Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security ⇒ 9.1.x security system works?


9.1.x security system works?
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Go to page 1, 2  Next
Post new topic    Reply to topic    Printer Friendly Page     Forum Index ⇒  Security

View previous topic :: View next topic  
Author Message
DJ Maze
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 5683
Location: http://tinyurl.com/5z8dmv
PostPosted: Tue Jun 13, 2006 6:14 pm
Post subject: 9.1.x security system works?

Is everyone that uses current CVS satisfied of how the security system works?

Shure there are config options missing and such but i ask this if the current available features are enough.

Personally i like the anti-flooding system that i've invented. Since january there are already 364 IP's banned due to flooding.
The system is so perfectly designed that some good bots are starting to obey the HTTP headers we are sending to them which realy makes it usefull by only banning unknown bots.

If someone noticed good people/bots were banned then report it Wink
For now i hear nothing so probably it all works as expected.


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
sultan
Nice poster
Nice poster

Offline Offline
Joined: Nov 01, 2005
Posts: 68

PostPosted: Tue Jun 13, 2006 9:41 pm
Post subject: Re: 9.1.x security system works?

Working quite well so far. Wink


sultan's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
[CentOS release 4.6 (Final)] | [Apache 1.3.37] | [MySQL 4.1.21-standard-log (client: 4.1.21) | [PHP 4.4.7] | [DF 9.2.1] | [FPro 2.0.2]
Back to top
View user's profile Visit poster's website
Beldak
Nice poster
Nice poster

Offline Offline
Joined: Jun 15, 2005
Posts: 78
Location: Edwards AFB, CA
PostPosted: Tue Jun 13, 2006 10:35 pm
Post subject: Re: 9.1.x security system works?

Works pretty goodfrom what I can tell! Caught a few flooders already as well.

Perhaps remove the "details" link for any of the options that don't have more details? (Right now clicking on details for E-Mail Domains, Flooding, or Unknown User-Agents, doesn't do anything).

This definately beats having to always mod the .htaccess manually.


Beldak's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.32 / Apache 1.3.37 / MySQL 5.0.16 / PHP 5.2.2 / Dragonfly CVS
Back to top
View user's profile Visit poster's website
run0
Supporter
Supporter

Offline Offline
Joined: Jun 28, 2004
Posts: 1559

PostPosted: Tue Jun 13, 2006 11:30 pm
Post subject: Re: 9.1.x security system works?

yeah you did a great job! only problem i've had is one visitor reported being blocked, he was using a mac with firefox. I'll try to find the thread that I posted it in

_________________


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
pretzy
500+ Posts Club
500+ Posts Club

Offline Offline
Joined: Sep 09, 2005
Posts: 519
Location: Australia
PostPosted: Wed Jun 14, 2006 12:03 am
Post subject: Re: 9.1.x security system works?

Seemes to work very well indeed, updating it definitely stopped a couple of suspect bots on my site,altho i did ban their IP's manually.

Great system, thanks guys Smile

_________________
Pretzy's Place Pertzel Family Tree History Genealogy
Riverlife Church Henty

pretzy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
XP_Apache 2.2.2_MySQL 5.0.21_PHP 5.1.4_CPGNuke 9.1.1
Back to top
View user's profile Visit poster's website
xfsunoles
XHTML Specialist
XHTML Specialist

Offline Offline
Joined: Apr 30, 2004
Posts: 2502
Location: Melbourne, Florida
PostPosted: Wed Jun 14, 2006 12:11 am
Post subject: Re: 9.1.x security system works?

run0 wrote:
yeah you did a great job! only problem i've had is one visitor reported being blocked, he was using a mac with firefox. I'll try to find the thread that I posted it in

thats already fixed by latest CVS?

_________________

Firefox is my Favorite Browser

xfsunoles's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Apache/1.3.34 (Unix)/4.0.25-standard/4.4.1/CVS
Back to top
View user's profile Visit poster's website AIM Address MSN Messenger Yahoo Messenger Photo Gallery
DJ Maze
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 5683
Location: http://tinyurl.com/5z8dmv
PostPosted: Wed Jun 14, 2006 2:00 am
Post subject: Re: 9.1.x security system works?

For safari browser? yes...
dragonflycms.org/cvs/h...=9.26-9.25


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 15 / 2.2.22 / 5.5.20 / 5.3.10 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
run0
Supporter
Supporter

Offline Offline
Joined: Jun 28, 2004
Posts: 1559

PostPosted: Wed Jun 14, 2006 6:50 pm
Post subject: Re: 9.1.x security system works?

o cool thanks

_________________


run0's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/1.3.33 (Unix)/4.0.22-standard/4.3.9/DF 9.x
Back to top
View user's profile Visit poster's website
skoeter
Silver Supporter
Silver Supporter

Offline Offline
Joined: Aug 17, 2004
Posts: 140
Location: Netherlands
PostPosted: Tue Jul 03, 2007 5:39 pm
Post subject: Re: 9.1.x security system works?

