Archive - April 2007

Featured photographers required!

Posted on Wednesday, April 25, 2007

I'm looking for professional users of Pixaria to join Jason Friend as featured case studies for the new Pixaria website. If you fulfil the following criteria, please let me know by e-mail so I can assess your application.

I'm looking for photographers who use Pixaria to sell images or prints and have a customised installation with a clean and well implemented design and appearance. Your site should have been up and running for at least six months and you must be willing to allow reproduction of at least two of your images (scaled down) on this website. The site doesn't have to be in English but you must be able to provide answers to an interview questionnaire in fluent English.

To get an idea of what the case study pages will be like, check out the current profiles in the 'Pro' section.

Permalink


Forthcoming updates

Posted on Tuesday, April 17, 2007

I'm expecting to be able to release a new version of Pixaria in the next two weeks which will offer a number of minor enhancements and bugs fixes.

Two much requested changes are additions to the appearance settings control panel to allow administrators to control the default number of galleries and images per page and options for choosing the position in which watermarks are superimposed onto images.

Look out for more details coming soon.

Permalink


Update on the recent security vulnerability

Posted on Tuesday, April 17, 2007

I just wanted to post a quick message about the recent security vulnerability in Pixaria now that it's been dealt with. The issue relates to a single file in Pixaria's resources/includes/ directory called class.Smarty.php and it will only affect systems where the 'register_globals' setting for PHP is turned on.

The vulnerability allows a hacker to include and execute malicious PHP code over the internet which can then be used to give the hacker access to the affected web server as if they owned it.

The fix works by preventing the class.Smarty.php file from including remote files. The next update to Pixaria will feature changes to all include files to prevent them from being called or executed individually in this way.

Permalink


Security Vulnerability Fixed

Posted on Sunday, April 15, 2007

Users have reported a security vulnerability in Pixaria which can be exploited if PHP's register_globals variable is turned on.

My current advice is for everyone to upgrade to the newly released version 1.4.3 or if that's not possible, to install this patched file: class.Smarty.php.zip into resources/includes on your current installation.

For reference, the installation documentation of Pixaria has been updated with information on how to prevent malicious access to Pixaria's 'include' and 'libraries' scripts as this can easily be prevented by creating a text file called .htaccess with the following text in it:


Order Deny,Allow 
Deny from all 

This file should then be uploaded to:

-/resources/incoming/
-/resources/library/
-/resources/includes/
-/resources/pixies/
-/resources/smarty/

To test whether this is working on your site, browse to these directories using your web browser like this:

http://www.mysite.com/pixaria/resources/includes/

You should get an error message and access denied warning.

Permalink


Pixaria 1.4.3 fixes security vulnerability

Posted on Sunday, April 15, 2007

Pixaria Gallery version 1.4.3 is now available and is a highly recommended upgrade for ALL current users as it fixes a serious security vulnerability that can affect any installation where PHP's register_globals setting is on.

Please contact me if you're a registered user and would like the upgrade or have any other concerns. info@pixaria.com

Permalink


Pixaria progress report and site update...

Posted on Friday, April 13, 2007

Don't panic, I've not disappeared completely, I've just had to put Pixaria on hold for a bit while the company I work for relocates to new offices. It's been a bit of a nightmare getting everything sorted out but it's nearly all done and I'm looking forward to a whole week to myself very soon during which I can really crack on with Pixaria.

I've not been into the forum for a good week and a half now because if I don't answer all the posts in one hit, PHPBB stops showing me the new posts and some get left unanswered. I hope to be able to put in some time on it this weekend and respond to all the outstanding posts.

Permalink


Easter bunnies

Posted on Thursday, April 5, 2007

Just a quick post to explain why it's been quiet from me on the forums at the moment. The company I work for in my day job are relocating and as Head of Operations, it's my job to make sure it happens smoothly. As you can imagine this is a busy time for me but as soon as it's over, I'll be back on form and ready to roll with some nice new updates to both Pixaria and the Pixaria website!

Permalink


Recent Entries

Offline Until Monday February 6th
Sunday, January 29, 2012

Pixaria Opposes SOPA and PIPA
Wednesday, January 18, 2012

Pixaria Software Ltd.
Tuesday, January 3, 2012

Pixaria 3.7 Now Available
Monday, January 2, 2012

Active Directory support coming to Pixaria AssetDeck
Sunday, December 4, 2011

Follow Pixaria on Twitter
Sunday, November 20, 2011

Pixaria Gallery 3.6 Now Available
Monday, November 14, 2011

Pixaria Gallery 3.5 Now Available
Monday, October 17, 2011

Updated Translations Coming Soon
Wednesday, September 28, 2011

Pixaria 3.4 Now Available
Saturday, September 10, 2011