1
ttremeth
register_globals and protector 3.02
  • 2007/5/28 3:26

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


'register_globals' : on Not secure
This setting invites a variety of injecting attacks.
If you can put .htaccess, edit or create...

/home/preemie/public_html/cms/.htaccess

php_flag register_globals off


What should a htaccess file look like,
each time i make one i get a internal server error.



2
ttremeth
Re: getting hacked every day
  • 2007/5/21 22:52

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


thanks, but this is 2.01? Is that still ok to use to upgrade from 1.01. i am looking at migrating but I just want to secure the site for now as It obviously takes a lot of time.



3
ttremeth
Re: getting hacked every day
  • 2007/5/21 22:10

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


thanks, we got protector up and running ok, except someone still managed to hack user.php which i easily uploaded from backup. Any ideas how they did? Alos WF-Sections V1.02 is not found on the web link suggested.



4
ttremeth
Re: getting hacked every day
  • 2007/5/19 10:48

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


suggestions?



5
ttremeth
Re: getting hacked every day
  • 2007/5/19 6:07

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


Followed protector step by step however the module never appears in the list to install and the admin page loses its format until i delete protector from the modules dir

Also wf-sections 1.02 download gives a 404 error

here is my config, a made a XOOPS_TRUST_PATH folder in my directory ie /myfolder above public html

<?php
// $Id: mainfile.dist.php,v 1.5 2003/02/12 11:36:33 okazu Exp $
// ------------------------------------------------------------------------ //
// XOOPS - PHP Content Management System //
// Copyright (c) 2000 XOOPS.org //
// <https://xoops.org/> //
// ------------------------------------------------------------------------ //
// This program is free software; you can redistribute it and/or modify //
// it under the terms of the GNU General Public License as published by //
// the Free Software Foundation; either version 2 of the License, or //
// (at your option) any later version. //
// //
// You may not change or alter any portion of this comment or credits //
// of supporting developers from this source code or any supporting //
// source code which is considered copyrighted (c) material of the //
// original comment or credit authors. //
// //
// This program is distributed in the hope that it will be useful, //
// but WITHOUT ANY WARRANTY; without even the implied warranty of //
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the //
// GNU General Public License for more details. //
// //
// You should have received a copy of the GNU General Public License //
// along with this program; if not, write to the Free Software //
// Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA //
// ------------------------------------------------------------------------ //

if ( !defined("XOOPS_MAINFILE_INCLUDED") ) {
define("XOOPS_MAINFILE_INCLUDED",1);

// XOOPS Physical Path
// Physical path to your main XOOPS directory WITHOUT trailing slash
define('XOOPS_ROOT_PATH', '/home/myfolder/public_html/cms');
define('XOOPS_TRUST_PATH', '/home/myfolder/XOOPS_TRUST_PATH');

etc etc



6
ttremeth
Re: getting hacked every day
  • 2007/5/19 2:14

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


any ideas how to fix system 2.13?



7
ttremeth
Re: getting hacked every day
  • 2007/5/19 1:53

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


Quote:

davidl2 wrote:
And which version of XOOPS itself?


2.2 however i found out after complaining omn a hackers site that it was weakeness in system 2.13 Any idea what? that is all i know



8
ttremeth
Re: getting hacked every day
  • 2007/5/19 1:18

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


ver 2.2
system 2.13
news 1.42
xoops gallery 1.34
links 1.1
faq 1.1
contact us 1
guest book 1.1
smart partner 1.2
headlines 1
extended profiles .1
wf-section 1.01
wf-links 1.03
protector 2.52



9
ttremeth
getting hacked every day
  • 2007/5/18 23:24

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


Yeah, almost daily my XOOPS kids site gets hacked by some Russion or turkish outfit, well according to their lovely pictures.

I am at a loss to stop it. They seem to get the ftp password, upload a new index.php and xmlrpc.php.

Any suggestions or help. I would need specific help if possible as i am nopt a developer or designer so it would have to be step by step, preemie.info is the site so any one who would not mind could jump it and help me out.



10
ttremeth
wf links 1.03 install issue
  • 2007/3/23 2:48

  • ttremeth

  • Just popping in

  • Posts: 25

  • Since: 2003/5/29


Originally i used the built in link module however where i referred to them as the most popular they refused to open only when I went direct to the links themselves. (just went back to home page)

We installed wf links. Although it looks fine when you click on a category it just goes to a blank page.

You can see the main index and the number of links and you can see all the links in link order in admin and now popular and recent blocks work ok. The opposite of my original issue.

I am not a developer but need some suggestions.




TopTop
(1) 2 3 »



Login

Who's Online

205 user(s) are online (133 user(s) are browsing Support Forums)


Members: 0


Guests: 205


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits