Not-Noticeably.net

Skip navigation

All posts tagged with "PHPAskIt"

CodeGrrl scripts and Surpass Hosting

If by now you aren't aware of the serious vulnerabilities that exist within CodeGrrl.com's most popular scripts then I would recommend that you read this announcement as a matter of urgency.

As a result of the above vulnerability, I have recently discovered that certain people have been telling others to delete the affected file, protection.php, to avoid being hacked.

DO NOT DO THIS.

Deleting protection.php takes away the admin panel's password protection and you will be leaving your scripts wide open to much more than hacking.

At first I thought it was just a misinformed user telling others what they thought was best - I was wrong. Today I was alerted to the fact that it is in fact Surpass Hosting that is spreading this very seriously incorrect advice.

Please spread the word about this. Deleting protection.php is about as secure as leaving it unpatched on the server. You WILL be hacked if you leave it unpatched, and you will also be hacked if you delete it. If you've deleted protection.php, put it back as soon as possible and tell anyone else who may have deleted it to do the same.

If you are at all worried about running PHPFanBase or any other affected CodeGrrl.com script and have decided against keeping said scripts, you need to delete ALL the files associated with the scripts, not just protection.php.

Oh, and Surpass have apparently banned my script, PHPAskIt, because they believed the recent security vulnerability hoax that stated that my script could be hacked like the rest of the CG scripts. It CAN'T. It is not based on PHPFanBase like the vulnerable CodeGrrl scripts are, and can NOT be hacked through protection.php (there is no such file anyway) or through any similar method in other files.

PHPAskIt Security Vulnerability

It has been brought to my attention that there is a serious security vulnerability within all versions of PHPAskIt, which states that the conversion scripts for Wak's Ask&Answer and the classic Ask&Answer can be hacked through the directory variables.

The security vulnerability is a hoax. The import files CANNOT be hacked through the $qadir and $dir variables even with register_globals on.

I find it such a shame that the person who discovered this has gone round telling everyone who will listen that my script's insecure (and every major security site there is) but 1) won't inform me (I found out through a Google search) and 2) makes things up. I've contacted them several times but each time the mail has bounced back. *Rolls eyes* How mature.

Ramble

I'm back. I'm not going to talk about the funeral or anything here, but if you're an LJ friend you can see some of the details there if you're interested.

Before I went, I added one of those Feedburner things, inspired, once again, by Jem. The subscriber count has kind of diminished though, last week it was about 8 subscribers and now it's on 3... Or 2, depends when you look

Oh and speaking of Jem, I visted some site today where she's been credited with the creation of my script, PHPAskIt. WTF? I wrote that! I mean, I don't mind the site who did it crediting someone else (as long as it isn't themselves) but still... Jem gets too many hits as it is, she doesn't need ones meant for me on top of the ones she gets already. Hmph... :P

Aaaand, I discovered today that my site is listed on the second page of Google when searching for Amelie. Not sure when that happened... Last time I checked, the first 20 million or so results were all reviews of that film with the same name, and plus I have Google and other bots blocked from my site since it stops spam... Somehow it's still associating my name with my domain, which it shouldn't really be doing since it's not supposed to index this site or anything. Oh well, can't complain - I was thinking of getting back into SEO and letting the bots back in anyway so this is definitely a good incentive. :D

Finally... Remember my dad's sponsored run? Well, my aunt (his sister) has done a sponsored skydive. She's already done the skydive but is hoping to use it to raise money for Daisy's Dream, a charity she's volunteered for for some time and who do an amazing job. If you have some spare cash, it would mean a lot to her and to us if you would sponsor her. Thanks :P

Edit: Oh yeah, and I made a fanlisting. Yeah, yeah, I jumped on the bandwagon... Anyway, it's for Jem's script, BellaBook. JOIN PLZ JOIN PLZ JOIN PLZ!!!111 (No really, it would be nice if you could join... If you're a fan of BellaBook, that is. Hee!)

Older Entries | Newer Entries