We are getting a lot of requests for information on mosDirectory’s future, in particular compatibility with Joomla 1.5.x
At the time of writing we have no intention of ever making mosDirectory compatible with Joomla 1.5.x
Earlier last month we started a completly new component, that is a directory type of component, with a whole host of new features and new code. Nothing from mosDirectory will be used in this component.
We do not know if/when this new component (compatible with Joomla 1.5.x) will be released, and please do not email us asking – (just assume its not soon and you will not be disapoointed if you are right). We will release it when it is ready.
The Bad News:
It has come to our attention overnight that an exploit for earlier versions of mosDirectory has been published on the internet. We have tested this exploit and can confirm that all versions of mosDirectory are affected.
We have personally emailed all customers who have purchased mosDirectory over the last three years.
The Good News:
We have worked hard this morning to secure mosDirectory from this exploit and we have just uploaded and released mosDirectory v2.5.0 which fixes all known problems.
YOU MUST UPGRADE TO mosDirectory v2.5.0 AS SOON AS POSSIBLE – to avoid your site being compromised.
The code of mosDirectory was written several years ago (Three in fact) and since then our experience and security levels have increased significantly in this area. The reported exploit is in code that was written three years ago and has never been identified as a problem before today.
We trust the quickness of our release of mosDirectory v2.5.0 after the confirmation of the exploit assures you of our dedication to your sites security! (Lets see Microsoft patch files within 4 hours of a bug report )
You can download the latest version from https://secure.myjoomla.com
To upgrade, just uninstall the component, and reinstall the new one, no data is lost in the process.
There are reports circulating this Christmas Eve that the modules provided by mosDirectory v2.3.2 are vulnerable to a remote file inclusion.
Having reviewed the code I can confirm that, under the right circumstances, this can happen with all versions up until mosDirectory v2.3.7.
The modules provided by mosDirectory are all community/customer developed and submitted and added into mosDirectory by request. It appears that our quality control missed this single line of code – and for this we are very sorry – the code in this file has not changed for almost two years and has never been flagged as an issue before, we now have automated nightly builds that check for this kind of security issue.
There are no reported cases of a Joomla site being hacked through mosDirectory
There are no reported cases of a Joomla site being hacked through this vulnerability in the module.
The vulnerability in a module – not in the main mosDirectory component
If you are using the htaccess file provided by Joomla then you are not vulnerable – however all customers should upgrade to the latest mosDirectory v2.4.0 as soon as possible to ensure that you are full protected.
The latest version of mosDirectory v2.4.0 can be downloaded by logging into your account at http://secure.myjoomla.com/
Full details of patching your site have been emailed to every customer. If you missed this email then please contact us at email@example.com ASAP
The issue surrounding mosDirectory where the config wasn’t being saved has now been fixed.
The new version of mosDirectory can now be downloaded from www.phil-taylor.com/cc
Details on how to upgrade can be also found at:
How to upgrade to the next version
We have identified an issue with mosDirectory in Joomla 1.0.12 when trying to save mosDirectory configuration the updated values are not saved. This bug has been introduced into our component by changes to Joomla 1.0.12 (Specifically, the array $_POST is now blank when it gets to mosDirectory, so we have no direct access to the passed values).
We are currently investigating the changes in Joomla 1.0.12 and developing a workaround.
Please watch our blog for more details, once a fix has ben created we will release a new version of mosDirectory to address the issue.
For today only we are reducing the cost of all our Joomla Components
to only GBP20.00 per component – thats almost 50percent off the price
of Phil-a-form, and a great deal on the other components!
Download a Joomla Component for only GBP20.00 Today only at:
=== UK Joomla Developers Course ===
- Are you a PHP Developer?
- Want to learn to develop Joomla Component?
- Free on the 16/17th
We have only * 5 * places left on our Joomla Developers Course in Gloucester,
UK, on the 16th and 17th
August SEPTEMBER (Two day course with accomodation)
Read more and book now at http://www.phil-taylor.com/booknow
In true Phil Taylor style I have decided o extend the £20.00 sale price offer on al my Joomla Components – Why? – whell you guys seem to like the price at £20.00 rather than a little higher (Normal prices range from £20.00 to £30.00).
I personally think you are getting a great bargain as I know how much time and dedicaton have gone into my components over the last 4 years and selling it for 20.00 seems illogical to many. However grab them while you can bfore prices increase.
I am also working very hard on my next Joomla component, as well as looking into the future and the rewriting of some components for Joomla 1.1 compatibility. More details on this soon, but for now go and buy Joomla components at only GBP20.00 – who knows when I will be bothered to up the prices again !
I have just released mosDirectory v2.3.1 which addresses several small issues surrounding SEF urls and problems with the search mambot. You can download this update in the normal manner from http://www.phil-taylor.com/Updates
mosDirectory is a Joomla Component for creating a web based directory like yellow pages by using Joomla!
Today we released an update of our popular Joomla Component and Extension, mosDirectory. This is a small release with big gains. We have implmented better cache handling and code consolidation to make the directory interface load a lot faster.
We have tested this with a directory of 11,000 listings and the speed was impressive. We also took the opportunity to address a few smaller bugs and issues with this release.
This directory component for Joomla has been developed to allow you to create a yellow pages type of directory on your Joomla powered website. The Joomla Extension can be used as a directory system to display businesses, schools, clubs, office locations or any other object that has an address.