<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: gCards 1.46 released due to security issues</title>
	<atom:link href="http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Tue, 27 Dec 2011 06:48:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Renton Currie</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-235765</link>
		<dc:creator>Renton Currie</dc:creator>
		<pubDate>Thu, 13 Nov 2008 03:43:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-235765</guid>
		<description>I have been hacked - help. What do I do fro here as I love the product and have a few CD&#039;s out there with a link to the hacked website  :(</description>
		<content:encoded><![CDATA[<p>I have been hacked &#8211; help. What do I do fro here as I love the product and have a few CD&#8217;s out there with a link to the hacked website  <img src='http://www.gregphoto.net/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BubblyBabs</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-79002</link>
		<dc:creator>BubblyBabs</dc:creator>
		<pubDate>Fri, 13 Jul 2007 02:45:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-79002</guid>
		<description>I wanted to comment that a security issue was found with gcards v1.46 which I&#039;m sure you know about by now...  I sent you an email, not sure if you got it, and posted a fix on the forum but I wanted to be sure you approved of it...

Babs</description>
		<content:encoded><![CDATA[<p>I wanted to comment that a security issue was found with gcards v1.46 which I&#8217;m sure you know about by now&#8230;  I sent you an email, not sure if you got it, and posted a fix on the forum but I wanted to be sure you approved of it&#8230;</p>
<p>Babs</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BubblyBabs</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-79000</link>
		<dc:creator>BubblyBabs</dc:creator>
		<pubDate>Fri, 13 Jul 2007 02:38:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-79000</guid>
		<description>I&#039;ve worked on the client collison problem and think I&#039;ve got it solved...  Please see here:
http://www.gregphoto.net/gcards/vanilla/comments.php?DiscussionID=188&amp;page=1#Item_5

Babs</description>
		<content:encoded><![CDATA[<p>I&#8217;ve worked on the client collison problem and think I&#8217;ve got it solved&#8230;  Please see here:<br />
<a href="http://www.gregphoto.net/gcards/vanilla/comments.php?DiscussionID=188&#038;page=1#Item_5" rel="nofollow">http://www.gregphoto.net/gcards/vanilla/comments.php?DiscussionID=188&#038;page=1#Item_5</a></p>
<p>Babs</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joni Solis</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-24489</link>
		<dc:creator>Joni Solis</dc:creator>
		<pubDate>Mon, 18 Dec 2006 01:29:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-24489</guid>
		<description>&gt;Tascha says...April 13th, 2006 at 3:50 am
Awesome script - thanks a lot for all the work :)
I was wondering if you plan to make this a wordpress plugin. I am facing now the task to actually integrate this into my wordpress layout &gt;_

I would like more info about using gcards with wordpress. Is anyone doing it. What about a plugin?</description>
		<content:encoded><![CDATA[<p>&gt;Tascha says&#8230;April 13th, 2006 at 3:50 am<br />
Awesome script &#8211; thanks a lot for all the work <img src='http://www.gregphoto.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
I was wondering if you plan to make this a wordpress plugin. I am facing now the task to actually integrate this into my wordpress layout &gt;_</p>
<p>I would like more info about using gcards with wordpress. Is anyone doing it. What about a plugin?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maria Claudia</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-14719</link>
		<dc:creator>Maria Claudia</dc:creator>
		<pubDate>Mon, 16 Oct 2006 05:46:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-14719</guid>
		<description>hi..... I try gcards in my web site... my hosting recently make an DNS upgrade, so I change the smtp ip for the new one in the config_email.php because I use the smtp functions....

but I have a problem....... it can&#039;t send any email

There has been a mail error sending to mc_arquitecta@hotmail.com
eCard could not be sent… 

but it&#039;s working well after the dns upgrade.....

it is possible that this it is the reason of the problem? I&#039;m sure to entered the data well then only changes the IP of the mail server.....

sorry my grammar....... 

María Claudia</description>
		<content:encoded><![CDATA[<p>hi&#8230;.. I try gcards in my web site&#8230; my hosting recently make an DNS upgrade, so I change the smtp ip for the new one in the config_email.php because I use the smtp functions&#8230;.</p>
<p>but I have a problem&#8230;&#8230;. it can&#8217;t send any email</p>
<p>There has been a mail error sending to <a href="mailto:mc_arquitecta@hotmail.com">mc_arquitecta@hotmail.com</a><br />
eCard could not be sent… </p>
<p>but it&#8217;s working well after the dns upgrade&#8230;..</p>
<p>it is possible that this it is the reason of the problem? I&#8217;m sure to entered the data well then only changes the IP of the mail server&#8230;..</p>
<p>sorry my grammar&#8230;&#8230;. </p>
<p>María Claudia</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-4584</link>
		<dc:creator>Paul</dc:creator>
		<pubDate>Mon, 03 Jul 2006 10:15:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-4584</guid>
		<description>sorry... I just realized I made an incorect statement on my last submission. The error is in the &quot;Submission Line&quot; of the confirmation email. 

