9.1.x security system works?
Post new topic   Reply to topic   Printer Friendly Page     Forum IndexSecurity
Author Message
DJ Maze
Developer


Joined: Apr 19, 2004
Posts: 5668
Location: http://tinyurl.com/5z8dmv

PostPost subject: 9.1.x security system works?
Posted: Tue Jun 13, 2006 6:14 pm
Reply with quote

Is everyone that uses current CVS satisfied of how the security system works?

Shure there are config options missing and such but i ask this if the current available features are enough.

Personally i like the anti-flooding system that i've invented. Since january there are already 364 IP's banned due to flooding.
The system is so perfectly designed that some good bots are starting to obey the HTTP headers we are sending to them which realy makes it usefull by only banning unknown bots.

If someone noticed good people/bots were banned then report it Wink
For now i hear nothing so probably it all works as expected.


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 12 / 2.2.15 / 5.1.47 / 5.3.3 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger
sultan
Nice poster


Joined: Nov 01, 2005
Posts: 68

PostPost subject: Re: 9.1.x security system works?
Posted: Tue Jun 13, 2006 9:41 pm
Reply with quote

Working quite well so far. Wink

sultan's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
[CentOS release 4.6 (Final)] | [Apache 1.3.37] | [MySQL 4.1.21-standard-log (client: 4.1.21) | [PHP 4.4.7] | [DF 9.2.1] | [FPro 2.0.2]
Back to top
View user's profile Visit poster's website
Beldak
Nice poster


Joined: Jun 15, 2005
Posts: 78
Location: Edwards AFB, CA

PostPost subject: Re: 9.1.x security system works?
Posted: Tue Jun 13, 2006 10:35 pm
Reply with quote

Works pretty goodfrom what I can tell! Caught a few flooders already as well.

Perhaps remove the "details" link for any of the options that don't have more details? (Right now clicking on details for E-Mail Domains, Flooding, or Unknown User-Agents, doesn't do anything).

This definately beats having to always mod the .htaccess manually.


Beldak's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.32 / Apache 1.3.37 / MySQL 5.0.16 / PHP 5.2.2 / Dragonfly CVS
Back to top
View user's profile Visit poster's website
run0
Supporter


Joined: Jun 28, 2004
Posts: 1559

PostPost subject: Re: 9.1.x security system works?
Posted: Tue Jun 13, 2006 11:30 pm
Reply with quote

yeah you did a great job! only problem i've had is one visitor reported being blocked, he was using a mac with firefox. I'll try to find the thread that I posted it in
_________________


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
pretzy
500+ Posts Club


Joined: Sep 09, 2005
Posts: 519
Location: Australia

PostPost subject: Re: 9.1.x security system works?
Posted: Wed Jun 14, 2006 12:03 am
Reply with quote

Seemes to work very well indeed, updating it definitely stopped a couple of suspect bots on my site,altho i did ban their IP's manually.

Great system, thanks guys Smile

_________________
Pretzy's Place Pertzel Family Tree History Genealogy
Riverlife Church Henty

pretzy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP_Apache 2.2.2_MySQL 5.0.21_PHP 5.1.4_CPGNuke 9.1.1
Back to top
View user's profile Visit poster's website
xfsunoles
XHTML Specialist


Joined: Apr 30, 2004
Posts: 2502
Location: Melbourne, Florida

PostPost subject: Re: 9.1.x security system works?
Posted: Wed Jun 14, 2006 12:11 am
Reply with quote

run0 wrote:
yeah you did a great job! only problem i've had is one visitor reported being blocked, he was using a mac with firefox. I'll try to find the thread that I posted it in

thats already fixed by latest CVS?

_________________

Firefox is my Favorite Browser

xfsunoles's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache/1.3.34 (Unix)/4.0.25-standard/4.4.1/CVS
Back to top
View user's profile Visit poster's website AIM Address MSN Messenger Yahoo Messenger
DJ Maze
Developer


Joined: Apr 19, 2004
Posts: 5668
Location: http://tinyurl.com/5z8dmv

PostPost subject: Re: 9.1.x security system works?
Posted: Wed Jun 14, 2006 2:00 am
Reply with quote

For safari browser? yes...
dragonflycms.org/cvs/h...=9.26-9.25


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 12 / 2.2.15 / 5.1.47 / 5.3.3 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger
run0
Supporter


Joined: Jun 28, 2004
Posts: 1559

PostPost subject: Re: 9.1.x security system works?
Posted: Wed Jun 14, 2006 6:50 pm
Reply with quote

o cool thanks
_________________


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
skoeter
Silver Supporter


Joined: Aug 17, 2004
Posts: 140
Location: Netherlands

PostPost subject: Re: 9.1.x security system works?
Posted: Tue Jul 03, 2007 5:39 pm
Reply with quote

Using latest DF version and somehow people get banned without warning... even worse I wanted to login today and found the Banned through bad ip screen pointing at my nose.... have been ofline for several hrs AND have had no warning... finally got in by deleting the last table line through phpMyAdmin but it has happened to more members... a ban out of the blue!!
So just been deleting all Flood bans and looked for the file to change the text on that screen I faced.... a simple addition so people read

