Closed (won't fix)
Project:
Drupal.org project ownership
Component:
Ownership transfer
Priority:
Normal
Category:
Support request
Assigned:
Unassigned
Reporter:
Created:
3 Feb 2011 at 16:08 UTC
Updated:
9 May 2014 at 00:31 UTC
Jump to comment: Most recent
Comments
Comment #1
itzcoatl commentedIm in shock too, I was planning a Videogame community site with OG and OG_Forum....
Im java developer but I have null Experiencie with PHP and I cant offer myself to fix the vulnerabilities discovered by th security team.
Please someone fix it...
OG_FORUMs FTW :)
Comment #2
daniel wentsch commentedsubscribing
Comment #3
McGrimm commentedsubscribing
Comment #4
crifi commentedI just want remind to the process for taking over abandoned projects with security issues:
(see: http://drupal.org/node/251466)So we need a patch first and I'm also interested in getting a secure version again. But I don't want obtrude me on taking over this project. ;-) So if pumpkinkid is ready it would be a pleasure! I can help to review, write and evolve the patch.
Comment #5
pumpkinkid commentedYes, I did see that, but I still don't have a patch for it...
I plan on spending some time looking at the source code tonight and see what we can do.
Here is the exact Security Warning:
OG Forum does not properly implement access controls on private forums it creates, which can lead to a private group's forums becoming public via Cross Site Request Forgeries (CSRF). Additionally, OG Forum stores private group and forum information in a global vocabulary, which can lead to information such as group and forum names being disclosed to members not part of the private group.
If you have time to take a look let me know what you find, I wouldn't mind additional help in getting the module to not be a security issue.
Comment #6
crifi commentedOG Forum updates public/private status direct over a HTTP Request (Link in the Admin UI) ...
Therefore I can send you a mail or redirect a URL of my server to a special prepared link (with the exact IDs) to get the forum accessible for the public. A good solution you can find in OG itself http://example.com/og/users/1 when giving membership or revoke it to/from a user.
Comment #7
AntiNSA commented+1
Comment #8
baff commentedsubscribe
Comment #9
spidersilk commentedI'd be happy to help on this in any way I can. I'm not an expert on PHP security, but I do have some experience, and would be happy to assist pumpkinkid or anyone else working on this with testing or anything else you'd like me to do. I'll be looking over the module code as well...
Comment #10
Media Crumb commentedWow this is a shock. I really hope we can get a fix together. This module is a must for almost all my client sites as well... :\
Comment #11
pumpkinkid commentedLove the help pouring in. Definitely appreciate it! Glad I'm not the only one that thought this module needed saving :-)
Comment #12
Drake commentedHi
I'm interesting in this module too.
At this time I'm using the 6.x1.4 version since the 6.x-2x prevent the user to create posting if the forum is mixed in organic group forums and general forums.
Unfortunatelly I have little PHP skils so cannot provide many help, but i would test the new version.
PS: It's really sad that the maintainer paul booker given up this project... very very bad...
Comment #13
MiniMax commentedsubscribe
Comment #14
rismondo commentedSubscribing!
Comment #15
thepanz commentedSubscribe!
@Drake: I've posted a patch for 2.x-dev fixing (maube it still needs some test) the issue with OG.
@crifi: maybe adding a FORM to edit such private/public visibility could be the solution. Could you point me to the right code line? I'll work on that issue ASAP.
ps: I'd like to help in co-maintaining this module too.
Comment #16
Drake commented@thePanz
You mean this patch?
http://drupal.org/files/issues/og_forum-651672-67.patch
I will test it imadiatelly and will share my experience with that...
Comment #17
thepanz commented@Drake: yep! waiting for your comments on the issue thread!
Comment #18
steve.m commented+1
We are actively developing a site that relies on og_forum and can very likely contribute some coding hours if needed.
Comment #19
mducharme commentedsubscribing
Comment #20
crifi commentedI've written a fix for the CSRF. Since this issue here is a "offering maintain" request I've opened a new issue here: #1055424: SA-CONTRIB-2011-004. Please help and review the patch, thanks!
Comment #21
pumpkinkid commentedNice! Taking a look at it now.
Comment #22
Drake commented@thePanz
I've checked the newest 6.x-2x-dev and your patch was already included.
Then I replaced the v6.14 with 6.x-2x-dev and have some problems.
1) I created every forum through the "OG_forum create" option which can be found in the og_group detail block.
I did it using the 6.x-1.4 version.
My forum path to a single forum was; mysite/forum/container/og_forum1
Now using 6.x-2x-dev, the forums in group has an path: mysite/og/container/og/forum
The page mysite/og/container/og/forum shows all the forums in the single group but if I try to access the particular forum in the group (path: mysite/forum/container/og_forum1) then the forum cannot be accessed... the whole page freezes and crashes...