I listed it as not being a problem but it is infact a problem as I copied and pasted from the wrong confirmation email.

The subject line actually reads: person1@yahoo.com, person2@aol.com, person3@yahoo.com, person4@hotmail.com, person5@sbcglobal.net, person6@aol.com,....

This is not good considering only one person of the group picked up the card. This makes me think that the other people will NOT be able to pick up their cards because the card now shows picked up and will automatically be removed from the database (or however it is stored). The person who picked up the card should be the ONLY person in the subject line, IMHO.

Sorry for the mix up.
Paul</description>
		<content:encoded><![CDATA[<p>sorry&#8230; I just realized I made an incorect statement on my last submission. The error is in the &#8220;Submission Line&#8221; of the confirmation email. </p>
<p>I listed it as not being a problem but it is infact a problem as I copied and pasted from the wrong confirmation email.</p>
<p>The subject line actually reads: <a href="mailto:person1@yahoo.com">person1@yahoo.com</a>, <a href="mailto:person2@aol.com">person2@aol.com</a>, <a href="mailto:person3@yahoo.com">person3@yahoo.com</a>, <a href="mailto:person4@hotmail.com">person4@hotmail.com</a>, <a href="mailto:person5@sbcglobal.net">person5@sbcglobal.net</a>, <a href="mailto:person6@aol.com">person6@aol.com</a>,&#8230;.</p>
<p>This is not good considering only one person of the group picked up the card. This makes me think that the other people will NOT be able to pick up their cards because the card now shows picked up and will automatically be removed from the database (or however it is stored). The person who picked up the card should be the ONLY person in the subject line, IMHO.</p>
<p>Sorry for the mix up.<br />
Paul</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-4583</link>
		<dc:creator>Paul</dc:creator>
		<pubDate>Mon, 03 Jul 2006 09:49:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-4583</guid>
		<description>So far this looks to be an awesome script. In testing out the multiple email addresses (which is seperated by a comma) so a card will go out to multiple people... I have found a bug that prevents ALL the people from picking up the card.

Here is the rundown of this issue:
1) When creating the card  there is a section that allows you to add the email of the person(s) you are sending the card to.  I wanted to send out an unlimited amount of cards so there were about 27 email addresses listed.
2) I selected the option box &quot;Notify me when card is picked up&quot;
3) Sent the card out to all the emails listed

And here is where the problem comes in... when a person of the group picks up the card I get a &quot;Person has Picked up your Card&quot; email. This email shows the following:

1) Subject line of the email: This line shows the email address of the person who picked up the card.  (This is fine)
2) The body of the confirm email: (this is the problem) This lists all the people and their email addreses that had this card sent to them. Next to the email address of the person who picked up the card says &quot;picked up your eCard&quot;. For example..
person1@yahoo.com,
person2@aol.com, picked up your eCard 
person3@yahoo.com,
person4@hotmail.com,
person5@sbcglobal.net,
person6@aol.com, 
person7@yahoo.com
person8@yahoo.com

Does that mean that because one person of the many that had this card sent to them closes the card because it shows it was picked up? In other words... if pesron &quot;A&quot; picks up the card will person &quot;B&quot; also be able to pick it up (at a later time) considering it shows the card was all ready picked up?

I would hope that when I place multiple email addresses into the email field that it would create individual cards for each email address. This means that the card would remain until EACH person picked up their card, or until the time limit of picking the card expires.

Please let me know what this program does in regards to multiple email addresses pertaining to the situation above. Before I release this on my site I want to make sure it does in fact create individual cards for each email address that is listed in the email field.

I look forward to your response,
Paul</description>
		<content:encoded><![CDATA[<p>So far this looks to be an awesome script. In testing out the multiple email addresses (which is seperated by a comma) so a card will go out to multiple people&#8230; I have found a bug that prevents ALL the people from picking up the card.</p>
<p>Here is the rundown of this issue:<br />
1) When creating the card  there is a section that allows you to add the email of the person(s) you are sending the card to.  I wanted to send out an unlimited amount of cards so there were about 27 email addresses listed.<br />
2) I selected the option box &#8220;Notify me when card is picked up&#8221;<br />
3) Sent the card out to all the emails listed</p>
<p>And here is where the problem comes in&#8230; when a person of the group picks up the card I get a &#8220;Person has Picked up your Card&#8221; email. This email shows the following:</p>
<p>1) Subject line of the email: This line shows the email address of the person who picked up the card.  (This is fine)<br />
2) The body of the confirm email: (this is the problem) This lists all the people and their email addreses that had this card sent to them. Next to the email address of the person who picked up the card says &#8220;picked up your eCard&#8221;. For example..<br />
<a href="mailto:person1@yahoo.com">person1@yahoo.com</a>,<br />
<a href="mailto:person2@aol.com">person2@aol.com</a>, picked up your eCard<br />
<a href="mailto:person3@yahoo.com">person3@yahoo.com</a>,<br />
<a href="mailto:person4@hotmail.com">person4@hotmail.com</a>,<br />
<a href="mailto:person5@sbcglobal.net">person5@sbcglobal.net</a>,<br />
<a href="mailto:person6@aol.com">person6@aol.com</a>,<br />
<a href="mailto:person7@yahoo.com">person7@yahoo.com</a><br />
<a href="mailto:person8@yahoo.com">person8@yahoo.com</a></p>
<p>Does that mean that because one person of the many that had this card sent to them closes the card because it shows it was picked up? In other words&#8230; if pesron &#8220;A&#8221; picks up the card will person &#8220;B&#8221; also be able to pick it up (at a later time) considering it shows the card was all ready picked up?</p>
<p>I would hope that when I place multiple email addresses into the email field that it would create individual cards for each email address. This means that the card would remain until EACH person picked up their card, or until the time limit of picking the card expires.</p>
<p>Please let me know what this program does in regards to multiple email addresses pertaining to the situation above. Before I release this on my site I want to make sure it does in fact create individual cards for each email address that is listed in the email field.</p>
<p>I look forward to your response,<br />
Paul</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-3784</link>
		<dc:creator>Jacob</dc:creator>
		<pubDate>Mon, 19 Jun 2006 14:59:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-3784</guid>
		<description>What about collisions Greg?!! As far as I understand the fix is fairly simple.</description>
		<content:encoded><![CDATA[<p>What about collisions Greg?!! As far as I understand the fix is fairly simple.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-3647</link>
		<dc:creator>Jacob</dc:creator>
		<pubDate>Mon, 19 Jun 2006 07:48:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-3647</guid>
		<description>Did you fix the client collision problem in the lates version of gcards?

The situation is caused by the use of the server time (seconds since epoch) as the identification of cards sent. It is quite obvious that two or more users sending a card in within the same second will collide because the second card cannot be created as it would produce a duplicate key - a MySQL error is generated when this happens. The solution is to identify the cards by a different means</description>
		<content:encoded><![CDATA[<p>Did you fix the client collision problem in the lates version of gcards?</p>
<p>The situation is caused by the use of the server time (seconds since epoch) as the identification of cards sent. It is quite obvious that two or more users sending a card in within the same second will collide because the second card cannot be created as it would produce a duplicate key &#8211; a MySQL error is generated when this happens. The solution is to identify the cards by a different means</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg</title>
		<link>http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/comment-page-1/#comment-3340</link>
		<dc:creator>Greg</dc:creator>
		<pubDate>Wed, 14 Jun 2006 04:41:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gregphoto.net/index.php/2006/03/27/gcards-146-released-due-to-security-issues/#comment-3340</guid>
		<description>@Susan - I&#039;ll take a look at it - I moved it around on my site and probably screwed up the demo

@Frank - sorry you&#039;re having problems with the script.  Unfortunately I haven&#039;t been able to put up a replacement for the forum.  It&#039;s hard to find good free forum software that can easily block spam and require a minimal amount of maintenance.  You can change the interface if you like - it&#039;s simple html and php...nothing too fancy.  As for storing things - I don&#039;t know exactly what you&#039;re referring to, but not much is stored in the filesystem aside from the actual images.

@Renton Curry - there&#039;s nothing built-in to support MPEG...it might be possible to hack it to do that, but nothing in the plans to do that.

Greg</description>
		<content:encoded><![CDATA[<p>@Susan &#8211; I&#8217;ll take a look at it &#8211; I moved it around on my site and probably screwed up the demo</p>
<p>@Frank &#8211; sorry you&#8217;re having problems with the script.  Unfortunately I haven&#8217;t been able to put up a replacement for the forum.  It&#8217;s hard to find good free forum software that can easily block spam and require a minimal amount of maintenance.  You can change the interface if you like &#8211; it&#8217;s simple html and php&#8230;nothing too fancy.  As for storing things &#8211; I don&#8217;t know exactly what you&#8217;re referring to, but not much is stored in the filesystem aside from the actual images.</p>
<p>@Renton Curry &#8211; there&#8217;s nothing built-in to support MPEG&#8230;it might be possible to hack it to do that, but nothing in the plans to do that.</p>
<p>Greg</p>
]]></content:encoded>
	</item>
</channel>
</rss>