You are banned due a bad IP
if you believe this to be an error contact the siteadmin at 'myemail'

I think that will solve a lot, thanx. I will also make it a habbit to delete (flood)bans every day 'Remove 24H Old Bans'

I DO like the IP issue in it, frequently people/bot try to add malicious links/URL (viagra etc) and I simply add their IP to the list LOL Now unregistered can add the links I do allow without registration ;0)


skoeter's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
server ??/MySQL 5+/PHP 5+/Dragonfly 9.1.2
Back to top
View user's profile Visit poster's website
darkgrue
Developer


Joined: Apr 20, 2004
Posts: 536
Location: Lancaster, CA

PostPost subject: Re: 9.1.x security system works?
Posted: Tue Jul 03, 2007 7:41 pm
Reply with quote

I think one of the biggest problems I have with the current security features is that I'm not exactly sure what it's doing, or in some cases, what it's trying to tell me. So I'm unsure as to whether it's actually working as intended, or I'm experiencing a bug.

Better documentation (is there any at all?) of the features and the settings/display would be a huge help. It'd also better enable me to evaluate their effectiveness.

_________________
It is pitch black. You are likely to be eaten by a grue.

darkgrue's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu 11.04, Atom D525/Apache 2.2.17/MySQL 5.1.54/PHP 5.3.5/Dragonfly 10.0.04 CVS
Back to top
View user's profile Visit poster's website
BadCO
Diamond Supporter


Joined: Sep 29, 2004
Posts: 115

PostPost subject: Re: 9.1.x security system works?
Posted: Tue Jul 03, 2007 9:31 pm
Reply with quote

I'm with darkgrue on this one - documentation would be really, really useful.

BadCO's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.4/5.0.37/5.2/9.1.2.1
Back to top
View user's profile Visit poster's website
Beldak
Nice poster


Joined: Jun 15, 2005
Posts: 78
Location: Edwards AFB, CA

PostPost subject: Re: 9.1.x security system works?
Posted: Thu Jul 05, 2007 2:08 pm
Reply with quote

People get banned still far too easily. I have to turn off the Flooding option, otherwise half my userbase would be banned...

Something is still very buggy with the flooding portion.


Beldak's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.32 / Apache 1.3.37 / MySQL 5.0.16 / PHP 5.2.2 / Dragonfly CVS
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer


Joined: Jun 29, 2004
Posts: 3677
Location: Melbourne, AU

PostPost subject: Re: 9.1.x security system works?
Posted: Thu Jul 05, 2007 2:37 pm
Reply with quote

I'm currently testing and debugging the flooding while adding few more options and fixing few little bugs. But none of those bugs accelerate the banning process.

As of today it includes an IP shield, logs, debugging and the possibility to add new bots. All of those are pretty stable.

New changes will not ban an user by mistake as well as the current version. However will log all requests so we all will know why they get banned. All this is just to prove that banned users are opening 3 pages in less then 2 seconds.

Using the current version we are able to permit all this (flooding off).
With the new version we will know why they get banned if flooding is on.
If debug is on then system will log any requests coming from the same ip like proxies or browser plugins and anything that accept or not cookies.

If debug on will add one query for every page visit just like what happen already with any user agent that doesn't accept cookies (bot or browser) all the rest doesn't require NO ONE additional query to what the system does already.

Anyways a documentation will be given at the CVS commit.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
MySQL 5.1 / PHP 5.3 / NextGen()
Back to top
View user's profile Visit poster's website
Beldak
Nice poster


Joined: Jun 15, 2005
Posts: 78
Location: Edwards AFB, CA

PostPost subject: Re: 9.1.x security system works?
Posted: Thu Jul 05, 2007 3:44 pm
Reply with quote

Sounds good Nano Smile

Would be nice to check the logs and find out the exact reason the ban got triggered. Good work!


Beldak's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.32 / Apache 1.3.37 / MySQL 5.0.16 / PHP 5.2.2 / Dragonfly CVS
Back to top
View user's profile Visit poster's website
Ronin
Dragonfly addicted


Joined: Jun 07, 2004
Posts: 475
Location: Calgary, AB

PostPost subject: Re: 9.1.x security system works?
Posted: Thu Jul 05, 2007 11:01 pm
Reply with quote

Excellent! Thanks Nano Very Happy
_________________
Cheers,

Ronin
Ronin Technologies
Dragonfly Google Maps Module

Ronin's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Lunarpages Linux / 1.3.37 / 4.1.22-standard-log / 4.4.4 / 9.1.2.5
Back to top
View user's profile Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic   Printer Friendly Page     Forum IndexSecurity All times are GMT
Go to page 1, 2  Next
Page 1 of 2


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

stopsoftwarepatents.eu petition banner
User Info [x]

Welcome Anonymous

Nickname
Password
(Register)

Last CVS commits [x]

Languages [x]

Community [x]

Support for DragonflyCMS in a other languages:

Deutsch
Español

X-links [x]
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

Preview theme [x]
Each user can view the site with a different theme.
Themes marked with a * also change the forum look.


You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
This page generated in 0.3706 seconds with 16 DB Queries in 0.054 seconds
Memory Usage: 3.03 MB
Interactive software released under GNU GPL, Code Credits, Privacy Policy