272361
GIJOE
Re: EMERGENCY: security hole of Agenda-X
  • 2004/2/14 21:06

  • GIJOE

  • Quite a regular

  • Posts: 265

  • Since: 2003/8/13


Quote:

Jan304 wrote:
I'm suprised of this post by GIJOE. I always tought he was posting on a professional way, but this... Scaring people like hell and advicing to remove in place of fixing it. I hope not for own profit...

My Profit ?
Teach me any profit generated by that Agenda-X users is transferred to piCal.
Though I proud that piCal is far more excellent than Agenda-X as Calendar or Event Manager Module,
I never recommend piCal to such a person who thinks that Agenda-X is better.
To begin with, comparing them is meaningless.

Quote:
Check the post by onokazu:
http://www.xoopscube.jp/modules/news/article.php?storyid=195

Did you read whole of his article?
He wrote REMOVE it as same as my article.
-------------------------
Above-mentioned modified information is not information from the module manufacturer but temporary.
Therefore, when it is not possible to correct it in the self-responsibility, we will recommend the module to be made the temporary each folder save from the module manufacturer to open to the public of a formal correspondence version in the safe place (Inaccessible place according to WEB a browser etc.).
-------------------------

Quote:
You might check the Agenda-X 2.0 beta 2 version, I don't think this version has any security flaw.

No!
2.0 beta 2 has the same sacurity hole.
Have you read the source codes ?

And the security hole of 1.2.2 or 2.0 beta 2 is found by me, not by onokazu.

I read the source and I had the conviction wjue does not have skills to be able to create modules which can be opened to the public.

The hole can be scared by only changing register_globals OFF, but I can't believe his skills any more.

Though the hole is caused by a third party module, the hole deteriorates the reputation of whole XOOPS.
In fact, the "slash dot news" wrotes the articles which the security hole of Agenda-X is misunderstood that XOOPS's security hole.
Only writing that do not use the module which has security holes and lowers the reputation of whole XOOPS might be a "PROFIT" for all.

onokazu also wrotes to the all of XOOPSers :
When you adopt a module made by the third party, you should ascertain the module enough.



272362
Herko
Re: MyDownloads RC1 and XOOPS 2.0.6
  • 2004/2/14 20:54

  • Herko

  • XOOPS is my life!

  • Posts: 4238

  • Since: 2002/2/4 1


As it's an RC, which means a Release Candidate, which entails it's a beta version that is not suited for production sites, then I can't recommend you use it as such. If you want to use it to test etc., no problem, of course. But Release Candidates, any RC's, are NOT meant for production environments. That's why they are RC's and not final versions

Herko



272363
Dave_L
Re: EMERGENCY: security hole of Agenda-X
  • 2004/2/14 20:33

  • Dave_L

  • XOOPS is my life!

  • Posts: 2277

  • Since: 2003/11/7


Re: turning off register_globals

A hosting service might be unwilling to do that because it could break other customers' scripts.

Depending on the server, an .htaccess file with the following contents might work:

php_flag register_globals off



272364
charpres
Re: Best for articles management
  • 2004/2/14 20:32

  • charpres

  • Not too shy to talk

  • Posts: 168

  • Since: 2003/9/4 2


"I would suggest you dig a little further in software that you make comment publicly."

Ok, I looked at Freecontent 3.0 again. You are correct that native XOOPS commenting is supported.

However, printing in the sense that the end user can display a printer-friendly version and then print out with a click (not using the browser's lame printing method) and with the developer's logo on the printed page, is not supported. The other modules in which I said printing is supported have this capability.

Also, XOOPS native searching does not appear to be supported. This is a must, in my humble opinion. What is the point of pulling in content if the content cannot be searched. I still maintain "low" for power is appropriate. Again, this is purely subjective and for my purposes, as I have already said. From someone else's viewpoint the power could be "high."



272365
Mithrandir
Re: EMERGENCY: security hole of Agenda-X

Ask your host to turn off Register Globals. If you host doesn't know, what it is... then switch host



272366
irmtfan
two iranian website with farsi xoops!
  • 2004/2/14 20:13

  • irmtfan

  • Module Developer

  • Posts: 3419

  • Since: 2003/12/7


hi all xoopsers

we are an iranian team & choose XOOPS CMS for development
we release farsixoops v1.1 & this is our official site:

http://ict.iut.ac.ir/

another site that i make it for iranian harry potter fans is:
http://www.jadoogaran.com (means wizards.com in persian)

i work on EADJ2.1 theme for this site

happy valentine's day



272367
marcan
Re: Blocks in center-left and center-right
  • 2004/2/14 20:06

  • marcan

  • Just can't stay away

  • Posts: 824

  • Since: 2003/10/8


Many thanks People !



272368
TooBaked
Re: Theme headerlogo and nav
  • 2004/2/14 20:04

  • TooBaked

  • Just popping in

  • Posts: 37

  • Since: 2003/2/9 5


Ok yes I would like to learn this as I don't want to come crying to you guys all the time Id rather be the one helping.
I'll dig into what you guys give me and see what I come up with, but before I do.

the three stripes are bg-image and those tables are not defined in style.css do I need to define this new table style. and if so how is the best way to code it for xoops.

Thanks for the help,
much appreciated



272369
fatman
Re: ShortURLs hack
  • 2004/2/14 19:45

  • fatman

  • Friend of XOOPS

  • Posts: 176

  • Since: 2003/12/13


Quote:

BPJones wrote:
Quote:
Just to be clear, for this hack to work, it requires Apache to be compiled with the RewriteEngine module.

How would one go about determining if their hosted site has Apache compiled with the RewriteEngine module, short of asking the hosting service themselves?


just upload an .htaccess file with a Rewrite function and see if it works.



272370
DobePhat
Re: Theme headerlogo and nav
  • 2004/2/14 19:33

  • DobePhat

  • Friend of XOOPS

  • Posts: 656

  • Since: 2003/4/15


OK so I see you header image rotates...kinda like a banner right?
I see you have a similar nav...bar...

All you need to do is look at XOOPS files: your template.html.....Open it up in a whysiwyg editor for instance (rec. Dreamweaver..Html Ace..etc) or just look at source....

The top Row...
is actually a table! Just make two rows....insert the appropiate code...the header on top...the your table in the second...
in Css you will need to look for or define the following....
(as example)
<tr id="header">
<id="headerlogo">
headerbanner
Headerbar --

etc.etc. depending on which theme you are basing it on....
Well that should get you looking into deeper solutions anyway...sorry dont have time to go into more detail.

If you want to keep the rotaing header images...you could proabbly just user banner.php code...instead of your logo and just use logo images in rotation...







Login

Who's Online

120 user(s) are online (48 user(s) are browsing Support Forums)


Members: 0


Guests: 120


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: May 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits