<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0">
<channel>
<title>News</title>
<link>http://www.neocrome.net</link>
<description></description>
<ttl>1</ttl>
<item>
 <title>New Seditio licensing system &amp; v125</title>
 <description>From now (This is not an April Fool's joke), the Seditio Commercial Licence and Copyright Removal are merged into a single kind of licence, the Seditio Licence. The base pricing of this licence is lowered from 30 to 25 Euros, and the Reseller Licence Owners will get a 20% discount, so that's 20 € per extra licence.&lt;br /&gt;
&lt;br /&gt;
The goal is to make the Licensing system easier to understand and more fair for our loyal contributors and resellers. And the price is lowered to take into account the recent EURO/USD balance.&lt;br /&gt;
&lt;br /&gt;
All existing licences in our database will be converted to the new single type.&lt;br /&gt;
The Services area will soon be updated with all these changes.&lt;br /&gt;
&lt;br /&gt;
And more news from the &quot;coding frontline&quot;, the next Seditio build is on it's way, it will be numbered 125, stay tuned for more details !</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2360</link>
 <pubDate>Tue, 01 Apr 2008 12:39:00 -0400</pubDate>
</item>
<item>
 <title>Search plugin, security patch</title>
 <description>It's recommended to all Seditio v121 users to re-download the v121 package, and replace the file &lt;strong&gt;plugins/search/search.php&lt;/strong&gt; as soon as possible, it will fix a potntial SQL injection.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;a href=&quot;page.php?al=seditio&quot;&gt;Download Seditio v121 here !&lt;/a&gt;&lt;/strong&gt;</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2349</link>
 <pubDate>Fri, 30 Nov 2007 09:21:47 -0500</pubDate>
</item>
<item>
 <title>Seditio v121, security patch</title>
 <description>It's recommended to all Seditio v121 users to re-download the v121 package, and replace the file &lt;strong&gt;system/functions.php&lt;/strong&gt; as soon as possible, it will fix a security issue about ASCII chars and HTML code execution in user submitted forms.&lt;br /&gt;
&lt;br /&gt;
Thanks to Yasebo, Kilandor, Orkan and Spartan for their contributions on the reports and the fix(es). &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;a href=&quot;page.php?al=seditio&quot;&gt;Download Seditio v121 here !&lt;/a&gt;&lt;/strong&gt;</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2344</link>
 <pubDate>Fri, 12 Oct 2007 08:17:00 -0400</pubDate>
</item>
<item>
 <title>Seditio v121 released</title>
 <description>There's a new build for Seditio available :&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;a href=&quot;page.php?al=seditio&quot;&gt;Download Seditio v121 here !&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The list of the changes is in the &lt;a href=&quot;plug.php?e=tracker&amp;m=project&amp;pr=1&amp;fixedin=121&quot;&gt;project tracker&lt;/a&gt;.&lt;br /&gt;
This release is ONLY made of bug fixes in the system files, it's a recommended upgrade.&lt;br /&gt;
&lt;br /&gt;
Please note that despite the core code being numbered &quot;121&quot;, it will run all plugins and skins made for any previous version (100, 101, 102, 110 or 120). You don't have to upgrade your current v1xx skins or plugins, only changes are in the system files.&lt;br /&gt;
&lt;br /&gt;
Thanks to all the reporters and contributors !</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2286</link>
 <pubDate>Sun, 18 Mar 2007 22:34:00 -0400</pubDate>
</item>
<item>
 <title>Seditio v120</title>
 <description>There's a new build for Seditio available :&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;a href=&quot;page.php?al=seditio&quot;&gt;Download Seditio v120 here !&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
The list of the changes is in the &lt;a href=&quot;plug.php?e=tracker&amp;m=project&amp;pr=1&amp;fixedin=120&quot;&gt;project tracker&lt;/a&gt;, and few more details in the &lt;a href=&quot;page.php?al=hist120&quot;&gt;history log&lt;/a&gt;.&lt;br /&gt;
This release is moslty made of bug fixes, none were critical.&lt;br /&gt;
Still, it's a recommended upgrade.&lt;br /&gt;
&lt;br /&gt;
Please note that despite the core code being numbered &quot;120&quot;, it will run all plugins and skins made for any previous version (100, 101, 102 or 110). Said another way, you don't have to upgrade your current v10x skins or plugins, only changes are in the system files and in the SQL structure.&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Edit :&lt;br /&gt;
&lt;br /&gt;
If you downloaded the new package before this notice, re-download and replace the files :&lt;br /&gt;
&lt;br /&gt;
- system/common.php&lt;br /&gt;
- system/functions.php&lt;/em&gt;</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2281</link>
 <pubDate>Thu, 15 Mar 2007 21:01:00 -0400</pubDate>
</item>
<item>
 <title>Seditio v110, security patch #2</title>
 <description>It's recommended to all Seditio v110 users to upload and replace the 5 files from &lt;a href=&quot;page.php?al=sed110patch&quot;&gt;this package&lt;/a&gt;, it's fixing several security issues, including the fix for the &quot;Avatar Select&quot; hack.&lt;br /&gt;
Those fixes are now also included in the full Seditio installation.&lt;br /&gt;
&lt;br /&gt;
Thanks to Nukedx for the report.&lt;br /&gt;
&lt;br /&gt;
UPDATE : And thanks to Poncha there's a &lt;a href=&quot;http://poncha.appcell.net/seditio/page.php?al=ldupatch_20061124multiv&quot;&gt;port for LDU v802 here&lt;/a&gt;.</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2233</link>
 <pubDate>Fri, 24 Nov 2006 19:55:00 -0500</pubDate>
</item>
<item>
 <title>Seditio and LDU all versions security issue (UPDATED!)</title>
 <description>A security breach was reported, about a potential SQL injection in all Seditio and LDU versions. A flaw in the code for the default avatar selection, coupled with a weirdness from a PHP function, allows an attacker to arbitrarily run a SQL query and change the password of the administrator and thus gain control of the whole site.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;page.php?al=avselect&quot;&gt;&lt;span style=&quot;color:#FF9900&quot;&gt;&lt;strong&gt;Please read the instructions here, all users !&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2210</link>
 <pubDate>Tue, 21 Nov 2006 19:30:00 -0500</pubDate>
</item>
<item>
 <title>Seditio v110 final build released</title>
 <description>There's a new build for Seditio available, the list of the changes is in the &lt;a href=&quot;plug.php?e=bugtracker&amp;fixedin=110&quot;&gt;bugtracker&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;a href=&quot;page.php?al=seditio&quot;&gt;Download Seditio v110 here !&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
If you're already running the v110 RC, you simply have to update the files listed &lt;a href=&quot;page.php?al=hist110&quot;&gt;here at the bottom of the page&lt;/a&gt;, don't run the SQL upgrade tool once again.</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2206</link>
 <pubDate>Thu, 28 Sep 2006 08:22:00 -0400</pubDate>
</item>
<item>
 <title>Seditio v102, new build is available.</title>
 <description>There's a new build for Seditio available, with few dozens of tweaks and fixes, the list of the changes is in the &lt;a href=&quot;plug.php?e=bugtracker&amp;fixedin=102&quot;&gt;bugtracker&lt;/a&gt;. It's a minor maintenance release, so the upgrade from the previous version shouldn't take you more than few minutes.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;a href=&quot;page.php?al=seditio&quot;&gt;Download Seditio v102 here !&lt;/a&gt;&lt;/strong&gt;</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2109</link>
 <pubDate>Wed, 03 May 2006 14:11:00 -0400</pubDate>
</item>
<item>
 <title>Security patch for Land Down Under 802</title>
 <description>A vulnerability was reported in Land Down Under v802.&lt;br /&gt;
A member could submit a malicious event and under some conditions steal the cookie of an administrator and later breach the security of the system. This upgrade is highly recommended. The full v802 package is updated with this fix.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Download it it &lt;a href=&quot;page.php?al=802sec&quot;&gt;here&lt;/a&gt;.&lt;/strong&gt;</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2052</link>
 <pubDate>Sat, 01 Apr 2006 20:20:00 -0500</pubDate>
</item>
<item>
 <title>Seditio v101, maintenance release.</title>
 <description>There's a new build for Seditio available, fixing some annoying bugs, aswell couple of cosmetic tweaks, the list of the changes is in the &lt;a href=&quot;plug.php?e=bugtracker&amp;fixedin=101&quot;&gt;bugtracker&lt;/a&gt;. The upgrade from Seditio 100 is pretty simple, it's only a matter of replacing files, all is detailled in the package.</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=2015</link>
 <pubDate>Thu, 16 Mar 2006 07:58:00 -0500</pubDate>
</item>
<item>
 <title>Seditio v100 !</title>
 <description>Here it is, the second website engine from Neocrome.&lt;br /&gt;
&lt;br /&gt;
To sum it up, it's a PHP/SQL website engine that takes the best of the 3 years of development for Land Down Under, with major improvements in security and handling of the datas. Another noticable point is that the management of the users in Seditio is based on groups, instead of the LDU &quot;levels&quot;. This greatly improves the usability of the CMS, with no loss of performance.&lt;br /&gt;
&lt;br /&gt;
There's a &lt;a href=&quot;page.php?al=upgrade&quot;&gt;tool available&lt;/a&gt; to upgrade from Land Down Under v802, be warned that it's not an easy move, so if you're happy with your actual LDU setup, keep it :]&lt;br /&gt;
&lt;br /&gt;
If you were already running one of the beta builds on your site... wait wait, didn't I tell you to not do this ? well anyway you simply have to replace all the files from the folder /system, and all the default plugins just to be sure.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Download Seditio &lt;a href=&quot;list.php?c=sed&quot;&gt;here&lt;/a&gt; !&lt;/strong&gt;</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=1999</link>
 <pubDate>Fri, 10 Mar 2006 10:27:00 -0500</pubDate>
</item>
<item>
 <title>Seditio in one week, and last beta today !</title>
 <description>There's a new build for Seditio available in the &lt;a href=&quot;list.php?c=sed&quot;&gt;download section&lt;/a&gt;, and the list of changes is &lt;a href=&quot;page.php?al=hist100&quot;&gt;here&lt;/a&gt;. The documentation is also slowly starting to roll, &lt;a href=&quot;list.php?c=sd&quot;&gt;here&lt;/a&gt;. If all tests are ok, the final version should be out the end of the next week, around the 10th, wild guess.</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=1984</link>
 <pubDate>Fri, 03 Mar 2006 08:34:00 -0500</pubDate>
</item>
<item>
 <title>Seditio v100 beta released.</title>
 <description>Here it is, the first real public build of Seditio v100.&lt;br /&gt;
&lt;br /&gt;
Remember that it's beta quality code, it's not recommended for live sites, even if it mostly works. There are bugs and issues left, and some details may change in the final release. This package is featuring a special skin made by &lt;a href=&quot;users.php?m=details&amp;id=6&quot;&gt;riptide&lt;/a&gt; that comes with an extra language file to handle the words there were previously hardcoded in the skin files.&lt;br /&gt;
&lt;br /&gt;
There's also an upgrade tool bundled, it's working fine, but there's some undocumented limitations so you should not use it on a live site.&lt;br /&gt;
&lt;br /&gt;
All comments, bug reports and feedback must go in the &lt;a href=&quot;forums.php?m=topics&amp;s=50&quot;&gt;Seditio section in the forums&lt;/a&gt;, thanks.&lt;br /&gt;
&lt;br /&gt;
I'll pack up and upload all the available compatible plugins in the next few days.&lt;br /&gt;
&lt;br /&gt;
Grab the Seditio beta &lt;a href=&quot;list.php?c=sedfiles&quot;&gt;here&lt;/a&gt;.</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=1964</link>
 <pubDate>Sun, 19 Feb 2006 20:45:00 -0500</pubDate>
</item>
<item>
 <title>First public beta of Seditio this week-end</title>
 <description>In order to speed up the testing phase of the upcoming Seditio v100, I'll release a public beta package this week-end, plus 2 or 3 skins, and all the plugins done so far.&lt;br /&gt;
&lt;br /&gt;
Be warned that it's beta quality code, it's not recommended for live sites, even if it mostly works fine. There are bugs and issues left, and some details may change in the final release. The upgrade tool (to move from Land Down Under to Sedito) will come as a separate pack.&lt;br /&gt;
&lt;br /&gt;
For this event the bugtracker will be &quot;unpaused&quot;, so all can help and contribute the development. As usual, all comments and suggestions are welcome in the forums.&lt;br /&gt;
&lt;em&gt;&lt;br /&gt;
(About the site, you may notice that the comments are back, and all ratings were reset)&lt;/em&gt;</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=1962</link>
 <pubDate>Fri, 17 Feb 2006 17:00:00 -0500</pubDate>
</item>
<item>
 <title>Land Down Under v802</title>
 <description>The changelog is &lt;a href=&quot;page.php?al=hist802&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
It's a minor release, some bugs fixes and few enhancements, thanks to all the people that helped with the &lt;a href=&quot;plug.php?p=bugtracker&amp;version=801&quot;&gt;bugtracker&lt;/a&gt; and their reports.&lt;br /&gt;
&lt;br /&gt;
This small upgrade is only a bout the core code, there's no required changes for the skins or the languages packs.</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=1957</link>
 <pubDate>Mon, 12 Dec 2005 06:30:00 -0500</pubDate>
</item>
<item>
 <title>LDU v801 released !</title>
 <description>&lt;span class=&quot;bbstyle6&quot;&gt; &lt;a href=&quot;pfs.php?m=view&amp;amp;v=1-pandora801.jpg&quot;&gt;&lt;img src=&quot;datas/thumbs/1-pandora801.jpg&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;/span&gt;The changelog is &lt;a href=&quot;page.php?al=hist801&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
This release mostly consist of bugs fixes and enhancements, thanks to all the people that helped with the &lt;a href=&quot;plug.php?p=bugtracker&quot;&gt;bugtracker&lt;/a&gt; and their reports.&lt;br /&gt;
&lt;br /&gt;
There's also few tweaks about the security and the handling of the error messages, so this build is a &quot;recommended upgrade&quot;, with no emergency.</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=1956</link>
 <pubDate>Thu, 25 Aug 2005 08:44:00 -0400</pubDate>
</item>
<item>
 <title>Regarding LDU at SecurityFocus.com</title>
 <description>Since yesterday there's 2 new items about LDU at &lt;a href=&quot;http://www.securityfocus.com,&quot;&gt;http://www.securityfocus.com,&lt;/a&gt; about &quot;security exploits&quot; that may affect LDU build 800. &lt;strong&gt;None of the tricks written there are working, the variables are properly sanitized and no LDU version is affected.&lt;/strong&gt; This morning I notified the moderators of the site.&lt;br /&gt;
&lt;br /&gt;
The 2 articles are here :&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://securityfocus.com/bid/14618/exploit&quot;&gt;http://securityfocus.com/bid/14618/exploit&lt;/a&gt;&lt;br /&gt;
&lt;a href=&quot;http://securityfocus.com/bid/14619/exploit&quot;&gt;http://securityfocus.com/bid/14619/exploit&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
I'll post here if there's updates on this topic.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;UPDATE :&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
And Internet being a wonderful place where everybody keeps blindly copying the others, the erroneous informations are now mirrored &lt;a href=&quot;http://www.securitytracker.com/alerts/2005/Aug/1014747.html&quot;&gt;here&lt;/a&gt;, &lt;a href=&quot;http://www.zone-h.org/advisories/read/id=7987&quot;&gt;here&lt;/a&gt;, &lt;a href=&quot;http://security.nnov.ru/Jdocument540.html&quot;&gt;here&lt;/a&gt;,  &lt;a href=&quot;http://www.networksecurityarchive.org/html/Bugtraq/2005-08/msg00294.html&quot;&gt;here&lt;/a&gt;, etc.</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=1955</link>
 <pubDate>Sun, 21 Aug 2005 09:25:00 -0400</pubDate>
</item>
<item>
 <title>Security advisory : Shoutbox plugin</title>
 <description>I've been informed that the plugin &quot;Shoutbox&quot; permits the contributors to directly post HTML code in the home pages. Of course this is a major security issue, and we strongly recommend the webmasters that installed this extension to disabled it as soon as possible, or to apply [url=forums.php?m=posts&amp;amp;p=81340#81340]the fix detailed here by bigdave[/url].&lt;br /&gt;
&lt;br /&gt;
Please notice that it's a third party plugin, LDU itself is not compromised.&lt;br /&gt;
&lt;br /&gt;
On more general scope, you should never install plugins where your visitors are allowed to publish HTML with no validation, and you should never allow the un-registered users (level 0) to submit a single byte of data.</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=1954</link>
 <pubDate>Thu, 28 Jul 2005 20:23:00 -0400</pubDate>
</item>
<item>
 <title>Security advisory : HTML in the signatures</title>
 <description>We received reports that under some circumstances an attacker could manage to steal your (web) cookies, by putting some evil Javascript code into his/her user signature, if images and HTML code are enabled there at your website. This is already fixed in the next LDU v801, until this release it's recommended to go in :&lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Administration panel &gt; Configuration &gt; Users&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
... and set the option : &lt;br /&gt;
&lt;br /&gt;
&lt;em&gt;Allow images and HTML in user signature : No&lt;/em&gt;</description>
 <category>News</category>
 <link>http://www.neocrome.net/page.php?id=1953</link>
 <pubDate>Thu, 28 Jul 2005 20:22:00 -0400</pubDate>
</item>
</channel>
</rss>