy Of Scout's Fortune Cookies 03/14/2005 06:28 PM
New York Post Mar 14 2005 4:27PM GMT

Safari Newsflash: PHP-Nuke Cookie Bug Fixed

The following phrases have been identified by the grok system as matching this entry: phpnuke cookie functions seem to be disabled. groupwise email invalid or missing cookies "favorite icon" safari "invalid or missing cookies" "safari 2.0" cookies bug "invalid or missing cookies)" groupwise webaccess invalid or missing cookie(s) maciej wwdc session "groupwise webaccess" and "invalid or missing cookies"

















Also check out: