An innovative open source blogging platform developed with ASP.NET 2.0.

BlogEngine.NET Project

Critical Security Patch Available

clock April 14, 2008 23:09 by author Team

Over the weekend, we were alerted to a security flaw in BlogEngine.NET 1.3.0.0.   We have created a new release 1.3.1.0 which corrects this issue and are making a patch available here for users running 1.3.0.0.  For those people running development version of BlogEngine.NET (from the source tab on CodePlex), please note that the latest release 1.3.0.29 has the security fix as well.

The security flaw makes it possible to access BlogEngine.NET user passwords (and other data that you normally would see with a password).  The flaw has been in the system since version 1.2.0.23 and we strongly encourage all BlogEngine.NET users to update to 1.3.1 as soon as possible.  If you see a fellow blogger running something prior to 1.3.0.29 or 1.3.1.0, please let them know to update their site as soon as possible.  In addition, we encourage you to update your BlogEngine.NET password(s) as a security measure after you update.

The BlogEngine.NET team takes security very seriously and we regret that this security issue was introduced into the system.   We hope that no one was seriously effected by the issue and have not heard reports of any to date.  Please update your software as soon as you can.  We are truly sorry for the inconvenience.

It is unfortunate that the issue could not have been handled more discretely.  If you are blogger writing about the issue, we'd hope that you could refrain for spelling out exactly how to attack sites that haven't been updated yet.  (Yes, we do want people to know there is a problem that needs patched, but we'd prefer if were weren't tempting casual hackers to try out the hack on a unpatched site by giving them a step by step guide.)

Again, we are sorry for the inconvenience and any trouble this may have caused you.  If you know of other BlogEngine.NET users, please pass this information along.

Download Full Release: BlogEngine.NET 1.3.1.0

Download Patch for BlogEngine.NET 1.3.0.0


New theme available

clock January 8, 2008 17:24 by author Team

Jesse Foster has portet a really cool theme to BlogEngine.NET. It's a dark theme that looks really stylish and clean.

You can see and download the theme here.

Thanks Jesse - good work (and sorry for getting your name wrong the first time around. )


Sponsor
DiscountASP.NET – BlogEngine.NET Hosting
BlogEngine Hosting by re-invent

ImageWhy use BlogEngine.NET?
BlogEngine.NET is a full featured blogging platform that is a breeze to setup, customize, and use. A small download and easy to follow instructions get you up and running in minutes. Pick one of our elegant default themes or make your own theme. Extend the functionality by creating your own custom control or add some of the many built into the system. Read more.