2) If I access the Forum from main page mysite/forum then all forums (og forums) are visible and listed but if I try to access any forum (path: mysite/forum/container/og_forum1) then the page freezes and crashes again....
I think this is caused by 'wrong' forum links... i think this has been changed in 6.x-2x-dev
PS: I use forum access module too...
Unfortunatelly, i cannot delete all the forums and cannot create it again becasue all my posting would be lost and could not be assigned again to the single group forums.
Comment #23
thepanz commented@Drake: I can confirm the crash. Please refer to the issue #1056428: Apache crash when visiting forum/TID I've just opened (with solution).
Comment #24
Drake commented@thePanz
I tested the new patch and it works!!!
Thenks to all you efforts!
It's great to see that there are people who want get this module working and keep developing on this module.
Now I'm using the og_forums 6.x-2x-dev in connection with advanced_forum-6.x-2.0-alpha3 and forum_access-6.x-1.5 and it seems to work!
Great work.... now we need only an patch to get the og_forums secured!
Comment #25
mreyher commentedsubscribe
Comment #26
Media Crumb commentedSo nice to see people coming to the aid of a great mod. I'll do whatever I can (not a php wiz) to help keep it alive. Maybe sponsor some code to get the bugs out?
Comment #27
kathrynrtb commentedsubscribing
Comment #28
rkdesantos commentedsubscribing
Happy to test once a fix is in the dev version. Thanks.
Comment #29
jen.c.harlan commentedsubscribing...
Thanks for all the great work guys. I was updating modules on my site tonight and went into a complete panic when I saw the message on my updates report page. Seeing this thread has made me feel much better. :)
Comment #30
haaid commentedsubscribing
Comment #31
murias commentedSub
Comment #32
nigelcunningham commentedSubscribing. Would love to help, but I'm spread far too thinly already.
Comment #33
titouilleSubscribing
Comment #34
crifi commentedPlease guys, if you really want to help and you have the skills don't only subscribe to this issue or offer your help here. Go to #1055424: SA-CONTRIB-2011-004 instead and help to complete the patch there! Otherwise we will have this situation: http://www.corsinet.com/braincandy/hlife.html ;-)
Comment #35
Julie Henn commentedsubscribe
Comment #36
Anonymous (not verified) commentedHi Drake,
I haven't given up on the project. The last conversation i had with Ryan (current / previous) maintainer was that he was going to look into the security problems. I'll be looking into this problem next week and would like to step up as project maintainer for this module moving forward.
Thoughts:
After the restoration of this module I would like to open a discussion with Moshe to see what needs to be done in order for the functionality provided by this module to be included along with the OG module.
Best,
Paul Booker
Appcoast
Comment #37
pumpkinkid commentedHey Paul,
No contest from me! If you are willing and have talked to the previous maintainer than by all means go ahead and carry on with the module... let us know what we can do to help.
Comment #38
eleben commentedsubscribing
Comment #39
Anonymous (not verified) commentedComment #40
pumpkinkid commentedThe OG Forum module has been abandoned for quite some time with considerable amount of support requests from users that are interested in seeing the current security issue resolved. (http://drupal.org/node/1048906). I had backed off from my initial request to take ownership of this module considering that additional interest in restoring this modules came from users other than myself.
Considering that the CSRF part of the security issue has been resolved and confirmed to be working as per (http://drupal.org/node/1055424) and that there has been a lot of work done to correct the second part of the security issue, I request access to maintain this module so that I can apply the patch and continue working on the outstanding issues related to this module.
Comment #41
Scyther commentedsubscribing
Comment #42
Media Crumb commentedPlease let pumpkinkid take over the support of OG forum!
Comment #43
River Donkey commentedSubscribing - really want to see tgus module working again :)
Comment #44
Drake commentedI've given up this module... have replaced this OG-forum using a solution: views, taxonomy
Comment #45
Media Crumb commentedHas pumpkinkid been given this project to maintain?
Comment #46
avpadernoThe project page is http://drupal.org/project/og_forum.
Has anybody of the security team been contacted about the module?
Comment #47
pumpkinkid commented@Media Crumb Not to my knowledge... lol I have however been out on vacation for a while so I'm just now trying to catch up!
Comment #48
Media Crumb commentedLets hope we can move on soon then
Comment #49
pumpkinkid commentedI'm bowing out of the resolution to this module, considering I seem to have a different idea of how it should be allowed to work.
Comment #50
Media Crumb commentedhow sad.