Using latest DF version and somehow people get banned without warning... even worse I wanted to login today and found the Banned through bad ip screen pointing at my nose.... have been ofline for several hrs AND have had no warning... finally got in by deleting the last table line through phpMyAdmin but it has happened to more members... a ban out of the blue!!
So just been deleting all Flood bans and looked for the file to change the text on that screen I faced.... a simple addition so people read

You are banned due a bad IP
if you believe this to be an error contact the siteadmin at 'myemail'

I think that will solve a lot, thanx. I will also make it a habbit to delete (flood)bans every day 'Remove 24H Old Bans'

I DO like the IP issue in it, frequently people/bot try to add malicious links/URL (viagra etc) and I simply add their IP to the list LOL Now unregistered can add the links I do allow without registration ;0)


skoeter's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
server ??/MySQL 5+/PHP 5+/Dragonfly 9.1.2
Back to top
View user's profile Visit poster's website
darkgrue
Developer
Developer

Offline Offline
Joined: Apr 20, 2004
Posts: 542
Location: Lancaster, CA
PostPosted: Tue Jul 03, 2007 7:41 pm
Post subject: Re: 9.1.x security system works?

I think one of the biggest problems I have with the current security features is that I'm not exactly sure what it's doing, or in some cases, what it's trying to tell me. So I'm unsure as to whether it's actually working as intended, or I'm experiencing a bug.

Better documentation (is there any at all?) of the features and the settings/display would be a huge help. It'd also better enable me to evaluate their effectiveness.

_________________
It is pitch black. You are likely to be eaten by a grue.

darkgrue's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu 11.04, Atom D525/Apache 2.2.17/MySQL 5.1.54/PHP 5.3.5/Dragonfly 10.0.04 CVS
Back to top
View user's profile Visit poster's website
BadCO
Diamond Supporter
Diamond Supporter

Offline Offline
Joined: Sep 29, 2004
Posts: 115

PostPosted: Tue Jul 03, 2007 9:31 pm
Post subject: Re: 9.1.x security system works?

I'm with darkgrue on this one - documentation would be really, really useful.


BadCO's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.4/5.0.37/5.2/9.1.2.1
Back to top
View user's profile Visit poster's website
Beldak
Nice poster
Nice poster

Offline Offline
Joined: Jun 15, 2005
Posts: 78
Location: Edwards AFB, CA
PostPosted: Thu Jul 05, 2007 2:08 pm
Post subject: Re: 9.1.x security system works?

People get banned still far too easily. I have to turn off the Flooding option, otherwise half my userbase would be banned...

Something is still very buggy with the flooding portion.


Beldak's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.32 / Apache 1.3.37 / MySQL 5.0.16 / PHP 5.2.2 / Dragonfly CVS
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer
Developer

Offline Offline
Joined: Jun 29, 2004
Posts: 3878
Location: Melbourne, AU
PostPosted: Thu Jul 05, 2007 2:37 pm
Post subject: Re: 9.1.x security system works?

I'm currently testing and debugging the flooding while adding few more options and fixing few little bugs. But none of those bugs accelerate the banning process.

As of today it includes an IP shield, logs, debugging and the possibility to add new bots. All of those are pretty stable.

New changes will not ban an user by mistake as well as the current version. However will log all requests so we all will know why they get banned. All this is just to prove that banned users are opening 3 pages in less then 2 seconds.

Using the current version we are able to permit all this (flooding off).
With the new version we will know why they get banned if flooding is on.
If debug is on then system will log any requests coming from the same ip like proxies or browser plugins and anything that accept or not cookies.

If debug on will add one query for every page visit just like what happen already with any user agent that doesn't accept cookies (bot or browser) all the rest doesn't require NO ONE additional query to what the system does already.

Anyways a documentation will be given at the CVS commit.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

Linux 64bit / Apache 2.2 / PHP 5.4 / MySQL 5.5.22 / v9, v10
Linux 32bit / Apache 2.2 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10
Windows 64bit / IIS 7.5 / PHP 5.3.10 / MySQL 5.5.22 / v9, v10


NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
mixed
Back to top
View user's profile Visit poster's website Photo Gallery
Beldak
Nice poster
Nice poster

Offline Offline
Joined: Jun 15, 2005
Posts: 78
Location: Edwards AFB, CA
PostPosted: Thu Jul 05, 2007 3:44 pm
Post subject: Re: 9.1.x security system works?

Sounds good Nano Smile

Would be nice to check the logs and find out the exact reason the ban got triggered. Good work!


Beldak's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.32 / Apache 1.3.37 / MySQL 5.0.16 / PHP 5.2.2 / Dragonfly CVS
Back to top
View user's profile Visit poster's website
Ronin
Dragonfly addicted
Dragonfly addicted

Offline Offline
Joined: Jun 07, 2004
Posts: 475
Location: Calgary, AB
PostPosted: Thu Jul 05, 2007 11:01 pm
Post subject: Re: 9.1.x security system works?

Excellent! Thanks Nano Very Happy

_________________
Cheers,

Ronin
Ronin Technologies
Dragonfly Google Maps Module

Ronin's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Lunarpages Linux / 1.3.37 / 4.1.22-standard-log / 4.4.4 / 9.1.2.5
Back to top
View user's profile Visit poster's website Photo Gallery
Display posts from previous:   
Post new topic    Reply to topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 2
All times are GMT
Go to page 1, 2  Next



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

lexo me teper

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy