Welcome to the E-Blah Community!
We would like to welcome you to our community and invite you to register an account or login.
Being a registered member is important, as it gives you several advantages over the normal Guest status. After registering you will be able to download files and images, post messages, and access member-only portions of the forum - just to name a few. Registration is quick and simple, and only takes about a minute of your time.

E-Blah Community    Informational    News  ›  Platinum 9 Security Warning
Users Browsing Forum
No Members and 3 Guests

Platinum 9 Security Warning  This thread currently has 2,210 views. Print
1 Pages 1 Recommend Thread
Justin
October 28, 2005, 4:07pm Report to Moderator Report to Moderator

The E-Blah Developer
E-Blah Programmer
Posts: 15,016
Gender: Male
Posts Per Day: 6.75
Reputation: 93.40%
Reputation Score: +297 / -21
Time Online: 36 days 17 hours 49 minutes
Location: Tallassee, AL
Age: 21
On some servers you can access the member files directly via going to their data file (username.dat).  In previous versions a .htaccess file was added into the install so no ones accounts could ever be compromised.  However, with Platinum 9, I forgot to add this file so some servers may be at risk.  To fix this problem upload the attached unzipped file to the following directories:

/Members/
/Boards/
/Prefs/
/Messages/
/Code/
/Languages/
/Mods/

On most servers, files inside the CGI-BIN are, by default, protected.  Not all servers are like this, though.

Please note that this ONLY works on Apache web servers.  If you are not on an Apache web server you should contact your host on how to disable access to these directories from the web or move them to an area that is not located in the /www/ directory (one that can be seen by others).

Sorry about the problems this may cause...



This post contains attachments; to download them you must login.



I do installs for $25 and upgrades for $20.
Technical support is always free.

  Donate to E-Blah!  

My Websites: Revolution Reality (My Blog)  |  MinistryTalk.com  |  Portfolio

"But you, O Lord, are a compassionate and gracious God, slow to anger, abounding in love and faithfulness." — Psalm 86:15 NIV


Revision History (1 edits)
admin  -  October 28, 2005, 4:11pm
Logged Offline
Site Site Private Message Private message
ricardogz
November 18, 2005, 2:28pm Report to Moderator Report to Moderator
E-Blah Member
Posts: 1
Posts Per Day: 0.00
Time Online: 26 minutes
Also upload to the subdirectories?
Logged Offline
Private Message Private message Reply: 1 - 6
Craig
November 19, 2005, 3:23am Report to Moderator Report to Moderator

SQL Support Team
Posts: 3,619
Gender: Male
Posts Per Day: 2.23
Reputation: 97.73%
Reputation Score: +215 / -5
Time Online: 14 days 14 hours 57 minutes
Location: Germany
Age: 38
Yeah, you need to add this to BHITS, HITS, and the English directory under Languages.


Don't just ask a question.
Instead ask a question, give us a screen shot and post a link to your forum.
Help us help you make your forum better!


If I helped...increase my Reputation by clicking here.
Logged Offline
Site Site Private Message Private message ICQ ICQ Reply: 2 - 6
Tim Linden
January 19, 2006, 8:48pm Report to Moderator Report to Moderator

Who IS that guy?
Administrator
Posts: 100
Posts Per Day: 0.04
Reputation: 100.00%
Reputation Score: +152 / -0
Time Online: 43 days 7 hours 41 minutes
Umm..  Someone forgot something..  It's "Deny from all" - not "Deny all". You may not notice, but it spewed errors in my error log. You may not have noticed cuz mod rewrite will try to change the url anyways.. (at least it is on mine)


Logged Offline
Site Site Private Message Private message Reply: 3 - 6
Craig
January 22, 2006, 1:53am Report to Moderator Report to Moderator

SQL Support Team
Posts: 3,619
Gender: Male
Posts Per Day: 2.23
Reputation: 97.73%
Reputation Score: +215 / -5
Time Online: 14 days 14 hours 57 minutes
Location: Germany
Age: 38
hmmm...that is interesting.  All E-Blah releases including 9.6 have .htacess files that say deny all.

Justin, you may want to change this .


Don't just ask a question.
Instead ask a question, give us a screen shot and post a link to your forum.
Help us help you make your forum better!


If I helped...increase my Reputation by clicking here.
Logged Offline
Site Site Private Message Private message ICQ ICQ Reply: 4 - 6
sundance
January 22, 2006, 6:31am Report to Moderator Report to Moderator

E-Blah Member
Alpaca Farmer
Posts: 353
Posts Per Day: 0.26
Reputation: 92.31%
Reputation Score: +12 / -1
Time Online: 3 days 5 hours 40 minutes
Location: Indiana, US
If anyone is interested... I had eBlah .htaccess files dating back to Nov 2004 saying "Deny all".
Logged Offline
Private Message Private message Reply: 5 - 6
Justin
January 22, 2006, 9:12am Report to Moderator Report to Moderator

The E-Blah Developer
E-Blah Programmer
Posts: 15,016
Gender: Male
Posts Per Day: 6.75
Reputation: 93.40%
Reputation Score: +297 / -21
Time Online: 36 days 17 hours 49 minutes
Location: Tallassee, AL
Age: 21
Quoted from sundance
If anyone is interested... I had eBlah .htaccess files dating back to Nov 2004 saying "Deny all".


Yeah, old versions had the .htaccess files included.


I do installs for $25 and upgrades for $20.
Technical support is always free.

  Donate to E-Blah!  

My Websites: Revolution Reality (My Blog)  |  MinistryTalk.com  |  Portfolio

"But you, O Lord, are a compassionate and gracious God, slow to anger, abounding in love and faithfulness." — Psalm 86:15 NIV

Logged Offline
Site Site Private Message Private message Reply: 6 - 6
1 Pages 1 Recommend Thread
Print

E-Blah Community    Informational    News  ›  Platinum 9 Security Warning