« January 2008 | Main | March 2008 »

February 27, 2008

Upcoming Webinars and In-house Classes for Tendenci training

Calendar Have you been to Tendenci training lately?  It's fun, it's free and can really help with the success of your Web site!  Plus you get to meet Schipul-ites in person and interact with other Tendenci users.

We have 6 really great classes for you to attend over the next six weeks:

  1. Thursday (3/6): Intro to Tendenci
  2. Wednesday (3/12):  Content Management Using Tendenci (Please note - Online Webinar)
  3. Thursday (03/13): Tendenci Newsletter Training
  4. Thursday (03/20): Content Management Using Tendenci
  5. Wednesday (04/01): Tendenci Newsletter Training (Please note - Online Webinar)
  6. Thursday (04/02): Intro to Tendenci

You can also take a look at the rest of our training classes by visiting our Schipul education calendar here.

Email (all, paid, or non-paid) Event Registrants

Tendenci now gives you the ability to email all, paid, or non-paid registrants for your event. Simply select the appropriate group and your registrants will receive your custom formatted email.

Email Calendar Event Registrants

February 15, 2008

Funding for Photo Albums Export

Hey all you totally awesome Tendenci users... If you use the photo albums module in Tendenci and are interesting in funding functionality for a bulk export of your albums, please contact Kim Lange at Schipul - The Web Marketing Company at 281.497.6567 ext. 514.

The basic export would include exporting your album to a zip file (no photo information will be included in the export). You would not have to download your images individually.  It cost about 2k to add this functionality to the photo albums module.

February 12, 2008

Cross Site Scripting

We wanted our clients to know that security researchers discovered cross site scripting vulnerabilities in numerous Tendenci modules  yesterday. Specifically a munged URL could be used in spam creating a link that looked legitimate. When a user clicked that link it would have then redirected them to a different site as intended by the bad guy.

The vulnerabilities have been patched and our programming team is continuing to test our security functions.

The timeline was we were contacted by security researcher Russ and Secunia yesterday morning. The patches were posted live on the server farm within hours.

Our biggest take away is a sense of gratitude for security researchers who help us keep our products and the Internet secure. It can be a thankless task so to be clear our position is THANK YOU!

FAQ:

Q: Did we lose any data?

A: No.

Q: Did any of our secure content get accessed?

A: No.

Q: Did any spammers take advantage of the cross site scripting vulnerabilities to redirect users?

A: We are researching this. So far we have only seen the safe tests run by the security researchers.

Q: What else do I need to do?

A: Nothing at this time. We have security as our top priority and will continue to do so.

Thanks,

Jennifer Brooks


UPDATE:
We are very pleased to read Russ' post about our quick response to the Cross Site Scripting vulnerability, entitled 'Fastest Fix in the West:  a vendor's excellent response'.  We are amazingly passionate about Security, our software and our amazing Clients - so this recognition means a lot. Here's an excerpt of his post:

Rare is the occasion when one who researches and responsibly reports web application vulnerabilities is met with an open, immediate, consumer oriented response from a vendor. But so it was when I let the folks who develop Tendenci, a Schipul offering, know about a few XSS issues...  To Schipul I say well done, extremely well done, and thank you.... (read the rest of the post)

February 07, 2008

You can now merge usergroups in Tendenci

Good news Tendenci users!  You can now merge or append usergroups.

Merging usergroups allows you as an admin, to take users from one group and add them to another. You  have the option to delete the group entirely.

Append usergroups allows you to merge usergroups while keeping the source group.

You will need a site authentication string to do the merge.

Check out the help files.

  1. Merging usergroups - http://www.tendenci.com/en/helpfiles/v/484     
  2. Appending usergoups - http://www.tendenci.com/en/helpfiles/v/485     
My Photo

Subscribe

BlogRoll

  • LongStation
    Advertising, business and online marketing information wrapped up in one great Web site!
  • The SEM Blog
    Search Engine Marketing knowledge sharing from the Schipul SEM team.
  • Happykatie
    Social Media marketing tidbits and online brain candy in the form of a happyblog.
  • Creative Leak
    Urban surrealist gallery and Houston art enthusiast community. One to check out!
  • JayMac Blog
    Music and advertising in the big city of Houston from the mind of a Canadian.
  • Brandtobedetermined
    One lucky guy with a beautiful wife, three kids, a dog, and some ungrateful fish.
  • Schipul - The Web Marketing Company
    Web marketing, web design and Search Engine Marketing. Does your Web site increase your sales?
  • Tendenci
    Association management software - empowering your members and making you into a hero!
  • Houston MetBlogs
    Houston news with an entertaining twist.